Users attempting to log in with a domain account to Aria Automation encounters 403 error if they have not been granted a role in Identity and Access Management (IAM).
This issue occurs within environments where Aria Automation is integrated with vIDM (VMware Identity Manager) configured to use LDAP as a source.
Access attempts are made via the Aria automation UI hosted at https://your_Aria_Automation_FQDN
VMware Aria Automation 8.x
The error occurs when a user lacks the necessary organization or service roles in Identity and Access Management (IAM). This is common after modifying vIDM directories or following environment synchronization issues, which can reset or clear user role mappings in the Aria Automation database.
To resolve this issue, follow these steps:
When logging in to Aria Automation for the first time or after configuration changes, make sure to select the "System Domain" when prompted by vIDM. This ensures that initial administrative access is granted correctly.
Use the configuration administrator credentials noted in Aria Suite Lifecycle (vRealize Suite Lifecycle Manager) under globalenvironment to log in initially. This user should have sufficient privileges to configure roles and permissions within Aria Automation for users.
Navigate to Identity and Access Management (IAM) within Aria Automation. Assign the appropriate roles to users from vIDM Workspace One.
Ensure that users are assigned organization roles (Organization Owner, Organization Member), service roles (Cloud Assembly Administrator/User/Viewer, Service Broker Administrator/User/Viewer, Code Stream Administrator/User/Viewer), and project roles as needed.