<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vCenter/vSphere and AD in VMware vSphere™ Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908950#M42463</link>
    <description>&lt;P&gt;Thank you.&amp;nbsp; I'm new to this board so not quite familiar yet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2022 14:20:34 GMT</pubDate>
    <dc:creator>timsheets13</dc:creator>
    <dc:date>2022-05-13T14:20:34Z</dc:date>
    <item>
      <title>vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908802#M42461</link>
      <description>&lt;P&gt;We recently setup our vCenter appliance VM and it's working great.&amp;nbsp; I have successfully joined the VM to our AD.&amp;nbsp; We can now authenticate vCenter with our AD credentials.&amp;nbsp; But, when I try to join vsphere html client to the domain so we can also use AD auth there, it fails.&amp;nbsp; The error&lt;BR /&gt;Idm client exception: Error trying to join AD, error code [11], user [spinet\administrator], domain [spinet.local], orgUnit []&lt;/P&gt;&lt;P&gt;Any assistance appreciated as we don't want to use local or shared accounts for vSphere.&lt;/P&gt;&lt;P&gt;Thanks, Tim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 21:29:40 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908802#M42461</guid>
      <dc:creator>timsheets13</dc:creator>
      <dc:date>2022-05-12T21:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908809#M42462</link>
      <description>&lt;P&gt;Expect a moderator to move your thread to the vSphere area now that I have reported it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 22:09:36 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908809#M42462</guid>
      <dc:creator>scott28tt</dc:creator>
      <dc:date>2022-05-12T22:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908950#M42463</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp; I'm new to this board so not quite familiar yet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 14:20:34 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908950#M42463</guid>
      <dc:creator>timsheets13</dc:creator>
      <dc:date>2022-05-13T14:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908972#M42464</link>
      <description>&lt;P&gt;Ciao&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not clear to me what you mean when you say you have joined the domain of the VM. What version of vCenter are you using? However, since vSphere 7.0 version VMware has deprecated Integrated Windows Authentication&lt;BR /&gt;&lt;A href="https://kb.vmware.com/s/article/78506" target="_blank"&gt;https://kb.vmware.com/s/article/78506&lt;/A&gt;&lt;/P&gt;&lt;P&gt;it is recommended to use Active Directory over LDAP&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.vmware.com/s/article/2041378" target="_blank"&gt;https://kb.vmware.com/s/article/2041378&lt;/A&gt;&lt;/P&gt;&lt;P&gt;continue for your mistake you can check this link&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://planetvm.net/blog/?p=3352" target="_blank"&gt;https://planetvm.net/blog/?p=3352&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 15:59:30 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2908972#M42464</guid>
      <dc:creator>fabio1975</dc:creator>
      <dc:date>2022-05-13T15:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909442#M42486</link>
      <description>&lt;P&gt;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5505266"&gt;@timsheets13&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's no longer recommended to you an active directory with vCenter. You should use LDAPS or even better ADFS for authentication.&lt;/P&gt;&lt;P&gt;Did you follow the guide? &lt;A href="https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.vcenter.configuration.doc/GUID-08EA2F92-78A7-4EFF-880E-2B63ACC962F3.html" target="_blank"&gt;https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.vcenter.configuration.doc/GUID-08EA2F92-78A7-4EFF-880E-2B63ACC962F3.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;From security perspective we are heading forwards in avoiding active directory authentication in any ways if not strictly required. You can see it in seperation of concerns. If an attacker gets compromised domain credentials, he will not be able to authenticate to your vCenter.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 11:29:51 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909442#M42486</guid>
      <dc:creator>stadi13</dc:creator>
      <dc:date>2022-05-17T11:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909448#M42487</link>
      <description>&lt;P&gt;Ensure that your Domain is always FQDN, and OU in LDAP format.. not getting this right sometime also cause issues.&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 12:14:26 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909448#M42487</guid>
      <dc:creator>ravjyo</dc:creator>
      <dc:date>2022-05-17T12:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909531#M42495</link>
      <description>&lt;P&gt;Thanks for the great info!&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 17:58:05 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909531#M42495</guid>
      <dc:creator>cool_breeze</dc:creator>
      <dc:date>2022-05-17T17:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909537#M42496</link>
      <description>&lt;P&gt;One more thing is to always use an NTP server to keep time synced between all server. Time is important.&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 18:20:39 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909537#M42496</guid>
      <dc:creator>mbufkin</dc:creator>
      <dc:date>2022-05-17T18:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909650#M42503</link>
      <description>&lt;P&gt;I agree with the indications of other colleagues and would add&lt;/P&gt;&lt;P&gt;As they have already stated Integrated Windows Authentication (IWA) is deprecated, don't use it&lt;/P&gt;&lt;P&gt;&lt;A href="https://blogs.vmware.com/vsphere/2020/05/vsphere-7-integrated-windows-authentication-iwa-ldap.html" target="_blank"&gt;https://blogs.vmware.com/vsphere/2020/05/vsphere-7-integrated-windows-authentication-iwa-ldap.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you use Active Directory as the identity source for vCenter Server, you should plan to enable LDAPS. For more information about this security update from Microsoft, see &lt;A href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190023" target="_blank"&gt;https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190023&lt;/A&gt; and &lt;A href="https://blogs.vmware.com/vsphere/2020" target="_blank"&gt;https://blogs.vmware.com/vsphere/2020&lt;/A&gt; /01/ microsoft-ldap-vsphere-channel-binding-signing-adv190023.html.&lt;/P&gt;&lt;P&gt;From a security perspective, we use DUO to have 2FA&lt;/P&gt;&lt;P&gt;I hope that helps&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 08:00:10 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909650#M42503</guid>
      <dc:creator>8islas</dc:creator>
      <dc:date>2022-05-18T08:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: vCenter/vSphere and AD</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909673#M42504</link>
      <description>&lt;P&gt;If I'm reading your issue properly, you have managed to successfully join vCenter to AD, but unable to join the ESXi hosts to AD ?&lt;/P&gt;&lt;P&gt;Have you tried to putty connect to your ESXi hosts (may need to manually start the SSH service), and perform nslookup to your domain controller? nslookup to the domain FQDN?&lt;/P&gt;&lt;P&gt;If your ESXi hosts are on a separate VLAN / IP range to your domain controllers have you confirmed the relevant port access is open? Check out&amp;nbsp;&lt;A href="https://ports.esp.vmware.com/home/vSphere-7" target="_blank"&gt;https://ports.esp.vmware.com/home/vSphere-7&lt;/A&gt;&amp;nbsp;for list of ports&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 09:44:25 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vCenter-vSphere-and-AD/m-p/2909673#M42504</guid>
      <dc:creator>MattStreet</dc:creator>
      <dc:date>2022-05-18T09:44:25Z</dc:date>
    </item>
  </channel>
</rss>

