Administration

Table Of Contents
Commands for Managing Authenticators
Authenticators are created when you congure SAML authentication between VMware Identity Manager
and a connection server. The only management task is to enable or disable True SSO for the authenticator.
For readability, the options shown in the following table do not represent the complete command you would
enter. Only the options specic to the particular task are included. For example, one row shows the
--list --authenticator options, but the vdmUtil command you would actually enter also contains
options for authentication and for specifying that you are conguring True SSO:
vdmUtil --authAs admin-role-user --authDomain netbios-name --authPassword admin-user-password --
truesso --list --authenticator
For more information about the authentication options, see “Command-line Reference for Conguring True
SSO,” on page 88.
Table 54. vdmutil truesso Command Options for Managing Authenticators
Command and Options Description
--list --authenticator [--verbose]
Lists the fully qualied domain names (FQDNs) of all SAML
authenticators found in the domain. For each one, species whether
True SSO is enabled. If you use the --verbose option, the FQDNs of
the associated connection servers are also listed.
--list --authenticator --name label
For the specied authenticator, lists whether True SSO is enabled, and
lists the FQDNs of the associated connection servers. For label use one
of the names listed when you use the --authenticator option
without the --name option.
--edit --authenticator --name label
--truessoMode mode-value
For the specied authenticator, sets the True SSO mode to the value
you specify, where mode-value can be one of the following values:
n
ENABLED. True SSO is used only when the Active Directory
credentials of the user is not available.
n
ALWAYS. True SSO is always used even if vIDM has the AD
credentials of the user.
n
DISABLED. True SSO is disabled.
For label use one of the names listed when you use the
--authenticator option without the --name option.
Advanced Configuration Settings for True SSO
You can manage the True SSO advanced seings by using the GPO template on the Horizon Agent machine,
registry seings on the enrollment server, and LDAP entries on the connection server. These seings include
default timeout, congure load balancing, specify domains to be included, and more.
Horizon Agent Configuration Settings
You can use GPO template on the agent OS to turn o True SSO at the pool level or to change defaults for
certicate seings such as key size and count and seings for reconnect aempts.
N The following table shows the seings to use for conguring the agent on individual virtual
machines, but you can alternatively use the Horizon Agent Conguration template les. The ADMX
template le is named (vdm_agent.admx). Use the template les to make these policy seings apply to all the
virtual machines in a desktop or application pool. If a policy is set the policy takes precedence over the
registry seings.
The ADMX les are available in a bundled .zip le named VMware-Horizon-Extras-Bundle-x.x.x-
yyyyyyy.zip, which you can download from the VMware download site at
hps://my.vmware.com/web/vmware/downloads. Under Desktop & End-User Computing, select the
VMware Horizon 7 download, which includes the bundled .zip le.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 91