Thursday 29 December 2016

How to unlock and reset SSO administrator password in vSphere 6.x

Coming back from vacation to office most of us forget the password :).....

What we see is "User account is locked. Please contact your administrator".

So here we go how to reset SSO administrator password.


 Unlock the account using another session that is still logged into the PSC server or using another user account with SSO administrator privileges.


  1. Click Home.
  2. Click Administration.
  3. Click Single Sign-On > Users and Groups.
  4. Click the Users tab.
  5. Right-click the affected user account,  "YOURLOCKEDACCOUNT"@vsphere.local, and click Unlock.
To reset the administrator@vsphere.local password:

On a Windows Platform Services Controller or vCenter Server with Embedded Platform Services Controller:
  1. Log in to vCenter Server with a domain administrator account. If the Platform Services Controller is installed separate from vCenter Server, log in to the Platform Services Controller server.
  2. Open an elevated command prompt.
  3. Run c:\> "%VMWARE_CIS_HOME%\vmdird\vdcadmintool.exe".

    This console loads:

    ===============================
    Please select:
    0. exit
    1. Test LDAP connectivity
    2. Force start replication cycle
    3. Reset account password
    4. Set log level and mask
    5. Set vmdir state
    ===============================
  4. Press 3 to enter the Reset account password option.
  5. When prompted for the Account UPN, enter:

    Administrator@vSphere_Domain_Name.localBy default, this is:

    Administrator@vSphere.localA new password is generated.

    Notes:
    • If you customized your vSphere Domain name, provide the customized domain name.
    • If the prededing steps fail with a domain administrator account, use a local administrator account.
  6. Use the generated password to log in to the administrator@vSphere.local account.
  7. After the password is regenerated, log in to vSphere Web Client and change the password.




1 comment: