VMware NSX 4.2.x
vCenter Server with external ADFS Identity Provider
The issue typically occurs because the LDAP search scope defined in the NSX Identity Source configuration is too restrictive. Even if the OIDC token flow is functional, NSX uses an LDAP bind to query the directory for users and groups. If the base_dn is set to a specific Organizational Unit (OU) rather than the root of the domain, or if there is a mismatch between the domain_name and the base_dn, the search query fails to locate the principals.
Follow these steps to verify and update the configuration
If the search still fails to return results, you can open a support request with the Broadcom, see Creating and managing Broadcom cases