VMware vCenter Server
VMware vSphere ESXi
The environment requires a local, minimum privilege user account configured on the ESXi host or vCenter Server to successfully execute Qualys vulnerability scans.
As per Qualys's official documentation, Qualys supports scanning ESXi hosts using two primary authentication methods. You can choose the method that best aligns with your environment's architecture:
Direct ESXi Credentials: The Qualys scanner authenticates directly to the individual ESXi host.
Action: To create a local user with the necessary permissions on the ESXi host, follow the official Qualys guide: Steps to Create Minimum Privilege User for ESXi Scan
vCenter Server Credentials: The Qualys scanner authenticates to the vCenter Server, which then pulls data for the managed ESXi hosts.
Action: To create a user and custom role within vCenter, follow the official Qualys guide: Steps to Create Minimum Privilege User for ESXi Scan (from vCenter)