When attempting to log in to VCF Operations for Logs 8.18.x using Single Sign-On (SSO) group membership, authentication may fail with a 401 Not Authorized error.
This issue occurs when a user belongs to an Active Directory Universal Group originating from a child domain. During the authentication process, the system may return that group under the parent domain. If the group was originally imported into VCF Operations for Logs using the child domain context, this domain mismatch causes the group lookup to fail, resulting in an authorization failure despite the user having valid permissions.
VCF Operations for Logs 8.18.x
This issue is caused by a known product limitation in how cross-domain Universal Group memberships are evaluated. Specifically, authentication fails when the domain returned during the active login sequence does not match the domain identifier defined during the initial group import.
Open a Broadcom support case referencing this KB article 454081 for details of the workaround.