6.5.1

Table Of Contents
n
Set the Default Domain for vCenter Single Sign-On
Each vCenter Single Sign-On identity source is associated with a domain. vCenter Single Sign-On
uses the default domain to authenticate a user who logs in without a domain name. Users who
belong to a domain that is not the default domain must include the domain name when they log in.
n
Add a vCenter Single Sign-On Identity Source
Users can log in to vCenter Server only if they are in a domain that has been added as a vCenter
Single Sign-On identity source. vCenter Single Sign-On administrator users can add identity sources
from the vSphere Web Client or the Platform Services Controller interface.
n
Edit a vCenter Single Sign-On Identity Source
vSphere users are defined in an identity source. You can edit the details of an identity source that is
associated with vCenter Single Sign-On.
n
Remove a vCenter Single Sign-On Identity Source
You can remove an identity source from the list of registered identity sources. When you do, users
from that identity source can no longer authenticate to vCenter Single Sign-On.
n
Use vCenter Single Sign-On With Windows Session Authentication
You can use vCenter Single Sign-On with Windows Session Authentication (SSPI). You must join
the Platform Services Controller to an Active Directory domain before you can use SSPI.
Identity Sources for vCenter Server with vCenter Single Sign-On
You can use identity sources to attach one or more domains to vCenter Single Sign-On. A domain is a
repository for users and groups that the vCenter Single Sign-On server can use for user authentication.
An identity source is a collection of user and group data. The user and group data is stored in Active
Directory, OpenLDAP, or locally to the operating system of the machine where vCenter Single Sign-On is
installed.
After installation, every instance of vCenter Single Sign-On has the identity source your_domain_name,
for example vsphere.local. This identity source is internal to vCenter Single Sign-On. A vCenter Single
Sign-On administrator can add identity sources, set the default identity source, and create users and
groups in the vsphere.local identity source.
Platform Services Controller Administration
VMware, Inc. 32