Integrated Windows Authentication (IWA) will be removed in the next major release after vSphere 8.0 Update 3 as announced in the release notes.
What does removal of IWA mean?
Customers are encouraged to migrate to a federated Identify Provider such as Okta, Entra ID, PingFederate, or Active Directory Federation Services (AD FS). See vSphere documentation for more details.
Active Directory over LDAPS (AD over LDAPS) is also available. KB 344919 describes important considerations when moving from IWA to AD over LDAPS.
When will support be removed?
Support for IWA will be removed from the next major release of vCenter after 8.0. ESXi will continue to support Active Directory authentication, but IWA functionalities like Windows Session Authentication (SSPI) will be removed in a future ESXi release.
What will happen when I upgrade my vCenter?
Upgrading to vSphere version 8.0 Update 3 or earlier will retain IWA settings with no change in authentication functionality. You will need to remove the IWA configuration before upgrading vCenter to the next major release after 8.0 Update 3.
What will happen when I upgrade my ESXi?
While IWA deprecation has been announced, Active Directory will still be supported for ESXi in the next major release after 8.0 Update 3. Therefore, upgrading ESXi will retain Active Directory settings with no change in authentication functionality. IWA functionalities like Windows Session Authentication (SSPI) will be removed in a future ESXi release.