"Access denied. Unable to authenticate the user" error during MFA login in VMware Identity Manager
search cancel

"Access denied. Unable to authenticate the user" error during MFA login in VMware Identity Manager

book

Article ID: 444907

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

When you attempt to log in to VMware Identity Manager with Multi-Factor Authentication (MFA) enabled, selecting the MFA identity directory results in an authentication failure.

This issue occurs even if you have verified access to the underlying domain.

During the login process, the system throws the following error message on the page:

Access Denied. Unable to authenticate the user

Environment

VMware Identity Manager 3.3.7

Cause

The third-party Identity Provider is not configured to accept authentication requests from the correct network IP ranges.

VMware Identity Manager utilizes network ranges to determine which identity providers and authentication policies apply to an incoming login request based on your source IP address.

If the appropriate network ranges are left unselected in the Network configuration section of the Identity Provider during initial setup, VMware Identity Manager blocks the authentication attempts originating from those IPs, resulting in the access denied error.

Resolution

To resolve the access restriction and allow the MFA authentication flow to complete successfully, you must assign the correct network ranges to the third-party Identity Provider so that it explicitly permits and properly routes authentication requests.

  1. Log into the VMware Identity Manager administration console.

  2. Navigate to the Identity Providers settings and edit the affected third-party MFA identity provider.

  3. Scroll to the Network section, which lists the existing network ranges configured in the service.

  4. Select All network ranges (or specify the exact network ranges for the users based on their IP addresses) to direct those users to this identity provider instance for authentication.

  5. Save the configuration and verify that MFA logins now succeed.