An active directory source is configured in Administration > Control Panel > Authentication Sources.
Under Administration > Control Panel > Access Control the expected active directory users or groups do not show under the "User Accounts" tab or the "User Groups" tab.
VMware Cloud Foundation (VCF) Operations 8.18.0
Active Directory users and groups are not automatically visible after configuring the authentication source because they must be explicitly imported from the source. In multi-vCenter environments, this issue can also occur if the domain account lacks root-level permissions or if Propagate to children is disabled within vCenter Server global permissions.
To import users or groups and ensure proper visibility:
Within a few minutes, the group should show up in the "User Groups" tab, and the users in that group should show up in the "User Accounts" tab.
Now roles can be associated with the desired users or groups.