When attempting to migrate the vCenter identity source from IWA to LDAPS, the process fails with an error similar to "Cannot add identity source because the domain is already configured"
This behavior is expected in vCenter Server. SSO does not allow two identity sources to be configured for the same domain name at the same time.
This issue is similar to:
To resolve this, follow these steps:
Migrating identity source from IWA to AD over LDAP/OpenLDAP - vCenter Server
Integrated Windows Authentication (IWA) was first deprecated with the release of vSphere 7.0. Broadcom has announced that IWA will be officially removed in the first major release after vSphere 8.0 Update 3 (vSphere 9.0). As a result, vCenter Server will no longer support joining an Active Directory domain via the IWA method, and users must transition to modern identity providers to maintain Active Directory authentication.