Academy/VVS/Identity & Access Management
This solution targets VCF 5.2

Identity and Access Management for VMware Cloud Foundation

VCF 5.2architectvcdxautomationPages 30-110

Provides detailed design, implementation, configuration, and operation guidance on use of Active Directory as an identity provider and authentication source, and on use of role-based access control (RBAC) in SDDC Manager, vCenter Server, ESXi, and NSX. Also covers password management, password policies, and account lockout policies across these components.

Key Components: NSX, SDDC Manager, vCenter, ESXi

External dependencies: None (Active Directory and Microsoft CA are external services)

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

26 design decisions

DD-IDDecisionQuality
IAM-VCF-SEC-001Limit use of local accounts for interactive/API access and solution integration.ManageabilitySecurity

Decision: Limit use of local accounts for interactive/API access and solution integration.

Rationale: Local accounts are not specific to user identity and do not offer complete auditing from endpoint back to user identity.

Implication: Administrators must sign in with directory-backed named accounts, and any remaining local-account usage (break-glass) must be documented, monitored, and audited.

Component: VCF

IAM-VCF-SEC-002Limit scope and privileges for accounts used for interactive/API access.ManageabilitySecurity

Decision: Limit scope and privileges for accounts used for interactive/API access.

Rationale: Principle of least privilege is critical for access management and defense-in-depth security.

Implication: Must define and manage custom roles.

Component: VCF

IAM-VCF-SEC-003Assign AD user accounts to security groups per organization's access policies.ManageabilitySecurity

Decision: Assign AD user accounts to security groups per organization's access policies.

Rationale: Allows AD security groups to be assigned to roles for streamlined management.

Implication: Must define/manage security groups, membership, and group lifecycle in Active Directory outside the SDDC stack.

Component: VCF

IAM-VCF-SEC-004Assign AD security groups to default or custom roles for SDDC Manager, ESXi (as applicable), vCenterManageabilitySecurity

Decision: Assign AD security groups to default or custom roles for SDDC Manager, ESXi (as applicable), vCenter Servers, NSX Managers.Group membership provides greater flexibility; unique AD user logins provide

Rationale: Esxi

Implication: Default Access Methods

Component: VCF

IAM-ESXI-SEC-001Configure password expiration policy for each ESXi host.Manageability

Decision: Configure password expiration policy for each ESXi host.

Rationale: Align with org/compliance; applies to root and SERVICE accounts.

Implication: Manage per-host via advanced settings in vSphere Client or Host Client.

Component: ESXI

IAM-ESXI-SEC-002Configure password complexity policy per ESXi host.Manageability

Decision: Configure password complexity policy per ESXi host.

Rationale: Align with org/compliance; applies to local ESXi users only.

Implication: Manage per-host via advanced settings.

Component: ESXI

IAM-ESXI-SEC-003Configure account lockout policy per ESXi host.Manageability

Decision: Configure account lockout policy per ESXi host.

Rationale: Align with org/compliance; local users only.

Implication: Manage per-host via advanced settings.

Component: ESXI

IAM-ESXI-SEC-004Change root user password per ESXi host on recurring/event-initiated schedule via SDDC Manager.Manageability

Decision: Change root user password per ESXi host on recurring/event-initiated schedule via SDDC Manager.

Rationale: ESXi root does not expire by default; SDDC Manager manages each host's root password.

Implication: Manage via SDDC Manager password management; rotation must be coordinated so credentials stored by SDDC Manager stay in sync with each host.

Component: ESXI

IAM-ESXI-SEC-005Rotate SERVICE account password per ESXi host via SDDC Manager.SDDC Manager creates a SERVICE accounManageability

Decision: Rotate SERVICE account password per ESXi host via SDDC Manager.SDDC Manager creates a SERVICE account for SSH access in context of Exception User in normal lockdown mode; doesn't expire by default.Man

Rationale: AD Integration

Implication: Triggering Use CaseNFS 4.1 with Kerberos (krb5 or krb5i) supplemental storage

Component: ESXI

IAM-VCS-SEC-001Configure vCenter to use AD over LDAPS as identity source.Security

Decision: Configure vCenter to use AD over LDAPS as identity source.

