Identity and Access Management for VMware Cloud Foundation
Provides detailed design, implementation, configuration, and operation guidance on use of Active Directory as an identity provider and authentication source, and on use of role-based access control (RBAC) in SDDC Manager, vCenter Server, ESXi, and NSX. Also covers password management, password policies, and account lockout policies across these components.
Key Components: NSX, SDDC Manager, vCenter, ESXi
External dependencies: None (Active Directory and Microsoft CA are external services)
26 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| IAM-VCF-SEC-001 | Limit use of local accounts for interactive/API access and solution integration. | ManageabilitySecurity |
Decision: Limit use of local accounts for interactive/API access and solution integration. Rationale: Local accounts are not specific to user identity and do not offer complete auditing from endpoint back to user identity. Implication: Administrators must sign in with directory-backed named accounts, and any remaining local-account usage (break-glass) must be documented, monitored, and audited. Component: VCF | ||
| IAM-VCF-SEC-002 | Limit scope and privileges for accounts used for interactive/API access. | ManageabilitySecurity |
Decision: Limit scope and privileges for accounts used for interactive/API access. Rationale: Principle of least privilege is critical for access management and defense-in-depth security. Implication: Must define and manage custom roles. Component: VCF | ||
| IAM-VCF-SEC-003 | Assign AD user accounts to security groups per organization's access policies. | ManageabilitySecurity |
Decision: Assign AD user accounts to security groups per organization's access policies. Rationale: Allows AD security groups to be assigned to roles for streamlined management. Implication: Must define/manage security groups, membership, and group lifecycle in Active Directory outside the SDDC stack. Component: VCF | ||
| IAM-VCF-SEC-004 | Assign AD security groups to default or custom roles for SDDC Manager, ESXi (as applicable), vCenter | ManageabilitySecurity |
Decision: Assign AD security groups to default or custom roles for SDDC Manager, ESXi (as applicable), vCenter Servers, NSX Managers.Group membership provides greater flexibility; unique AD user logins provide Rationale: Esxi Implication: Default Access Methods Component: VCF | ||
| IAM-ESXI-SEC-001 | Configure password expiration policy for each ESXi host. | Manageability |
Decision: Configure password expiration policy for each ESXi host. Rationale: Align with org/compliance; applies to root and SERVICE accounts. Implication: Manage per-host via advanced settings in vSphere Client or Host Client. Component: ESXI | ||
| IAM-ESXI-SEC-002 | Configure password complexity policy per ESXi host. | Manageability |
Decision: Configure password complexity policy per ESXi host. Rationale: Align with org/compliance; applies to local ESXi users only. Implication: Manage per-host via advanced settings. Component: ESXI | ||
| IAM-ESXI-SEC-003 | Configure account lockout policy per ESXi host. | Manageability |
Decision: Configure account lockout policy per ESXi host. Rationale: Align with org/compliance; local users only. Implication: Manage per-host via advanced settings. Component: ESXI | ||
| IAM-ESXI-SEC-004 | Change root user password per ESXi host on recurring/event-initiated schedule via SDDC Manager. | Manageability |
Decision: Change root user password per ESXi host on recurring/event-initiated schedule via SDDC Manager. Rationale: ESXi root does not expire by default; SDDC Manager manages each host's root password. Implication: Manage via SDDC Manager password management; rotation must be coordinated so credentials stored by SDDC Manager stay in sync with each host. Component: ESXI | ||
| IAM-ESXI-SEC-005 | Rotate SERVICE account password per ESXi host via SDDC Manager.SDDC Manager creates a SERVICE accoun | Manageability |
Decision: Rotate SERVICE account password per ESXi host via SDDC Manager.SDDC Manager creates a SERVICE account for SSH access in context of Exception User in normal lockdown mode; doesn't expire by default.Man Rationale: AD Integration Implication: Triggering Use CaseNFS 4.1 with Kerberos (krb5 or krb5i) supplemental storage Component: ESXI | ||
| IAM-VCS-SEC-001 | Configure vCenter to use AD over LDAPS as identity source. | Security |
Decision: Configure vCenter to use AD over LDAPS as identity source. Rationale: Encrypted LDAP; Microsoft recommends hardened config with LDAP channel binding and LDAP signing on DCs (Microsoft Security Advisory ADV190023). Implication: Domain controllers must present CA-signed certificates, and the LDAPS trust must be maintained through certificate rotations or vCenter logins will fail. Component: VCS | ||
