Aria Operations Active Directory authentication is configured but it's not seeing any users when attempting to grant access to a Active Directory user / Group
search cancel

Aria Operations Active Directory authentication is configured but it's not seeing any users when attempting to grant access to a Active Directory user / Group

book

Article ID: 374500

calendar_today

Updated On:

Products

VMware Aria Operations 8.x VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

An active directory source is configured in Administration > Control Panel > Authentication Sources.
Under Administration > Control Panel > Access Control the expected active directory users or groups do not show under the "User Accounts" tab or the "User Groups" tab.

Environment

VMware Cloud Foundation (VCF) Operations 8.18.0

Cause

Active Directory users and groups are not automatically visible after configuring the authentication source because they must be explicitly imported from the source. In multi-vCenter environments, this issue can also occur if the domain account lacks root-level permissions or if Propagate to children is disabled within vCenter Server global permissions.

Resolution

To import users or groups and ensure proper visibility:

  1. Log in to the VCF Operations UI with administrative privileges.
  2. Navigate to Administration > Access Control.
  3. Select the User Accounts or User Groups tab.
  4. Click Import from Source.
  5. Select the Basic tab.
  6. Choose the appropriate Authentication Source from the drop-down menu.
  7. Search for the desired user or group.
  8. Select the account from the list and click Finish.
  9. If inventory objects remain invisible for these accounts, verify that the corresponding vCenter roles are standardized and that Propagate to children is enabled under Administration > Access Control > Global Permissions in the vCenter Server.

Within a few minutes, the group should show up in the "User Groups" tab, and the users in that group should show up in the "User Accounts" tab.

Now roles can be associated with the desired users or groups.