You don't have permissions to access the HCX system or too many active sessions. Try again after sometime./common/logs/admin/web.log on the HCX Manager appliance during requests targeting /hybridity/ap/sessions reveals authentication failures referencing SYSTEM-DOMAIN:Caused by: org.springframework.security.access.AccessDeniedException: Could not assign NSP role based on logged in VCenter user group memberships ["SYSTEM-DOMAIN\\ComponentManager.Administrators", "SYSTEM-DOMAIN\\LicenseService.Administrators", "SYSTEM-DOMAIN\\SystemConfiguration.ReadOnly", "SYSTEM-DOMAIN\\HCX Administrators", "SYSTEM-DOMAIN\\SystemConfiguration.SupportUsers", "SYSTEM-DOMAIN\\__Administrators__", "SYSTEM-DOMAIN\\Everyone", "SYSTEM-DOMAIN\\CAAdmins", "SYSTEM-DOMAIN\\SystemConfiguration.Administrators", "SYSTEM-DOMAIN\\SystemConfiguration.BashShellAdministrators", "SYSTEM-DOMAIN\\__Support_Assistant_Operators__", "SYSTEM-DOMAIN\\Users"].vsphere.local are present.VMware vCenter Server: 8.x
VMware HCX
This issue occurs due to leftover legacy SSO artifacts remaining in the vCenter Directory Service (VMDIR).
During historical vSphere upgrades (such as migrating from legacy SSO in vSphere 5.1 using SYSTEM-DOMAIN to modern SSO in vSphere 5.5 and above using vsphere.local), obsolete SYSTEM-DOMAIN entries may persist. When HCX attempts to validate user sessions via /hybridity/ap/sessions, the presence of these legacy artifacts disrupts Single Sign-On domain resolution.
To resolve this issue, perform the following steps:
Verify Identity Sources:
Confirm that both SYSTEM-DOMAIN and vsphere.local exist in your Single Sign-On domain list within the vSphere Client.
Remove 'SYSTEM-DOMAIN' references from Identity Provider
Validate Access: