vCenter Server 8.x
IWA Authentication: Permissions are saved using a principal name format that utilizes the NetBIOS name:
<NetBIOS name>\<username or group name> (e.g., TEST\Administrator).
Active Directory over LDAP (Without Alias): If the domain alias is not set, the uppercase full domain name is used instead:
<UPPERCASE DOMAIN NAME>\<username or group name> (e.g., TEST.LOCAL\Administrator).
Because of this mismatch between the saved principal name and the newly evaluated format, permission authentication fails.
To resolve this issue, reconfigure the identity source and explicitly specify the NetBIOS name in the Domain alias field.
Removal of Integrated Windows Authentication (IWA)
https://knowledge.broadcom.com/external/article/314324
Considerations when migrating a vCenter Identity Source from Integrated Windows Authentication to AD over LDAP / OpenLDAP
https://knowledge.broadcom.com/external/article/344919