Unable to see VMware Cloud Director sites in multisite configuration when the user inherit the role from the imported SAML group
book
Article ID: 370144
calendar_today
Updated On:
Products
VMware Cloud Director
Issue/Introduction
After configuring VMware Cloud Director sites in multisite the user with System Admin role is not able to see the information for both sites.
The user with System Admin role is part of a group and the role is applied at group level
When disabling "Inherit roles from group" at user level, the multisite configuration works as expected.
Microsoft Entra ID (formerly Azure Active Directory) is used as Identity Provider.
Environment
VMware Cloud Director 10.5.x
Cause
Default "Groups" attribute name it is still used when populating the multisite user info response instead of getting the configured value like we do for role.
Resolution
This issue is resolved in VMware Cloud Director 10.6, available at Broadcom Downloads.
If you are unable to upgrade, please see the workaround below.
Workaround
Edit the attribute on the Azure Identity Provider in "Name = “Groups” " (with capitol G).