How to Safely Reset a Lost or Forgotten ESXi Root Password

VMware tutorial - IT technology blog
VMware tutorial - IT technology blog

Real-World Scenario: Losing Control of a Running ESXi Host

This scenario happens quite often in the real world: you just took over system administration from a former colleague, or powered on a Dell R740 or HPE DL380 server that sat idle in the server room for months, only to realize that nobody knows the root password.

Both the ESXi Host Client interface and the DCUI (Direct Console User Interface) reject your login. Meanwhile, 10–15 production virtual machines hosting databases, internal websites, or ERP systems are still running beneath it. If you perform a clean reinstall of the host, you could lose half a day reconfiguring vSwitches, VLAN tags, and storage mounts, posing a high risk of service downtime.

Why Does ESXi Lack a “Forgot Password” Feature?

Unlike standard Linux operating systems, VMware ESXi is a locked-down bare-metal hypervisor. VMware designed this operating system to run entirely in RAM after booting to maximize security and stability.

On every boot, ESXi extracts the state.tgz archive from the bootbank partition (formatted as FAT16/vfat) into RAM for operation. The etc/shadow file containing the password hash for the root user is buried deep inside this nested archive structure (state.tgz > local.tgz > etc/shadow). Only when you change the password via the management interface does the system recompress and write it back to the disk.

VMware officially recommends reinstalling ESXi whenever a root password is lost. However, in practical operations, you can safely modify the bootbank archive to clear the password without affecting the underlying virtual machine data.

3 Ways to Reset a Forgotten ESXi Root Password

Method 1: Reset Password Using an Ubuntu Live USB (Recommended for Standalone Hosts)

This method applies to standalone ESXi hosts not managed by vCenter. The required maintenance window is only about 5–10 minutes.

Step 1: Prepare a bootable Ubuntu Desktop USB drive (version 20.04 or 22.04 LTS). Plug it into the server and boot into Try Ubuntu without installing mode.

Step 2: Open Terminal in Ubuntu and locate the ESXi boot partition:

sudo blkid

Look for a vfat partition labeled BOOTBANK1 or with a size of approximately 250MB – 4GB (depending on whether it is ESXi 6.7, 7.0, or 8.0). Suppose this partition is /dev/sdb5 (or /dev/nvme0n1p5 on an NVMe drive).

Step 3: Mount the bootbank partition into Ubuntu:

sudo mkdir -p /mnt/esxi_boot
sudo mount /dev/sdb5 /mnt/esxi_boot
ls -lh /mnt/esxi_boot/state.tgz

If the output lists the state.tgz file, you have mounted the correct configuration partition.

Step 4: Extract the configuration archive to access the shadow file:

# Create a temporary working directory
mkdir -p /tmp/esxi_config && cd /tmp/esxi_config

# Extract state.tgz -> local.tgz -> etc/shadow
tar -xzf /mnt/esxi_boot/state.tgz
tar -xzf local.tgz
rm local.tgz

Step 5: Open the etc/shadow file using the nano editor:

nano etc/shadow

The first line typically looks like this:

root:$6$xyz123...password_hash...:13358:0:99999:7:::

Delete the entire hash string between the first and second colons, leaving it as:

root::13358:0:99999:7:::

Press Ctrl + O then Enter to save the file, and press Ctrl + X to exit. This resets the root password to a blank (empty) state.

Step 6: Repackage the configuration and write it back to the boot partition:

# Recompress into local.tgz and then state.tgz
tar -czf local.tgz etc
tar -czf /mnt/esxi_boot/state.tgz local.tgz

# Safely unmount
cd ~
sudo umount /mnt/esxi_boot
sudo reboot

Step 7: Remove the USB drive and let the server reboot into ESXi. Log in to the DCUI or Web UI with the root username and a blank password. Once logged in, change the password immediately.

Method 2: Synchronize a New Password via vCenter Host Profile (Zero Downtime)

If the ESXi host is part of a cluster managed by VMware vCenter (requires a vSphere Enterprise Plus license), you do not need to power off the server or use a rescue USB drive.

  1. Log in to the vSphere Client using an Administrator account.
  2. Navigate to Policies and Profiles > Host Profiles.
  3. Select Extract Host Profile from a healthy host, or create a new profile.
  4. Edit the Host Profile: Navigate to Security and Services > Security > User Configuration > root.
  5. Enter the new password you want to set for the root account.
  6. Attach this Host Profile to the target ESXi host with the lost password and click Remediate. vCenter will automatically apply the new password to the host within 1–2 minutes.

Method 3: Reinstall ESXi and Select “Preserve VMFS Datastore”

This approach is suitable when company security policies prohibit booting external Live CDs, or when the ESXi OS on the server has corrupted bootbank files that cannot be recovered via USB.

Insert the ESXi installation USB (or mount the ISO via iLO/iDRAC/KVM) matching your current version and proceed with the installation.

When reaching the disk selection screen, the installer will detect the existing ESXi installation and offer three options:

  • Upgrade ESXi, preserve VMFS datastore: Upgrades ESXi and keeps the existing configuration (does not reset the root password).
  • Install ESXi, preserve VMFS datastore: Installs a clean OS, resets root password and networking to defaults, while preserving 100% of the virtual machine data on the Datastore.
  • Install ESXi, overwrite VMFS datastore: Completely wipes the drive and deletes all virtual machines (never select this option).

Choose the second option (Install ESXi, preserve VMFS datastore). Once the installation completes in about 10–15 minutes, reconfigure your IP address and vSwitches, then browse the Datastore and select Register VM (re-registering VMs from their .vmx files) to bring your services back online.

Which Solution Should You Choose for Your Infrastructure?

Depending on your infrastructure setup, you can select the most appropriate method:

  • Standalone Physical Host: Use Ubuntu Live USB (Method 1). This is the fastest method, preserving 100% of network configurations, static IPs, and vSwitches with only 5–10 minutes of downtime.
  • Enterprise Environment with vCenter: Use Host Profile (Method 2). This method incurs zero downtime, is safe, and follows VMware best practices.
  • Corrupted Boot or Misconfigured ESXi Host: Use Reinstalling while Preserving Datastore (Method 3) to get a fresh OS installation while keeping all virtual machine data fully intact.
Share: