---
name: vmwaresolutions-vrw-iam-active-directory
title: Active Directory
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2025-10-24
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Active Directory
{: #vrw-iam-active-directory}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

**End of Marketing**: As of 31 October 2025, new deployments of VMware Solutions offerings are no longer available for new customers. Existing customers can still use and expand their active VMware® workloads on IBM Cloud&reg;. For more information, see [End of Marketing for VMware on IBM Cloud](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-eos-vms&format=markdown).
{: note}

Microsoft® Active Directory™ serves to authenticate access to manage the VMware® instance only and not to house SaaS consumer users of the workloads in the deployed instances. The forest root domain name of the Active Directory server equals to the Domain Name Services (DNS) domain name that you specify for the initial instance deployment.

Domain name services (DNS) in this design are for the cloud management and infrastructure components only. The DNS zone files are also replicated on the Active Directory servers.

## Active Directory groups and users
{: #vrw-iam-active-directory-account}

The Regulated Workloads Active Directory is used for the privileged administrators, service accounts, and the IBM Cloud for VMware Solutions `automation` service ID.

### Microsoft Active Directory user IDs
{: #vrw-iam-active-directory-account-users}

| User     | User ID       | Description |
|:---------|:------------- |:------------|
| IBM automation     | `automation`    | Used to add a host or a virtual machine for service. Also, to set up Active Directory and DNS entries |
| Privileged user | `Administrator` | Default Windows® user |
| Privileged user | `cloudadmin`    | Default user for the customer to access vCenter Server |
| Nonprivileged | `cloudreadonly` | Read-only account for the customer |
{: caption="Active Directory user IDs" caption-side="bottom"}

### Microsoft Active Directory groups
{: #vrw-iam-active-directory-account-groups}

| User     | User ID       | Description |
|:---------|:------------- |:------------|
| IBM automation or privileged users | `IC4v-vCenter` | vCenter Administration Group |
{: caption="Active Directory groups" caption-side="bottom"}

## Related links
{: #vrw-iam-active-directory-related}

* [IBM Cloud compliance programs](https://www.ibm.com/products/cloud/compliance){: external}
* [IBM Cloud Hyper Protect Crypto Services API](https://cloud.ibm.com/apidocs/hs-crypto)