VCF SSO login requires upn@domain
search cancel

VCF SSO login requires upn@domain

book

Article ID: 393150

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

If vCenter is directly configured to the Active Directory, it was possible to login to vCenter's even if the UPN suffix was different from the domain name using the UPN suffix.

Environment

VCF Operations 9.0, vCenter 9.0

Resolution

The user needs to log in using userName@domain in VCF SSO 9.0 for the login to be successful. 

 

Example: 

 

Scenario #1 - If vCenter is directly connected to the Active Directory 

Login will be successful using [email protected] , i.e., userPrincipalName is enough. 

 

Scenario #2 - If vCenter is connected to the Active Directory using VCF SSO in 9.0

Login will be successful using [email protected]@example.org. Login will fail using [email protected].

This means that userPrincipalName@domain is mandatory in order for the login to be successful.