STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The vCenter Server must limit membership to the "TrustedAdmins" Single Sign-On (SSO) group.

DISA Rule

SV-258957r961863_rule

Vulnerability Number

V-258957

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000291

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Groups.

Click the next page arrow until the "TrustedAdmins" group appears.

Click "TrustedAdmins".

Click the three vertical dots next to the name of each unauthorized account.

Select "Remove Member".

Check Contents

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Groups.

Click the next page arrow until the "TrustedAdmins" group appears.

Click "TrustedAdmins".

Review the members of the group and ensure that only authorized accounts are present.

Note: These accounts act as root on the Photon operating system and have the ability to severely damage vCenter, inadvertently or otherwise.

If there are any accounts present as members of TrustedAdmins that are not authorized, this is a finding.

Vulnerability Number

V-258957

Documentable

False

Rule Version

VCSA-80-000291

Severity Override Guidance

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Groups.

Click the next page arrow until the "TrustedAdmins" group appears.

Click "TrustedAdmins".

Review the members of the group and ensure that only authorized accounts are present.

Note: These accounts act as root on the Photon operating system and have the ability to severely damage vCenter, inadvertently or otherwise.

If there are any accounts present as members of TrustedAdmins that are not authorized, this is a finding.

Check Content Reference

M

Target Key

5573