6.7

Table Of Contents
If you want to configure permissions so that users and groups from an Active Directory can access the
vCenter Server components, you must join the Platform Services Controller instance to the Active
Directory domain.
For example, to enable an Active Directory user to log in to the vCenter Server instance in a
vCenter Server Appliance with an embedded Platform Services Controller by using the
vSphere Web Client with Windows session authentication (SSPI), you must join the
vCenter Server Appliance to the Active Directory domain and assign the Administrator role to this user. To
enable an Active Directory user to log in to a vCenter Server instance that uses an external
Platform Services Controller appliance by using the vSphere Web Client with SSPI, you must join the
Platform Services Controller appliance to the Active Directory domain and assign the Administrator role to
this user.
Prerequisites
n
Verify that the user who logs in to the vCenter Server instance in the vCenter Server Appliance is a
member of the SystemConfiguration.Administrators group in vCenter Single Sign-On.
n
Verify that the system name of the appliance is an FQDN. If, during the deployment of the appliance,
you set an IP address as a system name, you cannot join the vCenter Server Appliance to an Active
Directory domain.
Procedure
1 Use the vSphere Web Client to log in as administrator@your_domain_name to the vCenter Server
instance in the vCenter Server Appliance.
2 On the vSphere Web Client main page, click Home, and select System Configuration.
3 Under Deployment, click System Configuration.
4 Under System Configuration, click Nodes.
5 Under Nodes, select a node and click the Manage tab.
6 Under Advanced, select Active Directory, and click Join.
7 Enter the Active Directory details.
Option Description
Domain Active Directory domain name, for example, mydomain.com. Do not provide an IP
address in this text box.
Organizational unit Optional. The full OU LDAP FQDN, for example,
OU=Engineering,DC=mydomain,DC=com.
Important Use this text box only if you are familiar with LDAP.
User name User name in User Principal Name (UPN) format, for example,
jchin@mydomain.com.
Important Down-level login name format, for example, DOMAIN\UserName, is
unsupported.
Password Password of the user.
vCenter Server Appliance Configuration
VMware, Inc. 20