User and Group Discovery APIs No Longer Supported for Federation
search cancel

User and Group Discovery APIs No Longer Supported for Federation

book

Article ID: 388674

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

The vCenter APIs used to list or report information on users and groups are not supported by federated identity sources. These APIs include, but are not limited to, GroupChecker and PrincipalDiscovery.

For example, this means that the powershell cmdlet Get-VIAccount cannot function with federated identity sources in VCF 9.0.

Environment

vCenter 9.0 with a federated identity source.

Cause

This configuration was typically used to support legacy user/group enumeration via PowerCLI or API calls. This is no longer supported.  

Resolution

Instead of calling vCenter APIs to obtain user and group information from the federation provider, call the federation provider directly.

ADFS

Okta

Azure EntraID

Additional Information

For more information, see the documentation for your federation provider.