2V0-621 · Question #19
An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage users and groups. The AD domain group ESX Admins is planned for administrative access to the host. Which…
The correct answer is A. If administrative access for ESX Admins is not required, this setting can be altered. C. An ESXi host provisioned with Auto Deploy cannot store AD credentials. Joining an ESXi host to Active Directory grants the ESX Admins group full host admin privileges by default, and Auto Deploy hosts cannot persistently store AD credentials across reboots.
Question
An administrator wants to configure an ESXi 6.x host to use Active Directory (AD) to manage users and groups. The AD domain group ESX Admins is planned for administrative access to the host. Which two conditions should be considered when planning this configuration? (Choose two.)
Options
- AIf administrative access for ESX Admins is not required, this setting can be altered.
- BThe users in ESX Admins are not restricted by Lockdown Mode.
- CAn ESXi host provisioned with Auto Deploy cannot store AD credentials.
- DThe users in ESX Admins are granted administrative privileges in vCenter Server.
How the community answered
(40 responses)- A80% (32)
- B8% (3)
- D13% (5)
Why each option
Joining an ESXi host to Active Directory grants the ESX Admins group full host admin privileges by default, and Auto Deploy hosts cannot persistently store AD credentials across reboots.
By default, ESXi automatically grants full administrative privileges to any AD group named 'ESX Admins', but this default group name and behavior can be changed by the administrator if that level of automatic privilege assignment is not desired for the environment.
Members of the ESX Admins AD group are subject to Lockdown Mode restrictions just like other users - they are not automatically exempted unless they are also added to the Exception Users list on the host.
ESXi hosts provisioned via Auto Deploy boot statelessly from a network image and have no persistent local storage, so they cannot retain Kerberos tickets or other AD credentials between reboots, which requires additional planning for AD-based authentication in Auto Deploy environments.
The ESX Admins group grants administrative privileges only on the ESXi host itself, not in vCenter Server, as vCenter Server manages its own separate permissions system independent of ESXi host-level AD group assignments.
Concept tested: ESXi Active Directory integration and Auto Deploy AD credential limitations
Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-DC96FFDB-F5F2-43EC-8C73-05ACDAE6BE43.html
Topics
Community Discussion
No community discussion yet for this question.