nerdexam
Broadcom-VMware

2V0-622 · Question #113

An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for this

The correct answer is B. Install the vSphere Web Client Integration browser plug-in on each workstation from where a user C. The users must be signed into Windows using Active Directory user accounts. D. The administrator must create a valid Identity Source in Single Sign-On for the users domain.. Windows session authentication in vSphere Web Client requires client-side plug-in installation, Active Directory login, and a configured SSO Identity Source.

Section 1 – Configure and Administer vSphere 6.5 Security

Question

An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for this feature to be available and functional? (Choose three.)

Options

  • AInstall the vSphere Web Client Integration browser plug-in on the vCenter Server and Platform
  • BInstall the vSphere Web Client Integration browser plug-in on each workstation from where a user
  • CThe users must be signed into Windows using Active Directory user accounts.
  • DThe administrator must create a valid Identity Source in Single Sign-On for the users domain.
  • EThe administrator must create a valid Single Sign-On Identity Source using Integrated Windows

How the community answered

(40 responses)
  • A
    20% (8)
  • B
    73% (29)
  • E
    8% (3)

Why each option

Windows session authentication in vSphere Web Client requires client-side plug-in installation, Active Directory login, and a configured SSO Identity Source.

AInstall the vSphere Web Client Integration browser plug-in on the vCenter Server and Platform

The Client Integration plug-in is installed on each client workstation, not on the vCenter Server or Platform Services Controller - installing it server-side has no effect on enabling the feature for end users.

BInstall the vSphere Web Client Integration browser plug-in on each workstation from where a userCorrect

The Client Integration plug-in must be installed on each user's workstation because it provides the browser-level hook that captures the current Windows Kerberos token and passes it to vCenter for authentication. Without it on the local machine, the 'Use Windows session authentication' checkbox is not available in the browser. This is a per-client requirement, not a server-side installation.

CThe users must be signed into Windows using Active Directory user accounts.Correct

The feature relies on pass-through of the currently active Windows session credentials, so the user must be authenticated to Windows via an Active Directory domain account - local accounts cannot be forwarded to vCenter SSO.

DThe administrator must create a valid Identity Source in Single Sign-On for the users domain.Correct

vCenter SSO must have a valid Identity Source configured for the user's AD domain so it can validate the forwarded Kerberos credentials against a known directory service.

EThe administrator must create a valid Single Sign-On Identity Source using Integrated Windows

This option rephrases the Identity Source requirement already covered by D; configuring a standard AD Identity Source in SSO is sufficient and 'Integrated Windows Authentication' as a separate distinct step is not a separate requirement.

Concept tested: vSphere Web Client Windows session authentication requirements

Source: https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.authentication.doc/GUID-1F01B02C-E4D3-4B73-95C3-93C5CF5D2C2D.html

Topics

#Windows session authentication#SSO#Identity Source#Active Directory

Community Discussion

No community discussion yet for this question.

Full 2V0-622 Practice