Migrating identity source from IWA to LDAPS, received the error Cannot add identity source because the domain is already configured
search cancel

Migrating identity source from IWA to LDAPS, received the error Cannot add identity source because the domain is already configured

book

Article ID: 450293

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

When attempting to migrate the vCenter identity source from IWA to LDAPS, the process fails with an error similar to "Cannot add identity source because the domain is already configured" 

Cause

This behavior is expected in vCenter Server. SSO does not allow two identity sources to be configured for the same domain name at the same time.  

This issue is similar to:

vCenter can't join Active Directory domain using the same domain name as vCenter Single Sign-On (SSO)

Resolution

To resolve this, follow these steps:

  1. Take a Snapshot: Ensure there is a fresh, powered-off snapshot of the vCenter Server (and all linked vCenters in the SSO domain).
  2. Remove IWA: Navigate to Administration > Single Sign-On > Configuration, select the existing IWA identity source, and click Remove.
  3. Add LDAPS: Click Add, select Active Directory over LDAP, and enter your LDAPS details (ensure the domain controller certificates ready).
  4. Verify: Permissions should persist automatically as they are mapped by the domain name string.

Additional Information

Migrating identity source from IWA to AD over LDAP/OpenLDAP - vCenter Server

Integrated Windows Authentication (IWA) was first deprecated with the release of vSphere 7.0. Broadcom has announced that IWA will be officially removed in the first major release after vSphere 8.0 Update 3 (vSphere 9.0). As a result, vCenter Server will no longer support joining an Active Directory domain via the IWA method, and users must transition to modern identity providers to maintain Active Directory authentication.

Removal of Integrated Windows Authentication (IWA)