Rationale: Encrypted LDAP; Microsoft recommends hardened config with LDAP channel binding and LDAP signing on DCs (Microsoft Security Advisory ADV190023).

Implication: Domain controllers must present CA-signed certificates, and the LDAPS trust must be maintained through certificate rotations or vCenter logins will fail.

Component: VCS

IAM-VCS-SEC-002JustificationImplicationManageabilitySecurity

Decision: JustificationImplication

Rationale: See source document for rationale

Implication: IAM-VCS-SEC-003Assign default Administrator role to an AD security group.Simplifies user access management for administrative rights aligned to personas.AD group must exist; manage group lifecycle in AD.

Component: VCS

IAM-VCS-SEC-003Assign default Administrator role to an AD security group.ManageabilitySecurity

Decision: Assign default Administrator role to an AD security group.

Rationale: Simplifies user access management for administrative rights aligned to personas.

Implication: AD group must exist; manage group lifecycle in AD.

Component: VCS

IAM-VCS-SEC-004Assign vCenter global permissions for AD group with Administrator role.Global permissions span all EManageabilitySecurity

Decision: Assign vCenter global permissions for AD group with Administrator role.Global permissions span all ELM-linked vCenters using same IdP.None.

Rationale: IAM-VCS-SEC-005Assign default Read-Only role to an AD security group.Simplifies read-only user access.Manage AD group lifecycle.

Implication: IAM-VCS-SEC-006Assign vCenter global permissions for AD group with Read-Only role.Global permissions across ELM-linked vCenters.None.

Component: VCS

IAM-VCS-SEC-008Configure global password expiration policy for vCenter.Manageability

Decision: Configure global password expiration policy for vCenter.

Rationale: Align with org/compliance.

Implication: Manage via vSphere Client.

Component: VCS

IAM-VCS-SEC-009Configure local user password expiration policy.Manageability

Decision: Configure local user password expiration policy.

Rationale: Align with org standards; applies to local users only.

Implication: Manage per-instance.

Component: VCS

IAM-VCS-SEC-010Configure local user password complexity policy.Manageability

Decision: Configure local user password complexity policy.

Rationale: Align with compliance.

Implication: Manage per-instance via /etc/pam.d/system-password.

Component: VCS

IAM-VCS-SEC-011Configure local user account lockout policy.Compliance alignment.Manage per-instance via /etc/pam.d/Manageability

Decision: Configure local user account lockout policy.Compliance alignment.Manage per-instance via /etc/pam.d/system-auth.

Rationale: IAM-VCS-SEC-012Configure SSO password expiration policy.Applies to users in vsphere.local IdP (NOT local system accounts or administrator@vsphere.local).Manage per built-in IdP domain.

Implication: IAM-VCS-SEC-013Configure SSO password complexity policy.Applies to vsphere.local IdP accounts.Manage per built-in IdP domain.

Component: VCS

IAM-VCS-SEC-015For each vCenter, rotate the appliance root password on recurring schedule via SDDC Manager.Root pasManageabilitySecurity

Decision: For each vCenter, rotate the appliance root password on recurring schedule via SDDC Manager.Root password expiration tied to policy.Manage through SDDC Manager.

Rationale: IAM-VCS-SEC-016Change the vCenter Single Sign-On administrator@vsphere.local account password on recurring schedule via SDDC Manager.Security hygiene.Manage via SDDC Manager password management.

Implication: IAM-VCS-SEC-017Rotate passwords for each vCenter's service accounts via SDDC Manager.Automated credential rotation.Manage via SDD

Component: VCS

IAM-NSX-SEC-001Configure AD over LDAPS as identity source for NSX Manager.Enables enterprise IdP integration.None.ManageabilitySecurity

Decision: Configure AD over LDAPS as identity source for NSX Manager.Enables enterprise IdP integration.None.

Rationale: IAM-NSX-SEC-002Assign Enterprise Admin role to an AD security group.Simplifies admin role delegation per personas.AD group must exist and be maintained.

Implication: IAM-NSX-SEC-003Assign default Network Engineer role to an AD security group.Delegated network admin access.AD group lifecycle management.

Component: NSX

IAM-NSX-SEC-005Configure password complexity for NSX Manager.Manageability

Decision: Configure password complexity for NSX Manager.

