Domain user log in to NSX portal fails when logging in using vIDM
search cancel

Domain user log in to NSX portal fails when logging in using vIDM

book

Article ID: 399066

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • When attempting to log in to NSX Portal using 'Sign in with viDM' option, for certain newly added users into a AD group, the portal, keeps bouncing back and forth between NSX and vIDM post successful login rather than opening the NSX user / admin console. 
  • vIDM Authentication configuration on NSX UI using local admin users is successful and the vIDM status is marked as green. Validation is successful. 
  • Same user is unable to login to vIDM.

Environment

VMware NSX 4.x

VMware Identity manager 3.x

Cause

  • Broken / Un-updated directory sync on the vIDM associated as auth provider for the NSX.  
  • The new users would not be synced due to un-updated / broken sync for the respective AD. 
  • The directory sync on vIDM may fail due to various reasons. 

Resolution

  • Validate the AD sync settings in vIDM Administrator Portal > Directory Management > AD > validate all values and click save.
  • Re-run the directory sync for the AD on vIDM, ensure the group containing the users is covered.
  • Once successful, validate if the new users are listed in vIDM Administrator Portal > users and groups pane.
  • Validate the user is now able to log in to the vIDM portal successfully.
  • Once validated on vIDM, head over to the vIDM configurations on the NSX portal and click on Refresh.
  • Once refresh completes successfully, attempt to log in to the NSX portal using the user.