The Identity and Access Management for VMware Cloud Foundation validated solution has objectives to deliver prescriptive content about the solution so that it is fast to deploy and is suitable for use in production environments.



Main objective

Provide role-based access control for VMware Cloud Foundation infrastructure components through an organization's directory services as the authentication source.

VMware Cloud Foundation architecture support

  • vSAN ReadyNodes

    • Consolidated

    • Standard

  • Dell VxRail Nodes

    • Consolidated

    • Standard

Workload domain type support

  • Management Workload domain

  • VI Workload domain

Scope of implementation

  • Configuration of role based access control for VMware Cloud Foundation components:

    • ESXi

    • vCenter Server

    • NSX

    • SDDC Manager

Scope of guidance

  • Deployment and initial configuration of identity access and management components for management and VI workload domains.

  • Operational guidance for the identity access and management components such as operational and post-maintenance validation.

  • Solution interoperability with solution components, such as monitoring and alerting, logging, and life cycle management.

Cloud type

Private cloud



Authentication, authorization, and access control

  • Use of Microsoft Active Directory over LDAP as the identity provider.

  • Use of security groups and roles for least-privilege access control.

  • Use of service accounts and least-privilege access control for solution integration.

Support for other external identity providers is not in included in this solution.

Certificate signing

Certificates are signed by a certificate authority (CA) that consists of a root and intermediate certificate authority layers.