Symptoms
The user account does not have enough privilege to perform this operation.
/storage/log/vcops/log/vcfops-bridge.log:YYYY-MM-DDTHH:MM:SS INFO vcfops-bridge #### [ops@4413 threadId="####"] [com.vmware.vcops.bridge.server.vidb.vcf.VCFInstanceHelper.isVcSupportedVcVersion] - Normalized vc version: 9.0.2.0.########
YYYY-MM-DDTHH:MM:SS WARN vcfops-bridge #### [ops@4413 threadId="####"] [com.vmware.vcops.bridge.server.vidb.api.impl.IdentityProviderApi.getIdpByVidbResourceId] - Failed to get VIDB for ####. IDP deleted or does not exist/storage/log/vcops/log/adapters/ManagementAdapter/ManagementAdapter.log:YYYY-MM-DDTHH:MM:SS ERROR ManagementAdapter #### [ops@4413 threadId="####"] [(####) com.vmware.adapter.management.components.licensing.vcf.E.C.A] - Unable to find the user privileges: [Global.Licenses]
YYYY-MM-DDTHH:MM:SS ERROR ManagementAdapter #### [ops@4413 threadId="####"] [(####) com.vmware.adapter.management.components.licensing.vcf.G.A.C] - The configured User account for the VC endpoint #### is missing the required permission Global.Licenses. License collection will not be performed.The service account configured for the VCF Instance Adapter in VCF Operations lacks the mandatory Global.Licenses privilege.
VCF Operations 9.x requires this privilege to synchronize identity metadata. Without it, the adapter cannot validate the licensing state, causing the Fleet Management API to reject LDAP configuration requests as USER_UNAUTHORIZED.
To resolve the permission sync issue in existing deployments, repair the VCF Adapter integration using the steps below.
Administration > Integrations.administrator@domain.local).Validate Connection, accept any certificates, and click Save.Collecting.Identity & Access > VCF Instances.Identity Broker (embedded) deployment mode.