After migrating the identity source from Integrated Windows Authentication (IWA) to Active Directory (AD) over LDAP, users are unable to log in to vCenter Server when permissions are assigned via AD groups. Individual user accounts with direct permissions function correctly, but group-based authorization results in a permission error. This issue typically appears in multi-domain forests where groups and users reside in different child domains.
Configure the identity source to traverse the Active Directory forest.
[email protected].DC=ege,DC=ds) to ensure global lookup.