In VMware Cloud Foundation (VCF) 9 or vSphere 9, users authenticated via external identity sources (Active Directory or LDAP) may experience the following:
ServiceProviderUsers SSO group does not grant the expected visibility for these external accounts.vSphere 9.x
VCF 9.x
In vSphere 9, architectural changes to inventory visibility logic require users to reside in the local vCenter SSO domain to utilize group-based visibility shortcuts. Users from external identity sources are currently not processed by the legacy visibility bypass method.
Note: For environments running versions earlier than 9.x, the workflow described in KB 417756 remains valid. However, that specific workflow is no longer sufficient for external accounts in VCF 9/vSphere 9.
There is currently no resolution. A fix is planned for a future update.
To provide Namespace visibility for external AD/LDAP users, you must grant explicit permissions on the Namespaces folder using a local SSO group proxy.
Create a Local SSO Group:
[email protected]).Assign Folder Permissions:
[email protected] group.Validation: