In VMware Identity Manager, Active Directory synchronization stops functioning. As a result, users are unable to log in or authenticate to the environment.
VMware Identity Manager 3.3.7
Active Directory over IWA
A change to the Active Directory environment implementing Channel Binding Token (CBT) enforcement (also known as "LDAP sealing") causes corruption in the existing directory configuration.
To resolve this issue, delete and recreate the directory configuration.
Log in to the VMware Identity Manager administration console.
Navigate to the Directories configuration section.
Delete the existing Active Directory over IWA directory.
Recreate the directory using the Active Directory over IWA configuration.
Initiate a directory synchronization to verify the connection is restored.