Unable to see VMware Cloud Director sites in multisite configuration when the user inherit the role from the imported SAML group
search cancel

Unable to see VMware Cloud Director sites in multisite configuration when the user inherit the role from the imported SAML group

book

Article ID: 370144

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

  • After configuring VMware Cloud Director sites in multisite the user with System Admin role is not able to see the information for both sites.
  • The user with System Admin role is part of a group and the role is applied at group level
  • When disabling "Inherit roles from group" at user level, the multisite configuration works as expected.
  • Microsoft Entra ID (formerly Azure Active Directory) is used as Identity Provider.

Environment

VMware Cloud Director 10.5.x

Cause

Default "Groups" attribute name it is still used when populating the multisite user info response instead of getting the configured value like we do for role.

Resolution

This issue is resolved in VMware Cloud Director 10.6, available at Broadcom Downloads.

If you are unable to upgrade, please see the workaround below.

Workaround

Edit the attribute on the Azure Identity Provider in "Name = “Groups” " (with capitol G).