Changing the vCenter Server identity source from an External Identity Provider (Okta, Entra ID, Ping) back to Active Directory
search cancel

Changing the vCenter Server identity source from an External Identity Provider (Okta, Entra ID, Ping) back to Active Directory

book

Article ID: 406895

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

vCenter was configured to use Entra ID for authentication, and a reversion back to Active Directory is desired.

Environment

vCenter 8.x

Cause

vCenter Server supports one configured external identity provider and switching authentication to another provider(Okta, Entra ID, Ping) requires changing the provider. As a result, the previous provider is no longer available.

Resolution

To switch back to using Active Directory, select Other Providers > Embedded then add the previous Active Directory configuration.

 

Additional Information

Configure vCenter Server Identity Provider Federation for Microsoft Entra ID

Configure vCenter Server Identity Provider Federation for Microsoft Entra ID


vCenter Server supports only one configured external identity provider (one source), and the vsphere.local identity source (local source). Multiple external identity providers cannot be used. vCenter Server Identity Provider Federation uses OpenID Connect (OIDC) for user login to vCenter Server.