A user retains access to VMware Cloud Foundation (VCF) Operations after being removed from an Active Directory (AD) group that grants them access. This specifically occurs if the user is a member of two or more AD groups synced with VMware Identity Broker (VIDB), and only one of those groups has an assigned role in VCF Operations.
If a user is in both a privileged group and an unprivileged group, removing them from the privileged group and performing a VIDB sync will still allow the user to log in.
This is expected behavior due to caching. VCF Operations caches users and groups locally to optimize performance, rather than querying the VIDB in real-time for every authentication request. By default, the local cache of users and groups is only updated every 30 minutes.
To resolve this issue and immediately revoke access, manually synchronize the authentication source using one of the following methods:
Administrator role and All access scope).Authentication Sources.