| IAM-VCS-SEC-002 | JustificationImplication | ManageabilitySecurity |
Decision: JustificationImplication Rationale: See source document for rationale Implication: IAM-VCS-SEC-003Assign default Administrator role to an AD security group.Simplifies user access management for administrative rights aligned to personas.AD group must exist; manage group lifecycle in AD. Component: VCS | ||
| IAM-VCS-SEC-003 | Assign default Administrator role to an AD security group. | ManageabilitySecurity |
Decision: Assign default Administrator role to an AD security group. Rationale: Simplifies user access management for administrative rights aligned to personas. Implication: AD group must exist; manage group lifecycle in AD. Component: VCS | ||
| IAM-VCS-SEC-004 | Assign vCenter global permissions for AD group with Administrator role.Global permissions span all E | ManageabilitySecurity |
Decision: Assign vCenter global permissions for AD group with Administrator role.Global permissions span all ELM-linked vCenters using same IdP.None. Rationale: IAM-VCS-SEC-005Assign default Read-Only role to an AD security group.Simplifies read-only user access.Manage AD group lifecycle. Implication: IAM-VCS-SEC-006Assign vCenter global permissions for AD group with Read-Only role.Global permissions across ELM-linked vCenters.None. Component: VCS | ||
| IAM-VCS-SEC-008 | Configure global password expiration policy for vCenter. | Manageability |
Decision: Configure global password expiration policy for vCenter. Rationale: Align with org/compliance. Implication: Manage via vSphere Client. Component: VCS | ||
| IAM-VCS-SEC-009 | Configure local user password expiration policy. | Manageability |
Decision: Configure local user password expiration policy. Rationale: Align with org standards; applies to local users only. Implication: Manage per-instance. Component: VCS | ||
| IAM-VCS-SEC-010 | Configure local user password complexity policy. | Manageability |
Decision: Configure local user password complexity policy. Rationale: Align with compliance. Implication: Manage per-instance via /etc/pam.d/system-password. Component: VCS | ||
| IAM-VCS-SEC-011 | Configure local user account lockout policy.Compliance alignment.Manage per-instance via /etc/pam.d/ | Manageability |
Decision: Configure local user account lockout policy.Compliance alignment.Manage per-instance via /etc/pam.d/system-auth. Rationale: IAM-VCS-SEC-012Configure SSO password expiration policy.Applies to users in vsphere.local IdP (NOT local system accounts or administrator@vsphere.local).Manage per built-in IdP domain. Implication: IAM-VCS-SEC-013Configure SSO password complexity policy.Applies to vsphere.local IdP accounts.Manage per built-in IdP domain. Component: VCS | ||
| IAM-VCS-SEC-015 | For each vCenter, rotate the appliance root password on recurring schedule via SDDC Manager.Root pas | ManageabilitySecurity |
Decision: For each vCenter, rotate the appliance root password on recurring schedule via SDDC Manager.Root password expiration tied to policy.Manage through SDDC Manager. Rationale: IAM-VCS-SEC-016Change the vCenter Single Sign-On administrator@vsphere.local account password on recurring schedule via SDDC Manager.Security hygiene.Manage via SDDC Manager password management. Implication: IAM-VCS-SEC-017Rotate passwords for each vCenter's service accounts via SDDC Manager.Automated credential rotation.Manage via SDD Component: VCS | ||
| IAM-NSX-SEC-001 | Configure AD over LDAPS as identity source for NSX Manager.Enables enterprise IdP integration.None. | ManageabilitySecurity |
Decision: Configure AD over LDAPS as identity source for NSX Manager.Enables enterprise IdP integration.None. Rationale: IAM-NSX-SEC-002Assign Enterprise Admin role to an AD security group.Simplifies admin role delegation per personas.AD group must exist and be maintained. Implication: IAM-NSX-SEC-003Assign default Network Engineer role to an AD security group.Delegated network admin access.AD group lifecycle management. Component: NSX | ||
| IAM-NSX-SEC-005 | Configure password complexity for NSX Manager. | Manageability |
Decision: Configure password complexity for NSX Manager. Rationale: Compliance alignment. Implication: Manage via NSX CLI/API. Component: NSX | ||
| IAM-NSX-SEC-006 | Configure password complexity policy for NSX Edge nodes.Compliance.Must manage per-Edge settings. | Manageability |
Decision: Configure password complexity policy for NSX Edge nodes.Compliance.Must manage per-Edge settings. Rationale: IAM-NSX-SEC-007Configure account lockout policy for NSX.Compliance.Manage via NSX API/CLI. Implication: IAM-NSX-SEC-008Configure password expiration for NSX Manager.Compliance.Per-manager management. Component: NSX | ||
