Integrating Native Multi-Factor Authentication for Local vCenter Server Accounts is Unsupported
search cancel

Integrating Native Multi-Factor Authentication for Local vCenter Server Accounts is Unsupported

book

Article ID: 446153

calendar_today

Updated On:

Products

VMware vCenter Server 8.0

Issue/Introduction

Information Security teams may inquire about integrating Multi-Factor Authentication (MFA) to lock down all local users and accounts within VMware vCenter Server.

Environment

vCenter Server 8.x

Cause

Native Multi-Factor Authentication (MFA) for local vCenter Server accounts (such as administrator@vsphere.local or the local OS root account) is an unsupported configuration. vCenter Server does not provide a native, local MFA toggle for users.

Resolution

RESOLUTION

  • Acknowledge that native MFA for local accounts is an unsupported architecture in vCenter Server.
  • Restrict and retain the use of local accounts strictly for administrative access and error recovery scenarios when the identity provider is unavailable.

Additional Information

vCenter Server Identity Provider Federation