Hi,
could you please check whether you have properly configured Security role to user/group mapping for your application deployment?
There is several ways how you can do that - the simplest one, perhaps not the best practice though, is just to map special subject All Authenticated in Application's Realm so that (slightly simplifying) whoever is properly authenticated gets authorized to access Maximo (see example below). The other options are to grant access to specific users explicitly or perhaps one of the user groups (including AD ones) which contains users who should be able to access Maximo.
The other reason for your problem might be that the values of the Federated repository properties for login property of your user accounts in AD don't match MAXUSER.LOGINID values in Maximo. In that case even if user gets authenticated and authorized then Maximo cannot find a match between authenticated user context and Maximo users collection, or matched user is not active.

Finally the simplest answer might be that the user account is blocked in Maximo (MAXUSER.STATUS) or user IP is blocked etc.
------------------------------
Andrzej Więcław
Maximo Technical Consultant
Trivalo AB
Gothenburg, Sweden
------------------------------