This behavior is dependent upon the way identify source is configured in VCSA. Have seen this normally happen when identity source is configured to use integrated windows authentication. This requires the VCSA and any external PSC's to be joined to the domain. Changing the identity source type to "Active Directory as an LDAP server" fixes it.
Here is a link to setting up identity source. https://dineshgoundar.net/2017/06/30/configure-identity-sources-in-vcenter/