| IAM-NSX-SEC-011 | Rotate NSX Manager root, admin, audit passwords via SDDC Manager for VCF-deployed NSX. | Manageability |
Decision: Rotate NSX Manager root, admin, audit passwords via SDDC Manager for VCF-deployed NSX. Rationale: Centralized credential lifecycle. Implication: VCF-managed. Component: NSX | ||
| IAM-NSX-SEC-012 | Rotate NSX Edge root, admin, audit passwords via SDDC Manager. | Manageability |
Decision: Rotate NSX Edge root, admin, audit passwords via SDDC Manager. Rationale: Centralized. Implication: VCF-managed. Component: NSX | ||
| IAM-NSX-SEC-013 | Manage NSX Global Manager passwords per VCF guidance.Federation integrity.Manual or VCF-assisted rot | Manageability |
Decision: Manage NSX Global Manager passwords per VCF guidance.Federation integrity.Manual or VCF-assisted rotation. Rationale: IAM-NSX-SEC-014Rotate NSX Edge cluster passwords per cluster.Cluster-scoped rotation.Manage via SDDC Manager. Implication: SDDC Manager Component: NSX | ||
| IAM-SDDC-SEC-007 | Change SDDC Manager appliance root, vcf, backup account passwords on recurring schedule using the ap | ManageabilityPerformanceRecoverability |
Decision: Change SDDC Manager appliance root, vcf, backup account passwords on recurring schedule using the appliance shell. Rationale: UI/API cannot update these; passwords expire based on policy. Implication: Manage via appliance shell; because the UI/API cannot rotate these accounts, expiry must be tracked operationally to avoid appliance lockout. Component: SDDC Manager | ||
| IAM-SDDC-SEC-008 | Change local administrative admin@local account password on recurring schedule using the API.admin@l | Performance |
Decision: Change local administrative admin@local account password on recurring schedule using the API.admin@local does not expire.Routinely perform change via API. Rationale: Personas Example Implication: Persona: Cloud Admin Component: SDDC Manager | ||
Prerequisites
- VCF version listed in Support Matrix (5.1.0, 5.1.1, 5.2.0, 5.2.1)
- Environment configured per Before You Apply This Guidance
Implementation Procedure
Implementation
Captured all parameters for Identity and Access Management tab of VCF Planning and Preparation Workbook
VCF instance healthy and fully operational
- DNS forward/reverse records for relevant components
- AD Domain Controllers available
- Required AD service accounts created
- Required AD security groups created
- Microsoft Certificate Authority available
- OpenSSL 3.0 or later installed on PowerShell host
- PowerShell 7.2 or later for automation
- PowerShell Automation
- Modules
- VMware.PowerCLI >= 13.2.1
- VMware.vSphere.SsoAdmin >= 1.3.9
- ImportExcel >= 7.8.5
- PowerVCF >= 2.4.0
- PowerValidatedSolutions >= 2.11.0
- VMware.CloudFoundation.PasswordManagement >= 1.8.1 (password policies)
- Workflow
- Install/import modules; run Test-PowerValidatedSolutionsPrereq to verify
- Create folder structure (generatedJsons, certificates, binaries, validatedSolutions)
- Populate VCF Planning and Preparation Workbook (e.g. instanceA-pnpWorkbook.xlsx)
Run Start-ValidatedSolutionMenu with jsonPath/certificatePath/binaryPath/protectedWorkbook/logPath
Menu option 04. (IAM) Identity and Access Management
- Sub-option 01. Generate JSON Specification File
- Sub-option 02. Verify Prerequisites
- Sub-option 03. Request Root Certificate for the Microsoft AD Domain
- Sub-option 05. End-to-End Deployment
UI Implementation Outline
vCenter: Administration > Single Sign On > Configuration > Identity Sources > Add (Active Directory over LDAP) with LDAPS URI, Base DN for users, Base DN for groups, Bind DN, Bind password, and LDAPS certificate chain
Day-2 Operations Tasks
Operations
As neededOperational Verification
As neededvCenter
As neededItem 1
As neededSteps
As neededLog in https://<mgmt_vcenter_fqdn>/ui
As neededRepeat per vCenter
As neededItem 2
As neededSteps
As neededLog in with AD account assigned role
As neededMonitoring Points
- ProcVerify authentication using administrator@vsphere.local
- Verify ELM active for all vCenters (all instances visible in Hosts & Clusters)
- ProcVerify authentication using AD user account
- Verify menu access matches expected role
- Verify menu access
- Verify role-appropriate menu access
- Browse and verify menu access
- ProcVerify AD LDAP connection
- Click Check Status on LDAP domain row
- Verify Status = Success
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Use of vCenter built-in IdP + AD as identity source vs federated external IdP (e.g. ADFS, Okta). Justify: scope of solution limits federation. Trade-off: external IdP offers MFA and SAML but adds comp
Chosen:
Justification:
Multi-instance SSO sharing vs dedicated IdP per instance. Trade-off: ELM scope limits vs isolation for DR / compliance.
