VMware VCSA 6.5 Permissions and Active Directory Groups Not Working
I recently deployed VCSA 6.5U2 with embedded PSC and selected Active Directory (Windows Integrated Authentication) as the identity source.
All the required steps were carried out, joining the VCSA to Active Directory, rebooting the VCSA then adding the AD identity source with using the machine SPN.
I could successfully query and add users and group from Active Directory and added the security group used for VCSA administration and granted the Administrator role in Global Permissions section. The mentioned security group is a standard AD Global Security group with users in that group. I then logged into VCSA with an account from that group. Everything was working fine. I could login and had full administrative rights in VCSA.
I then started populating the roles and permissions from the various user AD security groups granting the different teams in the organisation the appropriate permissions in VCSA.
However, the users reported the following error when trying to login.
Tried multiple things to troubleshoot including rebooting the VCSA, granting Administrator rights, adding the group to Global Permissions, creating a new group in AD, but none of those fixed the issue.
I checked the vCenter vpxd logs as well as the PSC logs and found that the user was being authenticated correctly and found in Active Directory but it seems that the user’s group membership could not be enumerated to link the user to the group which was granted permissions.
Finally, I changed the identity source from Active Directory (Windows Integrated Authentication) to Active Directory over LDAP which fixed the issue.
The only reason that I could think of was maybe the Active Directory I was using was still on Windows 2003 functional level and VCSA was making a query that AD could not support.
Let me know in the comments if you had similar issues and your experiences.