There's separate roles and permissions for vCenter and Appliance configurations (such as SSO). Make sure you're properly setting the permissions for those users/groups there as well.
Example of the SSO permissions: link
与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…