This article outlines steps to troubleshoot scenarios where specific Active Directory (AD) users are unable to authenticate to the vCenter Server, while other users within the same domain or group structure can authenticate successfully.
This behavior often points to group membership conflicts or attribute synchronization issues rather than general identity source misconfiguration.
Symptoms:
memberOf attribute in the Active Directory Attribute Editor to ensure correct group nesting./var/log/vmware/sso/ssoAdminServer.log for group lookup failures specifically related to the AD group in question.