VMware Cloud Community
CoryIT
Enthusiast
Enthusiast

Set password expiry to never for individual accounts

Hello,

Is there a way to set specific account passwords to never expire in vCenter 6.5 U1?

We have two accounts we created for Microsoft Azure Backup server, but as they expire periodically, it keeps breaking our backups.

We don't want to set the policy to never expire, only specific accounts.

Cheers

Eds

0 Kudos
7 Replies
daphnissov
Immortal
Immortal

And you're asking about SSO local accounts here?

0 Kudos
CoryIT
Enthusiast
Enthusiast

Sorry, yes, these are local @vsphere.local accounts.

Cheers

Eds

0 Kudos
msripada
Virtuoso
Virtuoso

Check this KB VMware Knowledge Base

Thanks,

MS

0 Kudos
daphnissov
Immortal
Immortal

That's going to set all the SSO local accounts for unlimited expiry, msripada​. OP is looking for selective accounts with unlimited password expiration.

OP, any reason you're not using an external account with this solution (which you can control better) rather than an SSO local account?

0 Kudos
CoryIT
Enthusiast
Enthusiast

We are purely going by the Microsoft deployment guide for Azure Backup Server and Azure Site Recovery, and this is how it suggests to create accounts for use with these services.

Here is the guide we are following: https://docs.microsoft.com/en-us/azure/backup/backup-azure-backup-server-vmware

Is it possible (easier) then, to simply add a user from our AD, assign it to this role, and try to use these creds in these products?

Surprised MS don't suggest that during deployment since they develop AD lol

Cheers

Eds

0 Kudos
daphnissov
Immortal
Immortal

Yeah, there's nothing there that prohibits the use of an external (Active Directory) user principle in the place of an SSO account. I suspect they did that because, 1) they aren't very familiar with VMware and 2) it was quicker to produce the walk-through. I'd recommend using an external account which you can control to your liking in an external identity source such as your on-prem AD environment. The rest of the article applies as far as assigning a role with appropriate permissions.

0 Kudos
CoryIT
Enthusiast
Enthusiast

Perfect thanks, we will try switching to an AD account.

Cheers

Eds

0 Kudos