Ensure that the user is added to one of the groups which has been synced and is displayed in the VCF Operations UI, Fleet Management >> Identity & Access >> VCF Instance >> Identity Source (Edit) >> Group Provisioning
Login to each component (vCenter / NSX) with the local admin account and assign the necessary service roles to the provisioned users and groups as per Configure VCF Single Sign-On for NSX and vCenter