6.0.1

Table Of Contents
For example, to enable an Active Directory user to log in to the vCenter Server instance in a
vCenter Server Appliance with an embedded Platform Services Controller by using the vSphere Web Client
with Windows session authentication (SSPI), you must join the vCenter Server Appliance to the Active
Directory domain and assign the Administrator role to this user. To enable an Active Directory user to log in
to a vCenter Server instance that uses an external Platform Services Controller appliance by using the
vSphere Web Client with SSPI, you must join the Platform Services Controller appliance to the Active
Directory domain and assign the Administrator role to this user.
N If you want to enable an Active Directory user to log in to a vCenter Server instance by using the
vSphere Client with SSPI, you must join the vCenter Server instance to the Active Directory domain. For
information about joining a vCenter Server Appliance with an external Platform Services Controller to an
Active Directory domain, see the VMware knowledge base article at hp://kb.vmware.com/kb/2118543.
Prerequisites
Verify that the user name you use to log in to the vCenter Server instance in the vCenter Server Appliance is
a member of the SystemConguration.Administrators group in vCenter Single Sign-On.
Procedure
1 Use the vSphere Web Client to log in as administrator@your_domain_name to the vCenter Server instance
in the vCenter Server Appliance.
The address is of the type hp://appliance-IP-address-or-FQDN/vsphere-client.
2 Under Deployment, click System .
3 Under System Conguration, click Nodes.
4 Under Nodes, select a node and click the Manage tab.
5 Under Advanced, select Active Directory, and click Join.
6 Enter the Active Directory details.
Option Description
Domain
Active Directory domain name, for example, mydomain.com. Do not
provide an IP address in this eld.
Organizational unit
Optional. The canonical name of the organizational unit, for example,
mydomain.com/MyOrganizationalUnit/mycomputer.
I Use this eld only if you are familiar with LDAP.
User name
User name in User Principal Name (UPN) format, for example,
jchin@mydomain.com.
I Down-level login name format, for example,
DOMAIN\UserName, is unsupported.
Password
Password of the user.
7 Click OK to join the vCenter Server Appliance to the Active Directory domain.
The operation silently succeeds and you can see that the Join buon turned to Leave.
8 Right-click the node you edited and select Reboot to restart the appliance so that the changes are
applied.
I If you do not restart the appliance, you might encounter problems when using the
vSphere Web Client.
9 Navigate to Administration > Single Sign-On > .
10 On the Identity Sources tab, click the Add Identity Source icon.
vCenter Server Appliance Configuration
18 VMware, Inc.