5.5

Table Of Contents
Retrieve or Update Organization Settings
Organization settings define organization policies such as default lease settings for vApps and how
incorrect login attempts are handled. They also configure how the organization uses services such as email
and LDAP, and define the organization's federated identity provider if it uses one.
An AdminOrg element contains an OrgSettings element, which contains the following elements, each of
which represents a group of related organization settings. Default settings are inherited from the containing
cloud.
GeneralOrgSettings
Specifies storage and deployment quotas and other behaviors for virtual
machines owned by members of this organization. Sets the scope of catalog
publication and subscription within this organization.
VAppLeaseSettings
Controls storage and deployment leases for vApps.
VAppTemplateLeaseSettin
gs
Controls storage and deployment leases for vApp templates.
OrgLdapSettings
Defines whether this organization is connected to an LDAP service, and
whether it uses the service defined in the system LdapSettings or a custom
LDAP service defined here.
OrgEmailSettings
Defines whether this organization uses the email service defined in the
system EmailSettings or a custom email service defined here.
OrgPasswordPolicySettin
gs
Specifies policies to be followed when a user in this organization enters an
incorrect password. Initial values are inherited from the system
PasswordPolicySettings.
OrgOperationLimitsSetti
ngs
Specifies limits to be placed on simultaneous resource-intensive operations
and console sessions for members of this organization.
OrgGuestPersonalization
Settings
Default values for GuestCustomizationSection elements in virtual machines
created by this organization. See “Retrieve or Modify the
GuestCustomizationSection of a Virtual Machine,” on page 137
OrgFederationSettings
Defines the SAML identity provider used by this organization. An
organization can define a SAML identity provider that it shares with other
applications or enterprises. Users that authenticate to the identity provider
obtain a token that they can then use to log in to the organization. Such a
strategy can enable an enterprise to provide access to multiple, unrelated
services, including vCloud Director with a single set of credentials, an
arrangement often referred to as "single sign-on." An organization that wants
to participate in a federated identity scheme must include an
OrgFederationSettings element that contains SAML metadata retrieved from
the federation's identity provider. By default, this element is empty.
NOTE To update or remove OrgFederationSettings after a SAML identity
provider has been specified, you must include an empty SAMLMetadata
element in the update request. If this element is not present in the update
request, the OrgFederationSettings are not changed.
Prerequisites
Verify that you are logged in to the vCloud API as an organization administrator or system administrator.
Chapter 6 Creating and Managing Organizations
VMware, Inc. 157