An identity source in the identity provider is configured with the type "Active Directory (Integrated Windows Authentication)", but the node is not joined to an Active Directory domain.
Active Directory users are unable to log in to vCenter Server and receive authentication errors. This problem occurs when vCenter is not properly joined to the Active Directory domain.
The vCenter Server is not joined to the Active Directory domain. Without a valid domain join, domain authentication cannot be processed, resulting in login failures for AD users.
Join the vCenter to the Active Directory domain and then add the domain under global permissions. After performing these steps, AD users can log in successfully.
Steps:
2. If vCenter fails to join the AD domain after rebooting, verify whether there is a time mismatch between vCenter and Active Directory. See vCenter disconnects from Active Directory following a reboot due to host time skew