Configure VMware vCenter API integration with Tenable Security Center
Required User Role: Administrator, or an organizational user with appropriate permissions. For more information, see Configure VMware vCenter API integration with Tenable Security Center in the Tenable Security Center documentation.
In Tenable Security Center, VMware credentials are configured as authentication settings on a scan policy, or as reusable credentials, using the VMware vCenter API credential type in the Miscellaneous category.
Required Permissions
Within VMware, the minimum privileges depend on which API the scan uses.
| Scan Type | API Type | Permissions Needed |
|---|---|---|
| vCenter credential for vulnerability scanning (7.0.3+) | REST | vCenter account with read permissions, plus VMware vSphere Lifecycle Manager: Image Privileges = Read |
| vCenter credential for vulnerability scanning (earlier than 7.0.3) | SOAP | vCenter admin account with read and write permissions |
| Compliance scan | SOAP | Global → Settings |
To create a minimally privileged vCenter user role:
-
Log in to vCenter.
-
(Optional) Create a new user account:
-
Navigate to Administration > Access Control.
-
Select Roles.
-
Create a new role with a name of your choice (for example, "Nessus").
-
-
Select the VMware vSphere Lifecycle Manager category.
-
Under Lifecycle Manager: Image Privileges, select Read.
-
(Optional) To perform compliance scans, also select Global → Settings.
-
Click Create.
-
Go to the Inventory page and right-click the root vCenter object at the top of the left-hand tree.
-
Click Add Permission.
-
Select the user account and the role you created.
-
Select Propagate to children, then click OK.
-
Run a Tenable scan to verify the permissions work.
Required User Role: Some compliance audits — specifically those with "Bare Metal" in the name — require an SSH credential, and that SSH user must be an administrator-level ESXi user. A read-only user cannot be used. This requirement applies only to the SSH user needed by Bare Metal audits.
Note: Because the VMware vCenter API credential supports both a SOAP and a REST connection method, and Tenable selects between them by version, the scan configuration below covers both. Configure the credential once. No version-specific credential selection is required.