In VMware NSX environments, administrators may identify inactive default local accounts, such as guestuser1 and guestuser2. For security compliance or audit purposes, organizations often seek to remove these unused accounts to reduce the surface area for potential unauthorized access.
This article clarifies the behavior and restrictions regarding the deletion of these default local accounts across different versions of NSX and outlines the critical operational risks associated with their removal from specific node types.
VMware NSX
The ability to delete default local user accounts is version-dependent. In earlier versions (NSX-T 3.2.x), the system enforces a hard restriction on the removal of these accounts. Starting with NSX 4.1.x, the management plane allows for the deletion of these users; however, the underlying architecture of the NSX Edge node does not support the recreation of these specific accounts once they are purged from the local database.
For NSX-T 3.2.x: The system inherently restricts the deletion of default local user accounts.
For NSX 4.1.x and 4.2.x: Deletion is permitted via the UI or API if internal compliance mandates removal.
Procedure to Delete:
guestuser1).