Active Directory (AD) Users Unable to Log in to vCenter Server Due to Missing Domain Join
search cancel

Active Directory (AD) Users Unable to Log in to vCenter Server Due to Missing Domain Join

book

Article ID: 407687

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

An identity source in the identity provider is configured with the type "Active Directory (Integrated Windows Authentication)", but the node is not joined to an Active Directory domain.

Active Directory users are unable to log in to vCenter Server and receive authentication errors. This problem occurs when vCenter is not properly joined to the Active Directory domain.

Environment

  • VMware vCenter 7.0.x

  • VMware vCenter 8.0.x

Cause

The vCenter Server is not joined to the Active Directory domain. Without a valid domain join, domain authentication cannot be processed, resulting in login failures for AD users.

Resolution

Join the vCenter to the Active Directory domain and then add the domain under global permissions. After performing these steps, AD users can log in successfully.

Steps:

  • Using the vSphere Client, log in to vCenter Server as a user with administrator privileges in the local vCenter Single Sign-On domain (vsphere.local by default).

  • Select Administration.

  • Expand Single Sign On and click Configuration.

  • Under the Identity Provider tab, click Active Directory Domain.

  • Click Join AD, enter the domain, optional organizational unit, and user name and password, and click Join.

    Check the global permissions for the domain user, and if missing, add the domain user.

  • Restart vCenter Server.

    Note: 1. To attach users and groups from the joined Active Directory domain, add the joined domain as a vCenter Single Sign-On identity source. See Add or Edit a vCenter Single Sign-On Identity Source

                   2. If vCenter fails to join the AD domain after rebooting, verify whether there is a time mismatch between vCenter and Active Directory. See vCenter disconnects from Active Directory following a reboot due to host time skew