NSX Manager VCF SSO Login Fails with Access Denied Error in VCF 9.1.1
search cancel

NSX Manager VCF SSO Login Fails with Access Denied Error in VCF 9.1.1

book

Article ID: 456430

calendar_today

Updated On:

Products

VCF Operations VMware NSX

Issue/Introduction

  • SSO logins to VCF Operations and vCenter are successful, but the NSX SSO option fails without any visible response upon attempt.

  • The Authentication Providers section in NSX Manager displays the error: 'Access denied. Check client credentials'.
  • Within the SSO configuration, the VCF instance is marked as 'Not eligible'.

  • Attempting to select the 'Configure Components' tab yields the error: 'Sorry we encountered an error. Service "Identity broker" is not available. Please try again in 5 minutes'.

  • Manual verification of the vidb pods on the control plane node shows all pods are in a running state.

    kubectl get pods -n vidb-external -o wide
    

Environment

  • VMware Cloud Foundation (VCF) 9.1.1
  • NSX / NSX Manager

Cause

The NSX components lose their active binding or valid configuration state with the Identity Broker following the post-upgrade initialization.

Resolution

  1. Navigate to the SSO configuration and explicitly click into the VCF instance currently marked as 'Not eligible'. Confirming the components are configured in this specific view is the critical step required to prompt the system to synchronize the state.

  2. Return to the VCF SSO overview and wait for the previous warning on the VCF Instance to disappear. The view should update to show the status as 'Configured', indicating the Identity Broker service has synchronized.

  3. Access the 'Configure Components' tab.

  4. Perform an 'Unjoin' operation for both NSX components.

  5. Perform a 'Join' operation for both NSX components to successfully re-establish the authentication trust.

  6. For additional context on NSX manager UI login failures during or after related operations, review the KB below: