VMware ESXi and vSphere Cluster Management
Add an ESXi Host to vCenter Server Inventory
Learn how to create a vCenter datacenter and add a standalone ESXi host through the vSphere Web Client, including trust, licensing, lockdown mode, and verification.
Adding an ESXi host to vCenter Server registers the host in a centrally managed vSphere inventory. This lets administrators organize hosts, apply policies, and use capabilities such as vSphere High Availability and Fault Tolerance when the required cluster, storage, networking, and licensing conditions are met.
This lesson uses the graphical vSphere Web Client workflow. It assumes that vCenter Server is running, the ESXi host is reachable on its management network, and you have suitable permissions and valid ESXi root credentials.
Why Add an ESXi Host to vCenter Server?
An ESXi host is a bare-metal hypervisor that runs virtual machines. It can be administered directly through its host management interface, but direct administration manages that host largely in isolation.
vCenter Server is the centralized VMware management platform used to organize and manage ESXi hosts and other vSphere resources. After a host is added to vCenter inventory, administrators can manage it alongside other hosts and place it into larger structures such as clusters.
- Direct ESXi administration is useful for initial configuration, diagnostics, and recovery.
- vCenter administration provides centralized inventory, permissions, monitoring, licensing, and policy management.
- Features such as High Availability and Fault Tolerance depend on the appropriate vCenter-managed configuration and are not provided merely by administering an isolated host.
Prerequisites
- A running vCenter Server instance and access to its vSphere Web Client.
- A running ESXi host with a reachable management network.
- The ESXi management FQDN or management IP address. An FQDN is a fully qualified domain name that identifies a host through DNS.
- Valid credentials for the ESXi local root account.
- A vCenter account with permissions to create inventory objects and add hosts.
- Basic familiarity with IP addresses, DNS, and the vSphere inventory hierarchy.
Understand the vCenter Inventory Structure
The vCenter inventory is a hierarchy of managed objects. A datacenter object is a top-level logical container used to organize vSphere resources such as hosts, clusters, virtual machines, networks, and datastores.
At least one datacenter object must exist before an ESXi host can be added. The datacenter selected when the wizard starts becomes the host's initial inventory destination.
The relevant inventory view is Hosts and Clusters. In the described interface, navigate through:
Home > vCenter > Hosts and Clusters
Exact menu names and screen layouts can vary between vCenter versions, but the Hosts and Clusters view remains the place to create datacenters and manage host placement.
Create a Datacenter
- Sign in to the vCenter Server vSphere Web Client using a vCenter account with the required permissions.
- Open Hosts and Clusters.
- Select the vCenter Server or the appropriate inventory root.
- Choose the command to create a new datacenter.
- Enter a meaningful name, such as
Production-Site-AorLab-Datacenter. - Confirm the operation and verify that the new datacenter appears in the inventory tree.
Use names that describe the site, environment, or administrative boundary. Consistent naming becomes increasingly useful when multiple datacenters and clusters are present.
Open the Add Host Workflow
- Remain in the Hosts and Clusters view.
- Select the target datacenter object.
- Open its context menu.
- Select Add Host.
The selected datacenter determines where vCenter initially places the ESXi host. Starting the workflow from the wrong object can result in an unexpected inventory location, so confirm the selection before continuing.
Enter ESXi Host Connection Details
When prompted, provide the ESXi host's management identity and local administrative credentials.
- Enter the ESXi management FQDN or management IP address.
- Enter the local ESXi username, normally
rootfor this initial registration workflow. - Enter the ESXi root account password.
- Continue to allow vCenter to contact the host.
Use a management address that is reachable from vCenter Server. If you enter a hostname, verify that DNS resolves the FQDN to the intended management address. The vCenter administrator account used to sign in to the Web Client is separate from the ESXi root account used to authenticate to the host.
Verify Host Authenticity
On the first connection, vCenter may display a host authenticity, certificate, or security prompt. This occurs because vCenter is establishing trust with the ESXi host.
- Review the host name, address, certificate information, or other identity details shown by the prompt.
- Compare them with your intended ESXi host and known management information.
- Accept the trust prompt only when you have verified that the system is the correct host.
Review Detected Host Information
After authentication, the wizard displays a summary of information discovered from the ESXi host. Review the host identity and configuration before proceeding.
- Confirm the host name and management address.
- Verify that the hardware and ESXi installation correspond to the intended system.
- Check that the discovered host is not a different lab, test, or production machine.
- Stop and correct the connection details if the summary does not match your records.
Assign a License
The wizard may provide a license assignment step. Depending on your environment, choose an available existing license or enter and assign an appropriate new license key.
- Existing license: Select a compatible license already available in vCenter.
- New license key: Enter or add the key according to the client prompts, then assign it to the host.
Verify licensing during onboarding rather than postponing the check. The assigned edition and entitlement affect which host and vSphere capabilities are available. Licensing requirements can also affect later cluster, High Availability, Fault Tolerance, and management decisions.
Choose a Lockdown Mode Setting
Lockdown mode is an ESXi access-control setting that restricts direct management access after the host is enrolled in vCenter. With lockdown mode enabled, routine management is intended to occur through vCenter Server or, depending on the configuration, through the host's local console.
