With SDDC Manager, you can schedule password rotation automatically for some of the managed components. You set the password rotation interval to a period shorter than the period in your password expiration policy.

To avoid password expiry before the automated rotation triggers, ensure that the next password rotation occurs between the last modified date and the password expiration date.

If your environment has more than one VMware Cloud Foundation instance joined to a single vCenter Single Sign-On domain, do not schedule password rotation for the [email protected] account. For manual rotation in such cases, see VMware Knowledge Base artcle 85485.

You can configure a password rotation schedule for the following products:

Product

Account

vCenter Server

  • root

vCenter Single Sign-On

For VMware Cloud Foundation 5.1 and later:
For VMware Cloud Foundation 5.0 and earlier:

NSX Local Manager

  • admin

  • root

  • audit

NSX Edge Nodes

  • root

  • admin

  • audit

Note:

Auto rotate is automatically enabled for vCenter Server. It may take up to 24 hours to configure the auto-rotate policy for a newly deployed vCenter Server.

Procedure

VMware Cloud Foundation 4.5 or later
  1. Log in to SDDC Manager at https://<sddc_manager_fqdn> with a user assigned the Admin role.
  2. In the left pane, click Security > Password management.

  3. On the Password management page, from the components list, select the component.

  4. In the table, select the check box for the root accounts.

  5. From the Schedule rotation drop-down menu, select the rotation interval.

  6. In the Confirm changes dialog box, click Yes.

  7. Repeat the procedure for the remaining accounts.

  8. Repeat the procedure for the remaining products.

VMware Cloud Foundation 4.4 or earlier
  1. Log in to SDDC Manager at https://<sddc_manager_fqdn> with a user assigned the Admin role.
  2. In the left pane, click Administration > Security > Password management.

  3. From the Component drop-down menu, select the component.

  4. Select all root accounts and, from the Schedule rotation drop-down menu, select the rotation interval.

  5. In the Confirm changes dialog box, click Yes.

  6. Repeat the procedure for the remaining accounts.

  7. Repeat the procedure for the remaining components.