User retains access to VCF Operations after removal from Active Directory group when a member of multiple synced groups.
search cancel

User retains access to VCF Operations after removal from Active Directory group when a member of multiple synced groups.

book

Article ID: 440865

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

A user retains access to VMware Cloud Foundation (VCF) Operations after being removed from an Active Directory (AD) group that grants them access. This specifically occurs if the user is a member of two or more AD groups synced with VMware Identity Broker (VIDB), and only one of those groups has an assigned role in VCF Operations.

If a user is in both a privileged group and an unprivileged group, removing them from the privileged group and performing a VIDB sync will still allow the user to log in.

Environment

  • VCF Operations 9.0.x
  • VMware Identity Broker 9.0.x

Cause

This is expected behavior due to caching. VCF Operations caches users and groups locally to optimize performance, rather than querying the VIDB in real-time for every authentication request. By default, the local cache of users and groups is only updated every 30 minutes.

Resolution

To resolve this issue and immediately revoke access, manually synchronize the authentication source using one of the following methods:

Method 1: Staggered Sync

  1. Delete the user from the AD group (for example, the group providing the Administrator role and All access scope).
  2. Wait 3 to 5 minutes to allow backend propagation.
  3. Initiate a VIDB sync.

Method 2: Manual Authentication Source Sync in Operations

  1. Initiate a VIDB sync.
  2. Log in to VCF Operations.
  3. Navigate to Authentication Sources.
  4. Manually synchronize the VCF SSO authentication source to immediately refresh the local cache.