Authentication failure when connecting VMware Workstation to vCenter Server using MFA or Certificate-based Identity Providers
search cancel

Authentication failure when connecting VMware Workstation to vCenter Server using MFA or Certificate-based Identity Providers

book

Article ID: 427329

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

When attempting to connect to a vCenter Server instance through VMware Workstation, the connection fails even if the correct credentials are provided.

The following error is observed in the VMware Workstation UI: Failed to connect to <vcenter-fqdn>. Cannot complete login due to an incorrect user name or password.

Environment

 VMware Workstation Pro X

Cause

This issue is due to a product limitation. VMware Workstation currently supports single-factor authentication (SFA) for vCenter connections. It is not architected to process the advanced authentication handshakes (such as redirects for MFA or certificate prompts) required by certain external identity providers. The error "incorrect user name or password" is a generic response triggered when the IDP's additional authentication requirements are not met.

Resolution

To administer your vCenter environment, consider the following alternative approaches:

  • vSphere Client: Access vCenter using a supported web browser. Browsers inherently handle the redirects and authentication handshakes required for MFA and certificate-based authentication.
  • SFA Bypass: Coordinate with your Identity Management team to set up a dedicated service or user account with a Single-Factor Authentication (SFA) bypass for direct connections from VMware Workstation.
  • Local Accounts: If permitted by SSO policies, use a local vCenter account (for example, `[email protected]`), as these accounts typically do not invoke external Identity Provider (IDP) authentication.