You can add a domain to vSphere Authentication using the camconfig command.

You can add a domain to vSphere Authentication Proxy only after you enable the proxy. After you add the domain, vSphere Authentication Proxy adds all hosts that you provision with Auto Deploy to that domain. For other hosts, you can also use vSphere Authentication Proxy if you do not want to give those hosts domain privileges.


  1. Log in to the vCenter Server system as a user with administrator privileges.
  2. Run the command to enable access to the Bash shell.
  3. Go to the /usr/lib/vmware-vmcam/bin/ directory where the camconfig script is located.
  4. To add the domain and user Active Directory credentials to the Authentication Proxy configuration, run the following command.
    camconfig add-domain -d domain -u user

    You are prompted for a password.

    vSphere Authentication Proxy caches that user name and password. You can remove and recreate the user as needed. The domain must be reachable through DNS, but does not have to be a vCenter Single Sign-On identity source.

    vSphere Authentication Proxy uses the user name specified by user to create the accounts for ESXi hosts in Active Directory. The user must have privileges to create accounts in the Active Directory domain to which you are adding the hosts. At the time of writing of this information, the Microsoft Knowledge Base article 932455 had background information for account creation privileges.

  5. If you later want to remove the domain and user information from vSphere Authentication Proxy, run the following command.
    camconfig remove-domain -d domain