Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

VCSA join to Active directory

Posted on 2016-07-27
10
Medium Priority
?
144 Views
Last Modified: 2016-07-28
How do you join a VCSA to ADS...

And what is the difference of an identity source compared to joining to the domain?

We will need an identity source as domain.local    and joined to somedomain.com

Does that make since?
0
Comment
Question by:Indyrb
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 123

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 41731885
an identity source can be internal, local server or Active Directory domain.

you will need to follow the steps in this web link

http://www.virten.net/2015/02/how-to-add-ad-authentication-in-vcenter-6-0-platform-service-controller/

Are you using vCenter 6.0 ?
0
 
LVL 42

Assisted Solution

by:Adam Brown
Adam Brown earned 500 total points
ID: 41731975
Adding the vCSA to the domain makes it a domain member, which allows it to directly communicate with Domain Controllers for authentication using Kerberos. Kerberos is significantly more secure than doing password hashing comparisons at login, which is what happens when you use AD as an Identity Source. Essentially, the difference is in the type of security used to authenticate users at login. Using AD as an Identity Source means that there are more methods for cracking authentication than if it were a domain member. Both methods are probably secure enough for the vast majority of environments (Kerberos would be preferable in, say, a very high security environment).

TL;DR: Functionally, they both do more or less the same thing. They allow you to log in with AD usernames and passwords. The difference is in *how* they do it.
0
 
LVL 12

Accepted Solution

by:
Mr Tortur earned 1000 total points
ID: 41732953
Hi,
to configure AD users in SSO and vsphere, you need to add you domain as an identity source in SSO.
To do that you need to join your vCSA to your AD first.

To join vCSA to your domain, log in to the Web vsphere 6 client with full rights, meaning e.g. administrator@vsphere.local then go to  Administration / Deployment-System configuration / nodes / select your vcenter / manage tab / settings / advanced / Active directory / Join !

Proper dns server must be set before.
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 4

Author Comment

by:Indyrb
ID: 41733185
ty
0
 
LVL 4

Author Comment

by:Indyrb
ID: 41733187
The version is 6.0

Is there a difference with version 6 compared to 5.5
0
 
LVL 12

Assisted Solution

by:Mr Tortur
Mr Tortur earned 1000 total points
ID: 41733215
0
 
LVL 4

Author Comment

by:Indyrb
ID: 41733231
I mean adding to Domains...
0
 
LVL 4

Author Comment

by:Indyrb
ID: 41733234
Does version 6.0 "VCSA" add  to ADS domain same way version 5.5
0
 
LVL 123

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 41733266
Correct.
0
 
LVL 12

Assisted Solution

by:Mr Tortur
Mr Tortur earned 1000 total points
ID: 41733294
yes exactly the same way
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question