Chosen:
Justification:
Trade-Offs Analysis
Chosen:
Justification:
Allowing administrator@vsphere.local to be used for day-to-day ops instead of AD-based admin accounts
Chosen:
Justification:
Quiz — Identity & Access Management
- Active Directory (Integrated Windows Authentication)
- Active Directory over LDAP with SSL (LDAPS)
- OpenLDAP
- SAML 2.0 federation
- Always, to enforce AD-based logins
- Only when using NFS v4.1 with Kerberos supplemental storage
- Only when Enhanced Linked Mode is active
- Never, SDDC Manager prohibits it
- 3
- 5
- 10
- 99999
- root
- vcf
- backup
- admin@local
- PowerVCF
- VMware.PowerCLI
- PowerValidatedSolutions
- VMware.CloudFoundation.PasswordManagement
- They can still use ELM with global groups
- They can use ELM only if Bind DN is in root domain
- They cannot participate in ELM
- Only Administrators group works
- 6
- 8
- 12
- 14
- Enterprise Admin
- Network Engineer
- Auditor
- Security Operator
- Per local user, 90 days
- Per built-in IdP domain (e.g. vsphere.local), 90 days
- Per vCenter instance, 365 days
- Global across ELM, 60 days
- Domain Admins
- Account Operators group with Join Computers to Domain delegation
- Enterprise Admins
- Schema Admins
- 3
- 5
- 10
- 15
- 389
- 636
- 3268
- 3269
- Viewer
- Operator
- Administrator
- Auditor
- Restart NSX Manager
- Delete and re-create the AD identity source
- Edit LDAP domain server and paste new certificate, then Apply & Save
- Run SDDC Manager certificate rotation
- Generating random passwords
- Synchronizing SDDC Manager inventory with externally-set password and (optionally) rotating it
- Resetting vCenter SSO administrator password
- Forcing AD password reset
Flashcards — Identity & Access Management
Labs
Lab 1: Configure AD over LDAPS as IdP for vCenter and Assign Role to AD Security Group
Configure vCenter SSO to use AD over LDAPS and assign an AD group to the Administrator role with global permissions.
Starting State: VCF 5.2 management domain operational; AD DCs with LDAPS CA-signed certificate available; AD security group gg-vc-admins created; administrator@vsphere.local access.
Lab 2: Configure Password Policy and Detect Drift Across VCF Using PowerShell
Generate baseline password policy JSON, modify to match org standards, run drift report, apply changes.
Starting State: Windows/Linux workstation with PowerShell 7.2+, VMware.PowerCLI, PowerVCF, PowerValidatedSolutions, VMware.CloudFoundation.PasswordManagement installed; SDDC Manager accessible.
Lab 3: Authentication Transition — Migrate NSX from Workspace ONE Access to AD over LDAP
Reconfigure NSX to use AD over LDAP natively, removing Workspace ONE Access integration, and reassigning roles.
Starting State: VCF with NSX configured to use standalone Workspace ONE Access as authentication provider; AD security groups gg-nsx-enterprise-admins, gg-nsx-network-admins, gg-nsx-auditors exist.