VMware Cloud Community
vishalch
Enthusiast
Enthusiast

Nested AD group membership not working in VCSA 6.0

Hi Folks,

I am facing problems with nested group membership on my newly installed VCSA 6.0 ( Embedded Mode ).

I have joined the appliance to AD in the Root domain. I am observing the following scenarios.

1) I have added the Root domain as Active Directory ( Integrated Windows Authentication ) identity source. So, the users from the root domain and child domains are able to login to vCenter if added explicity by their user ids. However if the user is in child domain but a member of group in Root or Child domain is unable to login if permission on vCenter is defined for these groups.

2) I have added the Root domain as Active Directory ( Integrated Windows Authentication ) AND each child domain as Active Directory as an LDAP server Identity sources. So, the users from the root domain and child domains are able to login to vCenter if added explicity by their user ids. If the user is in child domain but a member of group in the same Child domain is able to login if permission in vCenter is defined for this group. However if a user is in child domain but it is a member of a group in Root domain is unable to login if permission in vCenter is defined for this group in Root Domain.

Example :-

The following are letters used to refer different domains.

Root Domain = R

Child Domains= A,B,C and D.

1 ) User1 ( Domain A ) -- > member of Group1 ( Domain A ) - Able to Login.

2) User1 ( Domain A ) --> member of Group 2 ( Domain R ) - Unable to login.

Is there anything wrong with the configuration or I am missing something?

Please share your feedback. Thanks in advance.

Reply
0 Kudos
4 Replies
vishalch
Enthusiast
Enthusiast

Hello Folks,

Can someone help me on this ?

Thanks

Reply
0 Kudos
mhampto
VMware Employee
VMware Employee

Could you get the SSO logs after a successful login and a login failure? Location of VMware vCenter Server 6.0 log files (2110014) | VMware KB

Reply
0 Kudos
roman79
Enthusiast
Enthusiast

Hi vishalch​,

What is the build number of VCSA you're using?

Have you checked the following KB first? - Unable to administer vCenter Single Sign-On after adding a User Group and individual users from a Di...

Regards,

Reply
0 Kudos
vishalch
Enthusiast
Enthusiast

Hi roman79,

Thanks for your reply.

Please find the vCenter details, version:- 6.0.0  and build:- 3634794.

Secondly, I have checked KB shared by you. It is not applicable in this case.

The problem is vCenter is unable to the authenticate users from Domain B who are members of a Group in Domain A and permissions are assinged through Group in Domain A on a vCenter object.

Thanks

Reply
0 Kudos