Certain user accounts existing in the underlying foundations fail to synchronize and appear within the Tanzu Hub console.
Tanzu Hub
The internal synchronization agent filters out users who do not meet specific identity and permission requirements. A user is automatically excluded from synchronization if they lack either of the following:
An Assigned Role: The user must possess at least one active, supported role within the foundation.
A Valid Email Attribute: The user must have a valid email address populated under either the username property or the email property.
To ensure users synchronize successfully and can log in, verify that their account profiles meet all platform criteria:
Verify Roles and Attributes: Ensure each target user has at least one valid role assigned and a fully populated email attribute in the foundation source.
Align Identity Provider (IdP) Claims: Confirm that the email ID recognized by the platform matches the synced email ID. If there is a mismatch, review and adjust your IdP configuration (specifically how email claims and attributes are mapped).
Confirm Synchronization: Validated and successfully synchronized users can be viewed directly within the platform's Administration section under "Roles and Permissions".