STIGQter STIGQter: STIG Summary: VMware vSphere 8.0 vCenter Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The vCenter Server must disable accounts used for Integrated Windows Authentication (IWA).

DISA Rule

SV-265979r1003616_rule

Vulnerability Number

V-265979

Group Title

SRG-APP-000516

Rule Version

VCSA-80-000305

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Users.

Select the "K/M" or "krbtgt/VSPHERE.LOCAL" and click "More" then select "Disable".

Click "Ok" to disable the user account.

Check Contents

If IWA is used for vCenter authentication, this is not applicable.

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Users.

Change the domain to "vsphere.local" and review the "K/M" and "krbtgt/VSPHERE.LOCAL" accounts.

If the "K/M" and "krbtgt/VSPHERE.LOCAL" accounts are not disabled, this is a finding.

Vulnerability Number

V-265979

Documentable

False

Rule Version

VCSA-80-000305

Severity Override Guidance

If IWA is used for vCenter authentication, this is not applicable.

From the vSphere Client, go to Administration >> Single Sign On >> Users and Groups >> Users.

Change the domain to "vsphere.local" and review the "K/M" and "krbtgt/VSPHERE.LOCAL" accounts.

If the "K/M" and "krbtgt/VSPHERE.LOCAL" accounts are not disabled, this is a finding.

Check Content Reference

M

Target Key

5573