Delayed permissions with vSphere SSO?

Sometimes vSphere Single-Sign-On does not work as I expect it to. Here is an example:

A few days ago, I had to assign vCenter access rights to several users. In the vCenter server, the according permissions were given to an active directory user group. In theory, all I had to do was to add the users to the AD group and tell them to log off and on again.

<The full post is only available in German>