SV-216875r612237_rule
V-216875
SRG-APP-000516
VCWN-65-000056
CAT II
10
To update a user or groups permissions to an existing role with reduced permissions do the following:
From the vSphere Web Client go to Administration >> Access Control >> Global Permissions. Select the user or group and click "Edit" and change the assigned role and click "OK". If permissions are assigned on a specific object then the role must be updated where it is assigned for example at the cluster level.
To create a new role with reduced permissions do the following:
From the vSphere Web Client go to Administration >> Access Control >> Roles. Click the green plus sign and enter a name for the role and select only the specific permissions required. Users can then be assigned to the newly created role.
From the vSphere Web Client go to Administration >> Access Control >> Roles.
View each role and verify the users and/or groups assigned to it.
or
From a PowerCLI command prompt while connected to the vCenter server run the following command:
Get-VIPermission | Sort Role | Select Role,Principal,Entity,Propagate,IsGroup | FT -Auto
Application service account and user required privileges should be documented.
If any user or service account has more privileges than required, this is a finding.
V-216875
False
VCWN-65-000056
From the vSphere Web Client go to Administration >> Access Control >> Roles.
View each role and verify the users and/or groups assigned to it.
or
From a PowerCLI command prompt while connected to the vCenter server run the following command:
Get-VIPermission | Sort Role | Select Role,Principal,Entity,Propagate,IsGroup | FT -Auto
Application service account and user required privileges should be documented.
If any user or service account has more privileges than required, this is a finding.
M
4030