Symptoms:
VMware Cloud Director
During the SAML login flow, vCloud Director attempts to determine whether the authenticated user has been imported directly or at least one group to which the user belongs has been imported into the target Organization.
The above error condition occurs when the Organization Administrator has neither imported the SAML user directly with a role nor have they imported at least one SAML group to which the user belongs into the target Organization, which is a requirement.
Follow steps from the Enable Your Organization to Use a SAML Identity Provider section of the vCloud Director documentation to configure SAML authentication.
Import the desired users and groups using the steps outlined in the Managing Users, Groups and Roles section of the vCloud Director documentation.
Note: If the same user has different usernames, for example username or username@vcd.example.com, the username with which the SAML login is carried out should be imported with a role assigned to it. Alternatively a group where the correct username is present should be imported into vCloud Director prior to login.