Rationale: Compliance alignment.

Implication: Manage via NSX CLI/API.

Component: NSX

IAM-NSX-SEC-006Configure password complexity policy for NSX Edge nodes.Compliance.Must manage per-Edge settings.Manageability

Decision: Configure password complexity policy for NSX Edge nodes.Compliance.Must manage per-Edge settings.

Rationale: IAM-NSX-SEC-007Configure account lockout policy for NSX.Compliance.Manage via NSX API/CLI.

Implication: IAM-NSX-SEC-008Configure password expiration for NSX Manager.Compliance.Per-manager management.

Component: NSX

IAM-NSX-SEC-011Rotate NSX Manager root, admin, audit passwords via SDDC Manager for VCF-deployed NSX.Manageability

Decision: Rotate NSX Manager root, admin, audit passwords via SDDC Manager for VCF-deployed NSX.

Rationale: Centralized credential lifecycle.

Implication: VCF-managed.

Component: NSX

IAM-NSX-SEC-012Rotate NSX Edge root, admin, audit passwords via SDDC Manager.Manageability

Decision: Rotate NSX Edge root, admin, audit passwords via SDDC Manager.

Rationale: Centralized.

Implication: VCF-managed.

Component: NSX

IAM-NSX-SEC-013Manage NSX Global Manager passwords per VCF guidance.Federation integrity.Manual or VCF-assisted rotManageability

Decision: Manage NSX Global Manager passwords per VCF guidance.Federation integrity.Manual or VCF-assisted rotation.

Rationale: IAM-NSX-SEC-014Rotate NSX Edge cluster passwords per cluster.Cluster-scoped rotation.Manage via SDDC Manager.

Implication: SDDC Manager

Component: NSX

IAM-SDDC-SEC-007Change SDDC Manager appliance root, vcf, backup account passwords on recurring schedule using the apManageabilityPerformanceRecoverability

Decision: Change SDDC Manager appliance root, vcf, backup account passwords on recurring schedule using the appliance shell.

Rationale: UI/API cannot update these; passwords expire based on policy.

Implication: Manage via appliance shell; because the UI/API cannot rotate these accounts, expiry must be tracked operationally to avoid appliance lockout.

Component: SDDC Manager

IAM-SDDC-SEC-008Change local administrative admin@local account password on recurring schedule using the API.admin@lPerformance

Decision: Change local administrative admin@local account password on recurring schedule using the API.admin@local does not expire.Routinely perform change via API.

Rationale: Personas Example

Implication: Persona: Cloud Admin

Component: SDDC Manager

Prerequisites

  • VCF version listed in Support Matrix (5.1.0, 5.1.1, 5.2.0, 5.2.1)
  • Environment configured per Before You Apply This Guidance

Implementation Procedure

Implementation

Captured all parameters for Identity and Access Management tab of VCF Planning and Preparation Workbook

VCF instance healthy and fully operational

  • DNS forward/reverse records for relevant components
  • AD Domain Controllers available
  • Required AD service accounts created
  • Required AD security groups created
  • Microsoft Certificate Authority available
  • OpenSSL 3.0 or later installed on PowerShell host
  • PowerShell 7.2 or later for automation
  • PowerShell Automation
  • Modules
  • VMware.PowerCLI >= 13.2.1
  • VMware.vSphere.SsoAdmin >= 1.3.9
  • ImportExcel >= 7.8.5
  • PowerVCF >= 2.4.0
  • PowerValidatedSolutions >= 2.11.0
  • VMware.CloudFoundation.PasswordManagement >= 1.8.1 (password policies)
  • Workflow
  • Install/import modules; run Test-PowerValidatedSolutionsPrereq to verify
  • Create folder structure (generatedJsons, certificates, binaries, validatedSolutions)
  • Populate VCF Planning and Preparation Workbook (e.g. instanceA-pnpWorkbook.xlsx)

Run Start-ValidatedSolutionMenu with jsonPath/certificatePath/binaryPath/protectedWorkbook/logPath

Menu option 04. (IAM) Identity and Access Management

  • Sub-option 01. Generate JSON Specification File
  • Sub-option 02. Verify Prerequisites
  • Sub-option 03. Request Root Certificate for the Microsoft AD Domain
  • Sub-option 05. End-to-End Deployment

