Error: Access Denied for vIDM group-based roles in NSX / Refreshed OAuth token doesn't work
search cancel

Error: Access Denied for vIDM group-based roles in NSX / Refreshed OAuth token doesn't work

book

Article ID: 447765

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

When logging into the NSX Manager UI using VMware Identity Manager (vIDM) integration, authentication fails with "Access Denied." This occurs specifically when permissions are assigned via vIDM Groups rather than individual users.

  • Failure message:
  • Affected users belong to one or more vIDM groups and assigned a role in NSX.
  • Individual user role assignments work correctly.
  • The issue is observed following an upgrade to NSX 9.1.0 (VCF 9).
  • In /var/log/proton/nsxapi.log, the following error is observed: 
  • [Timestamp] ERROR NSX 7672 [nsx@4413 comp="nsx-manager" errorCode="MP401" level="ERROR" logger="UserInfoUtil" msgID="SYSTEM" subcomp="manager" threadName="http-nio-127.0.0.1-7440-exec-46
    4"] User <vidm-username> with groups [ALL USERS] and incoming roles null is not authorized to access API with rbac_feature utilities_backup having required_permission read.
    [Timestamp]  ERROR NSX 7672 [nsx@4413 comp="nsx-manager" errorCode="MP401" level="ERROR" logger="UserInfoUtil" msgID="SYSTEM" subcomp="manager" threadName="http-nio-127.0.0.1-7440-exec-55
    1"] User <vidm-username> with groups [ALL USERS] and incoming roles null is not authorized to access API with rbac_feature search having required_permission read.

Environment

  • VMware Cloud Foundation 9.x
  • VMware NSX 9.1.0
  • VMware NSX 9.1.x
  • VMware Identity Manager (vIDM) 

Cause

 A logic defect in the NSX Management Plane causes the RBAC framework to return a null role for group-based memberships during the authentication consolidation process. 

Resolution

This is a known issue which will be fixed in upcoming NSX releases.

Workaround:  Assign individual vidm user roles directly on NSX

For further assistance, please Contact Broadcom Support.