AD user permission or privilege is not removed after user deletion in AD
search cancel

AD user permission or privilege is not removed after user deletion in AD

book

Article ID: 453451

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

After deleting an Active Directory (AD) user or group from the domain, the corresponding permissions are not automatically removed from the vCenter Server object hierarchy. 

Environment

VMware vCenter Server

Cause

vCenter Server permissions establish a static association between an inventory object and a user or group's Active Directory SID. When the object is destroyed in AD, the permission mapping remains orphaned within the vCenter database.

Resolution

  1. Log in to the vSphere Client with administrative privileges.
  2. Navigate to the specific inventory object where the permissions were originally assigned (e.g., vCenter Server global root, Datacenter, Cluster, or Virtual Machine).
  3. Select the Permissions tab for the selected object.
  4. Locate the removed AD user or group.
  5. Click the DELETE icon to delete the stale permission mapping.
  6. Repeat this process for any other explicitly assigned permissions across the inventory hierarchy.