City NSX Manager is bound to Active Directory, but Identity Firewall cannot enumerate finance users because the LDAP service account has no read permission on the user OU. What should the administrator fix first?
Select an answer to reveal the explanation.
Short Explanation
NSX is asking AD who is in Finance with a service account that cannot even open that OU. Fix the bind account’s read rights—do not blow a hole in the default DFW rule.
Full Explanation
The NSX Manager directory connection authenticates with a bind account that must be able to read the users and groups referenced by Identity Firewall. Missing OU read rights produce empty or stale mappings even when DFW syntax is correct. Changing the default firewall rule, substituting vCenter SSO, or weakening LDAPS does not grant directory visibility.