When logging into the NSX Manager UI using VMware Identity Manager (vIDM) integration, authentication fails with "Access Denied." This occurs specifically when permissions are assigned via vIDM Groups rather than individual users.
[Timestamp] ERROR NSX 7672 [nsx@4413 comp="nsx-manager" errorCode="MP401" level="ERROR" logger="UserInfoUtil" msgID="SYSTEM" subcomp="manager" threadName="http-nio-127.0.0.1-7440-exec-464"] User <vidm-username> with groups [ALL USERS] and incoming roles null is not authorized to access API with rbac_feature utilities_backup having required_permission read.[Timestamp] ERROR NSX 7672 [nsx@4413 comp="nsx-manager" errorCode="MP401" level="ERROR" logger="UserInfoUtil" msgID="SYSTEM" subcomp="manager" threadName="http-nio-127.0.0.1-7440-exec-551"] User <vidm-username> with groups [ALL USERS] and incoming roles null is not authorized to access API with rbac_feature search having required_permission read.A logic defect in the NSX Management Plane causes the RBAC framework to return a null role for group-based memberships during the authentication consolidation process.
This is a known issue which will be fixed in upcoming NSX releases.
Workaround: Assign individual vidm user roles directly on NSX
For further assistance, please Contact Broadcom Support.