UI Implementation Outline

vCenter: Administration > Single Sign On > Configuration > Identity Sources > Add (Active Directory over LDAP) with LDAPS URI, Base DN for users, Base DN for groups, Bind DN, Bind password, and LDAPS certificate chain

Day-2 Operations Tasks

Operations

As needed

Operational Verification

As needed

vCenter

As needed

Item 1

As needed

Steps

As needed

Log in https://<mgmt_vcenter_fqdn>/ui

As needed

Repeat per vCenter

As needed

Item 2

As needed

Steps

As needed

Log in with AD account assigned role

As needed

Monitoring Points

  • ProcVerify authentication using administrator@vsphere.local
  • Verify ELM active for all vCenters (all instances visible in Hosts & Clusters)
  • ProcVerify authentication using AD user account
  • Verify menu access matches expected role
  • Verify menu access
  • Verify role-appropriate menu access
  • Browse and verify menu access
  • ProcVerify AD LDAP connection
  • Click Check Status on LDAP domain row
  • Verify Status = Success

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

Using AD groups with domain local scope in multi-domain forests — membership lookup failures
Impact:
Mitigation:
Failing to update LDAPS trust when AD DC certs rotate — auth breaks silently
Impact:
Mitigation:
AD outage
Impact:
Mitigation:
Password rotation failures
Impact:
Mitigation:

Trade-off Analysis

Use of vCenter built-in IdP + AD as identity source vs federated external IdP (e.g. ADFS, Okta). Justify: scope of solution limits federation. Trade-off: external IdP offers MFA and SAML but adds comp

Chosen:

Justification:

Multi-instance SSO sharing vs dedicated IdP per instance. Trade-off: ELM scope limits vs isolation for DR / compliance.

Chosen:

Justification:

Trade-Offs Analysis

Chosen:

Justification:

Allowing administrator@vsphere.local to be used for day-to-day ops instead of AD-based admin accounts

Chosen:

Justification:

