When you assign a role to an SSO user, vCenter Server authenticates the user with the identity service configured on the SSO server. If the SSO server is not configured or is not available, the user is authenticated either locally or with Active Directory based on vCenter Server configuration.
When you assign a role to an SSO user, access is granted in the following interfaces:
- The Networking and Security plug-in in the vSphere Web Client.
- The NSX Manager appliance, including the API. This access is available only in NSX 6.4 or later.
Roles can be assigned individually or through a group membership. A user can be assigned an NSX role individually, and this user can also be a member of a group that is assigned a different NSX role. In such cases, the role that is assigned individually to the user is used for logging into the NSX Manager appliance.