Description of problem: https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/10/html/integrate_with_identity_service/sec-active-directory https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/10/html/integrate_with_identity_service/sec-idm Since OSP 10 and the resolution of https://bugzilla.redhat.com/show_bug.cgi?id=1408777 , both of the above articles need to contain a small modification to give the admin user the admin role in the default domain Additional info: More details here: https://access.redhat.com/solutions/2939821 ++++++++++++++++++++++++++++++++++++++++++++++ Resolution Upgrade to a recent version of python-django-horizon Upgrade to python-django-horizon-10.0.2-2.el7ost or later. This is currently being tracked in https://bugzilla.redhat.com/show_bug.cgi?id=1408777 Give the admin user the admin role in the default domain Also, add the admin role in the default domain to the admin user: First, find the admin user's UUID: Raw [stack@undercloud-4 ~]$ openstack user list | grep admin | a6a8adb6356f4a879f079485dad1321b | admin | Now, verify role assignments before making the change: Raw [stack@undercloud-4 ~]$ openstack role assignment list | grep a6a8adb6356f4a879f079485dad1321b | grep da558c2a79c24b3096b19ccdbb032361 | da558c2a79c24b3096b19ccdbb032361 | a6a8adb6356f4a879f079485dad1321b | | 6e8fedc92dcb481aae9b17a622fa2360 | | False | | da558c2a79c24b3096b19ccdbb032361 | a6a8adb6356f4a879f079485dad1321b | | | 6d3e495643524ebd8823849bea5041a8 | False | Add the admin role in the default domain to the admin user Raw [stack@undercloud-4 ~]$ openstack role add --domain default --user a6a8adb6356f4a879f079485dad1321b admin Verify role assignments after the change: Raw [stack@undercloud-4 ~]$ openstack role assignment list | grep a6a8adb6356f4a879f079485dad1321b | grep da558c2a79c24b3096b19ccdbb032361 | da558c2a79c24b3096b19ccdbb032361 | a6a8adb6356f4a879f079485dad1321b | | 6e8fedc92dcb481aae9b17a622fa2360 | | False | | da558c2a79c24b3096b19ccdbb032361 | a6a8adb6356f4a879f079485dad1321b | | | 6d3e495643524ebd8823849bea5041a8 | False | | da558c2a79c24b3096b19ccdbb032361 | a6a8adb6356f4a879f079485dad1321b | | | default | False | Now, the admin user can see the Domain tab.
Guide has been republished with new section: https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/10/html-single/integrate_with_identity_service/#grant_access_to_the_domain_tab
Looks good