When attempting to log in to the VMware NSX Manager UI using VMware Identity Manager (vIDM), you may observe the following:
This issue occurs due to a time synchronization mismatch (clock drift) between the NSX Manager, the vIDM appliance, and other identity sources (such as Active Directory). Authentication tokens used in the SAML/OAuth2 handshake have strict Time To Live (TTL) windows. If the system clocks are not aligned, the token may be rejected as invalid or "not yet valid," forcing the UI to redirect back to the local login prompt.
To resolve this issue, ensure all components are synchronized to the same authoritative time source.
For detailed requirements, see Time Synchronization between NSX Manager, vIDM, and Related Components.
Subscribe to a Broadcom knowledge article by article or product for updates on time-synchronization best practices.