nerdexam
Broadcom-VMware

2V0-621 · Question #113

An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for…

The correct answer is B. Install the vSphere Web Client Integration browser plug-in on each workstation from where a user C. The users must be signed into Windows using Active Directory user accounts. D. The administrator must create a valid Identity Source in Single Sign-On for the users domain. Windows session authentication in the vSphere Web Client requires client-side plug-in installation, Active Directory domain membership, and a configured SSO Identity Source to enable seamless pass-through authentication.

Section 1 – Configure and Administer vSphere 6.x Security

Question

An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for this feature to be available and functional? (Choose three.)

Options

  • AInstall the vSphere Web Client Integration browser plug-in on the vCenter Server and Platform
  • BInstall the vSphere Web Client Integration browser plug-in on each workstation from where a user
  • CThe users must be signed into Windows using Active Directory user accounts.
  • DThe administrator must create a valid Identity Source in Single Sign-On for the users domain.
  • EThe administrator must create a valid Single Sign-On Identity Source using Integrated Windows

How the community answered

(66 responses)
  • A
    12% (8)
  • B
    71% (47)
  • E
    17% (11)

Why each option

Windows session authentication in the vSphere Web Client requires client-side plug-in installation, Active Directory domain membership, and a configured SSO Identity Source to enable seamless pass-through authentication.

AInstall the vSphere Web Client Integration browser plug-in on the vCenter Server and Platform

The Client Integration Plug-in is a client-side browser extension installed on end-user workstations, not on the vCenter Server or Platform Services Controller appliance.

BInstall the vSphere Web Client Integration browser plug-in on each workstation from where a userCorrect

The Client Integration Plug-in must be installed on each user workstation because it is the browser extension that intercepts the Kerberos/Windows session token and passes it to the vSphere Web Client for authentication. Without it on the local machine, the checkbox does not appear or function.

CThe users must be signed into Windows using Active Directory user accounts.Correct

Windows session authentication relies on Kerberos tickets issued by Active Directory; if a user is logged in with a local account rather than a domain account, no valid AD credential exists to pass through.

DThe administrator must create a valid Identity Source in Single Sign-On for the users domain.Correct

vCenter Single Sign-On must have an Identity Source configured for the AD domain so it can validate the Kerberos ticket presented by the plug-in and map the user to vCenter roles.

EThe administrator must create a valid Single Sign-On Identity Source using Integrated Windows

While Integrated Windows Authentication is a related concept, the specific requirement for the SSO Identity Source is that it must be valid and mapped to the user domain, making D the correct phrasing; E is either redundant or refers to a different authentication type not required here.

Concept tested: vSphere Web Client Windows session authentication requirements

Source: https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.vcenterhost.doc/GUID-9885D2A0-4A68-4AC6-8AB2-C18CF4EC44B4.html

Topics

#Windows session authentication#SSO#Active Directory#Web Client Integration plugin

Community Discussion

No community discussion yet for this question.

Full 2V0-621 Practice