Signing in to the management console granted no permissions
Single sign-on for the hypervisor console worked — the sign-in completed and the account appeared — but the account landed with no permissions at all. Every menu beyond the basics was missing.
Nothing reported a problem. The sign-in succeeded, no error was logged, and the only symptom was an interface that looked stripped down.
Cause. The console adds the realm name as a suffix to every group it receives from the sign-in service before matching it against its own groups. The group had been created under its plain name, so the two never matched and the account was placed in no group — and therefore granted nothing.
Fix. The group now carries the name the console actually looks for. Administrator rights resolve correctly, and group membership is re-derived from the sign-in service at each login, so removing someone from the group there removes their access here.
Status: resolved and verified.
0 Comments
Sign in to comment
No comments yet. Be the first to share your thoughts!
