VMware Cloud Community
lvaibhavt
Hot Shot
Hot Shot

unable to see Virtual Center in the Web Client when logged as domain administrator in 5.5

Hi All,

In my lab environment I have installed VC 5.5. When I connect to the VC via the web client and login with Administrator@vsphere.local account I am able to see the Virtual Center.

However when I login to the VC 5.5 via web client and login with my domain admin credentials then I am unable to see the Virtual Center

I have added my domain as default domain from administrator@vsphere.local credentials

I am able to login to the VC via vsphere client from my domain administrator credentials and all looks fine

I am just not able to see VC in the Web client when I login from domain admin credentials.

Any suggestion on how to proceed

Thanks

0 Kudos
13 Replies
lvaibhavt
Hot Shot
Hot Shot

reinstalled the Web client but no go ..... I am still unable to see VC in Web client when I log in as domain admin

0 Kudos
vThinkBeyondVM
VMware Employee
VMware Employee

I think, you have not given vCenter permission to your domain administrator.

As you are able to login to vCenter through web client using domain controller, I assume you have already added your active directory as identity source . Now login using "administrator@vsphere.local" & give admin permission to the domain administrator account user for managing your vCenter, once permission are given, log out from administrator@vsphere.local   & login using domain admin acc. It should work now.

You can refer this blog post for the same:vSphere 5.5 how to add domain users to SSO | VirtuallyLG


----------------------------------------------------------------
Thanks & Regards
Vikas, VCP70, MCTS on AD, SCJP6.0, VCF, vSphere with Tanzu specialist.
https://vThinkBeyondVM.com/about
-----------------------------------------------------------------
Disclaimer: Any views or opinions expressed here are strictly my own. I am solely responsible for all content published here. Content published here is not read, reviewed or approved in advance by VMware and does not necessarily represent or reflect the views or opinions of VMware.

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

Hi Vicky,

Thanks for replying but this is not working. I removed the permissions and added them as per the article you mentioned but no go

0 Kudos
a_p_
Leadership
Leadership

That's rather unusual. I've done this many times and never had any issues. Please post a screenshot which shows the permissions on the vCenter Server object as well as one for the Edit Permissions window for the Domain Admin (user/group ?).

André

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

Hi Andre,

here are the screen shots

administrator_at_home.local.pngadministrator_at_vsphere.local.png

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

Hi Andre,

pastedImage_0.png

my test domain is home.local >>>> when I choose home and added administrator (user) ///  administrators (group) I was unable to login

but when I added the administrators group from the local machine of VC i.e. vc02.home.local >>> then I logged in as home\administrator I was able to see the VC

I am unable to understand this

0 Kudos
a_p_
Leadership
Leadership

According to the screenshot with the empty inventory, you were logged in as the local admin "administrator@vc02" rather than domain admin "administrator@home.local"!?

André

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

Andre if I try logging in as home\administrator -- then also it shows as logged in administrator@vc02

0 Kudos
a_p_
Leadership
Leadership

Can't tell you why at the moment. However, is it the same when you logon using "administrator@home.local"?

André

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

check this video Andre -- you know the issue

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

Andre I checked and found that I need to add local admin account of the VC server as Administrator

and then I am able to login from domain admin account

0 Kudos
a_p_
Leadership
Leadership

I read it, but I can't believe it Smiley Wink

Did you try to login entering "administrator@home.local" rather than "HOME\Administrator" yet?

Also - to rule identity source issues - please ensure that the local and domain administrator have different passwords for this test. This way you should receive an error if the Web clinet tries to login as the local admin even though you entered the domain admin credentials.

I still think that - for whatever reasons - you are not logged in as the domain admin.

André

0 Kudos
lvaibhavt
Hot Shot
Hot Shot

Andre -- the issue seems to be fixed now

I removed the AD integrated identity source and added again as ldap

things are working fine

0 Kudos