Although this should work you may also try to put the users in Global groups, and the Global groups into Domain Local groups. Then assign the vCenter permission to the Domain Local groups.
I think this is general best practice for AD group nesting (unless you also want to use the groups as Distribution Lists).