Quiz — Identity & Access Management

0/15
Q1
Which integration method is used for vCenter Single Sign-On to consume Active Directory as identity source in this validated solution?
  • Active Directory (Integrated Windows Authentication)
  • Active Directory over LDAP with SSL (LDAPS)
  • OpenLDAP
  • SAML 2.0 federation
Solution specifies AD over LDAPS (IAM-VCS-SEC-001) to ensure encrypted LDAP traffic and support Microsoft channel binding/signing hardening.
Q2
Under which condition must ESXi hosts be joined to Active Directory in this design?
  • Always, to enforce AD-based logins
  • Only when using NFS v4.1 with Kerberos supplemental storage
  • Only when Enhanced Linked Mode is active
  • Never, SDDC Manager prohibits it
ESXi hosts are joined to AD only to support NFS 4.1 Kerberos (krb5/krb5i); otherwise SDDC Manager manages their lifecycle without AD.
Q3
What is the default ESXi Security.AccountLockFailures value?
  • 3
  • 5
  • 10
  • 99999
Default is 5; Security.AccountUnlockTime is 900 seconds. DCUI and ESXi Shell do not support account lockout — only SSH and API.
Q4
Which SDDC Manager account does NOT expire by default and must be rotated via API?
  • root
  • vcf
  • backup
  • admin@local
admin@local has no expiry and cannot be changed via UI; SDDC Manager API is used for rotation (IAM-SDDC-SEC-008).
Q5
Which PowerShell module is used specifically for password policy reporting and configuration across VCF?
  • PowerVCF
  • VMware.PowerCLI
  • PowerValidatedSolutions
  • VMware.CloudFoundation.PasswordManagement
VMware.CloudFoundation.PasswordManagement provides Invoke-PasswordPolicyManager and Start-PasswordPolicyConfig cmdlets.
Q6
What happens to ELM if two VCF instances are deployed to separate AD child domains in a multi-domain forest?
  • They can still use ELM with global groups
  • They can use ELM only if Bind DN is in root domain
  • They cannot participate in ELM
  • Only Administrators group works
Per IAM-VCS-SEC-001 implications, instances in separate AD child domains cannot be in enhanced linked-mode.
Q7
Which default vCenter Single Sign-On password complexity minimum length is specified?
  • 6
  • 8
  • 12
  • 14
SSO min length default is 8; max is 20; restrict reuse = 5.
Q8
Which NSX role is assigned to the AD security group dedicated to network administrators in the validated design?
  • Enterprise Admin
  • Network Engineer
  • Auditor
  • Security Operator
IAM-NSX-SEC-003 assigns Network Engineer role for network-scoped admin personas.
Q9
Where is the SSO password expiration policy configured and what is its default Maximum lifetime?
  • Per local user, 90 days
  • Per built-in IdP domain (e.g. vsphere.local), 90 days
  • Per vCenter instance, 365 days
  • Global across ELM, 60 days
SSO password expiration is per built-in IdP domain; default Maximum lifetime is 90 days. Does not apply to local system accounts or administrator@vsphere.local.
Q10
Which account privilege is recommended for the AD join account used when ESXi needs to join AD for NFS 4.1 Kerberos?
  • Domain Admins
  • Account Operators group with Join Computers to Domain delegation
  • Enterprise Admins
  • Schema Admins
Least privilege: Account Operators with delegated 'Join Computers to Domain' permission.
Q11
What is the SDDC Manager default password policy deny (lockout threshold) value?
  • 3
  • 5
  • 10
  • 15
SDDC Manager deny = 3 failures; unlock_time = 86400 seconds (24h); root_unlock_time = 300s.
Q12
Which port is used for LDAPS when integrating AD with NSX Manager?
  • 389
  • 636
  • 3268
  • 3269
LDAPS uses TCP/636.
Q13
Which SDDC Manager role corresponds to the Cloud Admin persona in this design?
  • Viewer
  • Operator
  • Administrator
  • Auditor
Cloud Admin maps to SDDC Manager Administrator, vCenter Administrator, NSX Enterprise Admin, SSO Administrator.
Q14
After AD LDAPS certificate is replaced, which procedure must be performed for NSX Manager trust?
  • Restart NSX Manager
  • Delete and re-create the AD identity source
  • Edit LDAP domain server and paste new certificate, then Apply & Save
  • Run SDDC Manager certificate rotation
NSX Manager trust re-establishment procedure: Edit LDAP > LDAP server > paste new certificate > Add > Apply > Save, for each NSX Local/Global Manager.
Q15
What is Password Remediation used for in SDDC Manager's context?
  • Generating random passwords
  • Synchronizing SDDC Manager inventory with externally-set password and (optionally) rotating it
  • Resetting vCenter SSO administrator password
  • Forcing AD password reset
Password Remediation updates the SDDC Manager inventory with a new password for an account and can trigger rotation; commonly used after expiration or manual reset.

Flashcards — Identity & Access Management

Card 1 of 15
Decision IAM-VCS-SEC-001
Configure vCenter instances to use AD over LDAPS as identity source — encrypts LDAP, follows Microsoft ADV190023 hardening; implication: multi-child-domain forests lose ELM across instances.

Labs

Lab 1: Configure AD over LDAPS as IdP for vCenter and Assign Role to AD Security Group

Configure vCenter SSO to use AD over LDAPS and assign an AD group to the Administrator role with global permissions.

Starting State: VCF 5.2 management domain operational; AD DCs with LDAPS CA-signed certificate available; AD security group gg-vc-admins created; administrator@vsphere.local access.

Lab 2: Configure Password Policy and Detect Drift Across VCF Using PowerShell

Generate baseline password policy JSON, modify to match org standards, run drift report, apply changes.

Starting State: Windows/Linux workstation with PowerShell 7.2+, VMware.PowerCLI, PowerVCF, PowerValidatedSolutions, VMware.CloudFoundation.PasswordManagement installed; SDDC Manager accessible.

Lab 3: Authentication Transition — Migrate NSX from Workspace ONE Access to AD over LDAP

Reconfigure NSX to use AD over LDAP natively, removing Workspace ONE Access integration, and reassigning roles.

Starting State: VCF with NSX configured to use standalone Workspace ONE Access as authentication provider; AD security groups gg-nsx-enterprise-admins, gg-nsx-network-admins, gg-nsx-auditors exist.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.