Error: "Authorization to perform this operation has been rejected" when attempting to log into ESXi with AD users
search cancel

Error: "Authorization to perform this operation has been rejected" when attempting to log into ESXi with AD users

book

Article ID: 388441

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Active Directory users cannot log into the ESXi host UI (https://HostFQDN/ui)

The following error is observed when attempting to login: Authorization to perform this operation has been rejected

/var/run/log/hostd.log reports an error like below:

Er(163) Hostd[2102217]: [Originator@6876 sub=Default opID=esxui rhost=##.##.##.## sid=#] [module:pam_lsass]pam_sm_authenticate: failed [error code:40017]
In(166) Hostd[2102217]: [Originator@6876 sub=Vimsvc.HaSessionManager opID=esxui sid=#] Accepted password for user Domain\Username from ##.##.##.## - session=#

Environment

ESXi 8.0.x

Cause

The ESX Admins group is missing from the Assigned users and roles for Host In the Manager Permissions menu.

Resolution

Add the ESX Admins Group to the Assigned users and roles for Host In the Manager Permissions menu.

Additional Information