<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSO - Moving user to another OU breaks SSO in VMware vCenter™ Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670082#M36197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi All&lt;/STRONG&gt; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO, I think that u can use CN=OU_Name,DC=domain,DC=com and that OU contains all of vCenter admins and users in ur enviroment..&lt;BR /&gt;I never tested that, but I think it goes levels down..I.e. if u have another OU inside, its users will be contained..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Jul 2013 09:51:36 GMT</pubDate>
    <dc:creator>ShadyMalatawey</dc:creator>
    <dc:date>2013-07-18T09:51:36Z</dc:date>
    <item>
      <title>SSO - Moving user to another OU breaks SSO</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670080#M36195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have been using vCenter 5.1 with SSO for about 6 months now without issues.&amp;nbsp; Today though I have been testing some new GPO changes I need to make and realized my users were still in the default Users folder in AD so I can't applied user GPOs to them.&amp;nbsp; Not a biggy so I created a new OU and moved myself into a new Admin AU and created a test user into a new users OU, and so far all seemed fine, until i tried to log into my vSphere Client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when I logon with Windows Credentials I can't connect as it says incorrect user or password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I look at the SSO settings for my Active Directory Identity Source I realized its because I have pointed it to the CN=Users,DC=mydomain,DC=local but the users I just moved out now don't work.&amp;nbsp; So my question is, do i need to create another identity source for my new OU and for each one so have multiple Identity Sources for CN=Admins,DC=mydomain,DC=local and CN=NewUsers,DC=mydomain,DC=local or would I be better of just going with something like DC=mydomain,DC=local for the BaseDN in a single identity source?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if I created a OUs below OUs does the SSO identity source go down multiple levels yeah?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jul 2013 23:33:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670080#M36195</guid>
      <dc:creator>AndyR8939</dc:creator>
      <dc:date>2013-07-17T23:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Moving user to another OU breaks SSO</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670081#M36196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For my setup, i use &lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;DC=mydomain,DC=com and it works&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Girish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 04:34:13 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670081#M36196</guid>
      <dc:creator>raog</dc:creator>
      <dc:date>2013-07-18T04:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Moving user to another OU breaks SSO</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670082#M36197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi All&lt;/STRONG&gt; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO, I think that u can use CN=OU_Name,DC=domain,DC=com and that OU contains all of vCenter admins and users in ur enviroment..&lt;BR /&gt;I never tested that, but I think it goes levels down..I.e. if u have another OU inside, its users will be contained..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 09:51:36 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670082#M36197</guid>
      <dc:creator>ShadyMalatawey</dc:creator>
      <dc:date>2013-07-18T09:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSO - Moving user to another OU breaks SSO</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670083#M36198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks both.&amp;nbsp; I'll probably set it up like roag said and just point it to &lt;STRONG&gt;&lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #333333;"&gt;DC=mydomain,DC=com&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #333333;"&gt; because I don't need to control access at the SSO level more than that, because vCenter access is all controlled by AD groups on there anyway, so it'll make it easier have it referencing my whole domain anyway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #333333;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;Thanks guys!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 20:23:32 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/SSO-Moving-user-to-another-OU-breaks-SSO/m-p/2670083#M36198</guid>
      <dc:creator>AndyR8939</dc:creator>
      <dc:date>2013-07-18T20:23:32Z</dc:date>
    </item>
  </channel>
</rss>

