AD Users Unable to Access Workload Domain vCenter in VMware Cloud Foundation
search cancel

AD Users Unable to Access Workload Domain vCenter in VMware Cloud Foundation

book

Article ID: 453996

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Active Directory (AD) users are unable to access the Workload Domain (WLD) vCenter, while the [email protected] account remains accessible. 

AD domain users are not displayed within the vCenter. 

The SDDC Manager reports that the [email protected] account is in a "Disconnected" state.

Environment

vCenter 9.1

Cause

 The SSO integration between the WLD vCenter and the Active Directory domain has become stale or disconnected. 

Resolution

  1. Remediate Administrator Account:

    • Log in to the SDDC Manager.
    • Identify the warning status for the [email protected] account.
    • Use the Remediate Password function in the SDDC Manager to resolve the "Disconnected" status.
  2. Reconfigure SSO Integration: If AD user access is still not restored, reconfigure the SSO component:

      • In the VCF Operations navigation bar at the top, click Manage.
      • In the left navigation pane, click Fleet Management > Identity & Access.
      • In the Identity & Access pane, click VCF SSO Overview.
      • Under the Component Configuration tab, select the affected vCenter appliance from the data grid.
      • Click the horizontal ellipsis (...) and select Unjoin SSO.
      • Once the process completes, select the checkbox for the vCenter component and perform the Configure Component option to re-establish the SSO connection.