How to Reset the ESXi Root Password Without Knowing the Old One

ESXi
playhackmenow.com

Let me guess. You inherited a host, the previous admin walked out the door with the password in their head, and now you are staring at a DCUI login prompt that may as well be a brick wall. Or maybe it was you, and the password is sitting in a KeePass vault that corrupted itself last Tuesday. Either way, you need back in, and the old password is gone.

Grab a coffee. This one is fixable, but only if you planned ahead without knowing you were planning ahead.

Symptom

The ESXi root password has been lost, forgotten, or compromised, and it needs to be reset without providing the old password.

Root Cause

Here is the part that makes people angry, and honestly they have a point.

VMware by Broadcom explicitly blocks the old tricks. No backdoor access. No GRUB single-user mode password reset. This is deliberate, done in the name of security and compliance, and it means that if the current password is truly gone, you cannot reset it from the Direct Console User Interface (DCUI) or from a plain SSH session. The host simply will not let you.

So the days of booting to single-user mode and editing the shadow file are over. Mourn them if you must, then move on, because there is still a way out if your host is not a lonely island.

Resolution and Workaround

Everything hinges on one question: is this host managed, or is it standalone?

If the ESXi host is connected to a vCenter Server, or it is joined to Active Directory, you can sidestep the local root requirement entirely and force a password reset. The management layer already has the authority to do it.

If the host is completely standalone, with no vCenter and no AD integration, I have bad news. You are reinstalling ESXi. There is no clever shortcut, and anyone promising you one is about to get you into trouble. Back up what you can, evacuate the VMs if the host still runs, and plan the rebuild.

For everyone else, PowerCli to the rescue!

PowerCLI via vCenter

If the host is connected to vCenter, this is the quickest path by a mile. You lean on the vpxuser account’s implicit permissions, which vCenter uses to manage the host behind the scenes, and push a new password down without ever being asked for the old one.

The script below handles multiple hosts at once, because of course the password is lost on more than one of them. It is never just one.

A couple of things before you run it:

  • You need PowerCLI installed and an account with the rights to manage the hosts in vCenter.
  • When the credential box pops up, leave the username as root and type the NEW password you want in the password field. You are not entering the old password anywhere, because you do not have it. That is the whole point.
# 1. Define Variables
$vCenterServer = "vcenter01.angrysysops.com"
$TargetHosts = @(
    "esx-host01.angrysysops.com",
    "esx-host02.angrysysops.com"
)

# 2. Connect to the vCenter Server
Connect-VIServer -Server $vCenterServer

# 3. Prompt for the NEW root password
# (Leave username as "root", type the NEW password in the password field)
$Creds = Get-Credential -UserName "root" -Message "Enter the NEW root password for the ESXi hosts"

# 4. Iterate through each host and update the password
foreach ($HostFQDN in $TargetHosts) {
    Write-Host "Processing host: $HostFQDN" -ForegroundColor Cyan

    try {
        # Retrieve the VMHost object
        $VMHostObj = Get-VMHost -Name $HostFQDN -ErrorAction Stop

        # Map the ESXCLI v2 namespace
        $EsxCli = Get-EsxCli -VMHost $VMHostObj -V2

        # Build the payload for the account modification
        $UserArg = $EsxCli.system.account.set.CreateArgs()
        $UserArg.id = "root"
        $UserArg.password = $Creds.GetNetworkCredential().Password
        $UserArg.passwordconfirmation = $Creds.GetNetworkCredential().Password

        # Invoke the password change
        $Result = $EsxCli.system.account.set.Invoke($UserArg)
        if ($Result -eq $true) {
            Write-Host "Successfully updated root password on $HostFQDN" -ForegroundColor Green
        }
    }
    catch {
        Write-Host "Failed to update password on $HostFQDN. Error: $_" -ForegroundColor Red
    }
}

# 5. Disconnect from vCenter
Disconnect-VIServer -Server $vCenterServer -Confirm:$false

The script can be downloaded here: https://github.com/AngrySysOps/scripts/blob/main/PowerShell/esxirootpasswordreset.ps1

Run it, watch for the green text, and test the new password at the DCUI before you walk away. If you see red, read the error. It is almost always a name resolution problem or an account that does not actually have permission on the host.

A quick note on the new password itself: ESXi enforces password complexity, so do not try to set password123 and then come complain when it rejects you. Give it length and mixed character classes and save yourself the second round trip.

When vCenter Is Not an Option

If the host is domain joined but not in vCenter, you have another door. Log in with an AD account that has administrative rights on the host, then reset root from there, either through the Host Client or esxcli. Same idea as above, different front door. The host trusts Active Directory, so Active Directory gets you in.

And if the host is standalone with neither vCenter nor AD, see the Root Cause section again. Reinstall. I did warn you.

The Lesson, Because There Is Always One

The reason this works is that you had a management layer in place before disaster struck. The reason it fails is that someone decided a standalone host did not need to be managed, and now that chicken has come home to roost.

So, action items for after you have fixed today’s fire:

  • Join your hosts to vCenter. All of them.
  • Store the root password in a real secrets manager, not a sticky note and not someone’s memory.
  • Rotate the root password when people leave, as a matter of routine and not panic.

Do that, and the next time this happens it is a five minute script instead of a reinstall and a very long apology email.

Please leave the comment