2V0-621 · Question #113
An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for…
The correct answer is B. Install the vSphere Web Client Integration browser plug-in on each workstation from where a user C. The users must be signed into Windows using Active Directory user accounts. D. The administrator must create a valid Identity Source in Single Sign-On for the users domain. Windows session authentication in the vSphere Web Client requires client-side plug-in installation, Active Directory domain membership, and a configured SSO Identity Source to enable seamless pass-through authentication.
Question
An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for this feature to be available and functional? (Choose three.)
Options
- AInstall the vSphere Web Client Integration browser plug-in on the vCenter Server and Platform
- BInstall the vSphere Web Client Integration browser plug-in on each workstation from where a user
- CThe users must be signed into Windows using Active Directory user accounts.
- DThe administrator must create a valid Identity Source in Single Sign-On for the users domain.
- EThe administrator must create a valid Single Sign-On Identity Source using Integrated Windows
How the community answered
(66 responses)- A12% (8)
- B71% (47)
- E17% (11)
Why each option
Windows session authentication in the vSphere Web Client requires client-side plug-in installation, Active Directory domain membership, and a configured SSO Identity Source to enable seamless pass-through authentication.
The Client Integration Plug-in is a client-side browser extension installed on end-user workstations, not on the vCenter Server or Platform Services Controller appliance.
The Client Integration Plug-in must be installed on each user workstation because it is the browser extension that intercepts the Kerberos/Windows session token and passes it to the vSphere Web Client for authentication. Without it on the local machine, the checkbox does not appear or function.
Windows session authentication relies on Kerberos tickets issued by Active Directory; if a user is logged in with a local account rather than a domain account, no valid AD credential exists to pass through.
vCenter Single Sign-On must have an Identity Source configured for the AD domain so it can validate the Kerberos ticket presented by the plug-in and map the user to vCenter roles.
While Integrated Windows Authentication is a related concept, the specific requirement for the SSO Identity Source is that it must be valid and mapped to the user domain, making D the correct phrasing; E is either redundant or refers to a different authentication type not required here.
Concept tested: vSphere Web Client Windows session authentication requirements
Source: https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.vcenterhost.doc/GUID-9885D2A0-4A68-4AC6-8AB2-C18CF4EC44B4.html
Topics
Community Discussion
No community discussion yet for this question.