SSO validations in VCF 9.x receiving invalid username and password for specific users
search cancel

SSO validations in VCF 9.x receiving invalid username and password for specific users

book

Article ID: 444784

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

You have received invalid username and password messages after modifications to AD domains. Users cannot exist in sub domains while also in the original domains setup as sAMAccountName authentication. 

Environment

VCF 9.x Embedded SSO

VCenter, or external IDB 9.x

Active directory SAML authentication

Cause

If you have a duplicate name in the primary domain and the subdomain, sAMAccountName authentication cannot differentiate between accounts, and will fail. 

Resolution

  • Swapping to UPN(UserPrincipalName) to include the domain path allows for duplicate users. 
  • The process can vary depending on SSO configuration. Please follow this document to validate the SSO configuration used. 
  • Configure a New VCF Single Sign-On for a VCF Instance