<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vcfa on Clouds and Unicorns</title><link>https://cloudsandunicorns.com/tags/vcfa/</link><description>Recent content in Vcfa on Clouds and Unicorns</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © 2007–2026, Scott Bowe</copyright><lastBuildDate>Thu, 23 Jul 2026 15:31:08 -0500</lastBuildDate><atom:link href="https://cloudsandunicorns.com/tags/vcfa/index.xml" rel="self" type="application/rss+xml"/><item><title>VCFA OIDC Groups and the Case Sensitivity Trap</title><link>https://cloudsandunicorns.com/2026/07/vcfa-oidc-groups-and-the-case-sensitivity-trap/</link><pubDate>Thu, 23 Jul 2026 15:31:08 -0500</pubDate><guid>https://cloudsandunicorns.com/2026/07/vcfa-oidc-groups-and-the-case-sensitivity-trap/</guid><description>
&lt;p&gt;I &lt;a href="https://williamlam.com/2025/08/vcf-automation-provider-organization-as-an-oidc-identity-provider-for-vcfa-tenant-organizations.html"&gt;federated&lt;/a&gt; one of my VCF Automation tenant orgs to vIDB the other day. I imported the &lt;code&gt;labAdmins@int.sentania.net&lt;/code&gt; group from AD, gave it Organization Owner, and figured I was done. Individual users I'd imported logged in and got their roles just fine. The group did not. Same identity provider, same login flow, and the group members landed in the org with nothing.&lt;/p&gt;
&lt;h2 id="where-things-went-sideways"&gt;Where things went sideways&lt;/h2&gt;
&lt;p&gt;My first instinct was that the OIDC config on the org itself must be wrong, the scopes or the claim mapping not set up right. I went and checked, and it was fine (that's actually a separate post, because I found a different tenant with that exact problem). So the token was carrying the group. VCFA just wasn't matching it.&lt;/p&gt;</description></item></channel></rss>