2V0-622 · Question #113
An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for this
The correct answer is B. Install the vSphere Web Client Integration browser plug-in on each workstation from where a user C. The users must be signed into Windows using Active Directory user accounts. D. The administrator must create a valid Identity Source in Single Sign-On for the users domain.. Windows session authentication in vSphere Web Client requires client-side plug-in installation, Active Directory login, and a configured SSO Identity Source.
Question
An administrator wants to allow users to login to the vSphere Web Client using the Use Windows session authentication check box for faster authentication. Which three requirements must be met for this feature to be available and functional? (Choose three.)
Options
- AInstall the vSphere Web Client Integration browser plug-in on the vCenter Server and Platform
- BInstall the vSphere Web Client Integration browser plug-in on each workstation from where a user
- CThe users must be signed into Windows using Active Directory user accounts.
- DThe administrator must create a valid Identity Source in Single Sign-On for the users domain.
- EThe administrator must create a valid Single Sign-On Identity Source using Integrated Windows
How the community answered
(40 responses)- A20% (8)
- B73% (29)
- E8% (3)
Why each option
Windows session authentication in vSphere Web Client requires client-side plug-in installation, Active Directory login, and a configured SSO Identity Source.
The Client Integration plug-in is installed on each client workstation, not on the vCenter Server or Platform Services Controller - installing it server-side has no effect on enabling the feature for end users.
The Client Integration plug-in must be installed on each user's workstation because it provides the browser-level hook that captures the current Windows Kerberos token and passes it to vCenter for authentication. Without it on the local machine, the 'Use Windows session authentication' checkbox is not available in the browser. This is a per-client requirement, not a server-side installation.
The feature relies on pass-through of the currently active Windows session credentials, so the user must be authenticated to Windows via an Active Directory domain account - local accounts cannot be forwarded to vCenter SSO.
vCenter SSO must have a valid Identity Source configured for the user's AD domain so it can validate the forwarded Kerberos credentials against a known directory service.
This option rephrases the Identity Source requirement already covered by D; configuring a standard AD Identity Source in SSO is sufficient and 'Integrated Windows Authentication' as a separate distinct step is not a separate requirement.
Concept tested: vSphere Web Client Windows session authentication requirements
Source: https://docs.vmware.com/en/VMware-vSphere/6.5/com.vmware.vsphere.authentication.doc/GUID-1F01B02C-E4D3-4B73-95C3-93C5CF5D2C2D.html
Topics
Community Discussion
No community discussion yet for this question.