VMware vCenter Server 8.x
This is a administrative configuration task triggered by security requirements to rotate exposed credentials or transition to a new service account for Identity Provider authentication.
Follow these steps to update the service account credentials. In an Enhanced Linked Mode environment, these changes only need to be performed on one vCenter Server instance, as the configuration will replicate to all other linked vCenter Servers.
Ensure that the new service account or updated password has already been configured and verified on the external Identity Provider (e.g., Active Directory).
(Optional but recommended) Take a snapshot of the vCenter Server Appliance (VCSA) before making configuration changes. In ELM, it is best practice to snapshot all linked appliances while powered off, though not strictly required for this specific UI-based change.
Confirm the vCenter Servers are in a healthy replication state.
Log in to the vSphere Client with an account that has SSO administrator privileges.
Navigate to Administration > Single Sign On > Configuration.
Select the Identity Provider tab.
Identify the relevant Identity Source (e.g., the AD over LDAP source) and click Edit.
In the Edit Identity Source window:
To update the existing account: Enter the new password in the Password field.
To switch to a new account: Update the Username field (use the format user@domain or <domain>\user) and enter the new password.
Click Save or OK.
The vCenter will attempt to authenticate with the LDAP server using the new credentials. If authentication fails, the original settings are typically retained.
Verify an AD user is able to successfully log into the vCenter. If in linked mode, verify replication completed by logging into a different linked vCenter instance with an AD account and checking the Identity Provider settings.