seems to be ok... try these:
1. Because is set as default domain, try to login without MYDOMAIN prefix
2. Try to login with user@mydomain.com
3. Try to revoce group under sso and set up permission directly from object (you must see your Administrator members under SSO Configuration / Users / Choose MYDOMAIN from dropdown)
Could you post what you see under event log under vcenter OS (if it is VA login as root user and try to post what you see under /var/log/vmware/vpx/vpxd.log)?