Hello!
I have seen this on two occasions. First was an upgrade from vCenter 5.1 to 5.5 update 1a, later upgraded again to 5.5 update 1b. Yesterday I did an upgrade from vCenter 5.0 update 1 to 5.5 update 1b.
In both cases I have a problem with AD-members belonging to a group in AD, they get the same message as the OP. If I grant the same user rights in vCenter as a user, instead of through a group, it works. I automatically added the AD during upgrade from 5.1 to 5.5 update 1a, but NOT during the upgrade from 5.0 update 1 to 5.5 update 1b. The installation of SSO failed when I tried to import the AD, so I added it later, once the entire upgrade was completed.
I haven't seen this in 5.5 update 1, only update 1a and update 1b. Anyone else recognize this behaviour?
Cheers,
Matts