Users attempting to log into the VMware NSX Manager web interface using the VCF SSO option may experience a hanging or frozen UI.
This article provides the troubleshooting and resolution steps for this issue, which is caused by an OAuth2 credential mismatch between the NSX Manager and the VCF Identity Broker.
The issue occurs when the OAuth2 Client Credentials (specifically the Client Secret) used for backend communications between the NSX Manager and the VCF Identity Broker expire, fall out of sync, or exceed their Time-To-Live (TTL). Although initial user authentication succeeds on the Identity Broker front-end, the backend token exchange and SCIM role queries fail with a 401 Unauthorized (invalid_client) response, preventing the login workflow from completing.
To restore the trust relationship and push fresh OAuth2 credentials to the NSX Manager:
Broadcom KB 447583