Enable Lockdown Mode When
- Security policy requires administrators to manage hosts centrally.
- Direct connections to the ESXi management interface should be limited.
- Administrators have confirmed that vCenter access works correctly.
- Appropriate console or recovery access is available for emergencies.
Leave Lockdown Mode Disabled When
- The environment still requires controlled direct host administration.
- Operational procedures for vCenter-based management are not complete.
- Recovery access has not been tested or documented.
Enabling lockdown mode improves control over direct access but can make troubleshooting and recovery more dependent on vCenter or console access. Make the decision according to security requirements and operational readiness.
Choose the Virtual Machine Location
The wizard asks where the host's virtual machines should be represented in the vCenter inventory. Select the applicable datacenter or another offered location within the selected inventory structure.
The host, its virtual machines, and related resources must be organized consistently. The datacenter selected for the host determines the inventory context in which administrators find and manage it. If the wrong location is selected, the host may appear under an unexpected datacenter and be harder to administer according to your organization’s structure.
Review and Complete the Wizard
- Review the final summary, including the host address, credentials context, license choice, lockdown mode, and inventory location.
- Correct any value that does not match the intended design.
- Select Finish or Ready to Complete, depending on the client version.
- Wait for the task to finish and watch for errors in the Recent Tasks or task pane.
Verify the Host Addition
- Expand the selected datacenter in Hosts and Clusters.
- Locate the newly added ESXi host beneath the datacenter.
- Confirm that the host status is Connected and that it is available for vCenter-managed operations.
- Review the host summary and check for license, certificate, network, storage, or configuration alarms.
For example, an administrator might create a datacenter named Production-Site-A, add the intended host by its management FQDN, confirm the identity prompt, enable lockdown mode after validating recovery access, and then expand the datacenter to verify that the host is listed and connected.
Add Host Wizard Inputs and Decisions
| Wizard stage | Required input or decision | What to verify | Operational impact |
|---|---|---|---|
| Host name or IP address | ESXi management FQDN or IP address | The address is reachable and identifies the intended host | Determines which ESXi system vCenter contacts |
| ESXi root credentials | Local root username and password | Credentials belong to the ESXi host, not vCenter | Allows initial authentication and registration |
| Host trust confirmation | Accept the certificate or authenticity prompt after verification | Host identity and certificate details are expected | Establishes trust between vCenter and ESXi |
| Host summary | Review discovered identity and configuration | Hardware, ESXi installation, and host name are correct | Prevents onboarding the wrong system |
| License assignment | Choose an available license or assign a new key | Edition and entitlement meet operational requirements | Controls available licensed capabilities |
| Lockdown mode | Enable or leave disabled | Security policy and recovery procedures support the choice | Changes how direct ESXi management access is controlled |
| Virtual machine location | Select the applicable datacenter or inventory location | Placement matches the intended site and organization | Controls where the host and its VMs are shown in inventory |
| Ready to Complete review | Confirm all settings and finish | No address, license, security, or placement errors remain | Commits the host registration task |
Credential and Access Roles
| Credential or access method | Used for | Not interchangeable with |
|---|---|---|
| vCenter administrator account | Signing in to vCenter and performing inventory operations | ESXi root credentials |
| ESXi root account | Authenticating directly to the ESXi host during initial registration | vCenter administrator credentials |
| Host console access | Local or recovery administration, especially when lockdown mode limits direct access | Normal vCenter Web Client authentication |
Troubleshooting
Add Host Is Unavailable
There may be no suitable datacenter, the current view may not be Hosts and Clusters, or the wrong inventory object may be selected. Create or select the target datacenter, open its context menu, and start Add Host from there.
vCenter Cannot Connect When a Hostname Is Used
Check the spelling of the FQDN, verify DNS resolution from the vCenter environment, and confirm management-network reachability. If appropriate, use the correct ESXi management IP address instead of the hostname, while preserving correct host identity and DNS configuration.
Authentication Fails
Confirm the ESXi root username and password. A common mistake is entering the vCenter sign-in account instead of the local ESXi root account.
A Certificate or Host Authenticity Warning Appears
This can be normal during the first trust connection, but the host identity must still be verified. Check the presented name, address, and certificate details before accepting the prompt.
The Host Was Added but Cannot Be Managed as Expected
Check whether the host is under the intended datacenter, review the configured lockdown mode, and inspect license assignment. If direct access is restricted, use vCenter or the authorized host console according to the security design.
Key Exam and Operations Notes
- A datacenter object must exist before a host can be added to vCenter inventory.
- The Add Host workflow is started from the target datacenter in Hosts and Clusters.
- The host connection uses the ESXi management FQDN or IP address and local ESXi root credentials.
- vCenter administrator credentials and ESXi root credentials serve different purposes.
- Accept a host trust prompt only after verifying the host identity.
- License assignment and lockdown mode are separate onboarding decisions with operational consequences.
- Successful completion is confirmed by finding the host beneath the intended datacenter with a Connected status.
For additional context, review communication between vCenter Server and ESXi, basic ESXi configuration, and vSphere High Availability admission control.