From reading http://kb.vmware.com/kb/2037546 it looks like I need to have a service account with specific AD permissions for my AD to be used as an identity source for SSO but can anyone tell me the absolute (minimum) permissions it needs as the article just says "the service account must have sufficient permissions to read the properties and attributes of any user which you intend to have login capabilities in vSphere".
↧