Not all users are synchronized from Foundations to Tanzu Hub
search cancel

Not all users are synchronized from Foundations to Tanzu Hub

book

Article ID: 445155

calendar_today

Updated On:

Products

VMware Tanzu Platform Core

Issue/Introduction

Certain user accounts existing in the underlying foundations fail to synchronize and appear within the Tanzu Hub console.

Environment

Tanzu Hub

Cause

The internal synchronization agent filters out users who do not meet specific identity and permission requirements. A user is automatically excluded from synchronization if they lack either of the following:

  • An Assigned Role: The user must possess at least one active, supported role within the foundation.

  • A Valid Email Attribute: The user must have a valid email address populated under either the username property or the email property.

Resolution

To ensure users synchronize successfully and can log in, verify that their account profiles meet all platform criteria:

  1. Verify Roles and Attributes: Ensure each target user has at least one valid role assigned and a fully populated email attribute in the foundation source.

  2. Align Identity Provider (IdP) Claims: Confirm that the email ID recognized by the platform matches the synced email ID. If there is a mismatch, review and adjust your IdP configuration (specifically how email claims and attributes are mapped).

  3. Confirm Synchronization: Validated and successfully synchronized users can be viewed directly within the platform's Administration section under "Roles and Permissions".