Deleting default local guest user accounts in VMware NSX
search cancel

Deleting default local guest user accounts in VMware NSX

book

Article ID: 450730

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

In VMware NSX environments, administrators may identify inactive default local accounts, such as guestuser1 and guestuser2. For security compliance or audit purposes, organizations often seek to remove these unused accounts to reduce the surface area for potential unauthorized access.

This article clarifies the behavior and restrictions regarding the deletion of these default local accounts across different versions of NSX and outlines the critical operational risks associated with their removal from specific node types.

Environment

VMware NSX

Cause

The ability to delete default local user accounts is version-dependent. In earlier versions (NSX-T 3.2.x), the system enforces a hard restriction on the removal of these accounts. Starting with NSX 4.1.x, the management plane allows for the deletion of these users; however, the underlying architecture of the NSX Edge node does not support the recreation of these specific accounts once they are purged from the local database.

Resolution

For NSX-T 3.2.x: The system inherently restricts the deletion of default local user accounts.

  • Action: No deletion is possible.
  • Recommendation: Leave the accounts in their current Inactive status. Inactive accounts do not pose a security risk as they cannot be used for authentication without explicit activation and password assignment.

For NSX 4.1.x and 4.2.x: Deletion is permitted via the UI or API if internal compliance mandates removal.

Prerequisites:
  • Ensure you have Enterprise Admin or admin privileges.
  • If you delete these default guest users from an NSX Edge node, they cannot be recreated. 

Procedure to Delete:

  1. Log in to the NSX Manager UI.
  2. Navigate to System > User Management.
  3. Select the Local Users tab.
  4. Locate the specific guest user (e.g., guestuser1).
  5. Click the Actions menu (three dots) and select Delete.
  6. Confirm the deletion when prompted.

Additional Information

Manage Local User Accounts 3.2

Manage Local User Accounts 4.x