7.0

Table Of Contents
Complete the following tasks prior to using the administration console to add the third-party identity
provider instance.
n
Verify that the third-party instances are SAML 2.0 compliant and that the service can reach the third-
party instance.
n
Obtain the appropriate third-party metadata information to add when you configure the identity
provider in the administration console. The metadata information you obtain from the third-party
instance is either the URL to the metadata or the actual metadata.
Configure an Identity Provider Instance
vRealize Automation is supplied with a default identity provider instance. Users may want to create
additional identity provider instances.
vRealize Automation is supplied with an default identity provider. In most cases, the default provider is
sufficient for customer needs. If you use an existing enterprise identity management solution, however,
you can set up a custom identity provider to redirect users to your existing identity solution.
Prerequisites
n
Configure the network ranges that you want to direct to this identity provider instance for
authentication. See Add or Edit a Network Range.
n
Access to the third-party metadata document. This can be either the URL to the metadata or the
actual metadata.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Navigate to the Administration > Directories Management > Identity Providers.
This page displays all configured Identity Providers.
2 Click Add Identity Provider and edit the identity provider instance settings.
Form Item Description
Identity Provider Name Enter a name for this identity provider instance.
SAML Metadata Add the third party IdPs XML-based metadata document to establish trust with the identity
provider.
1 Enter the SAML metadata URL or the xml content into the text box.
2 Click Process IdP Metadata. The NameID formats supported by the IdP are extracted from
the metadata and added to the Name ID Format table.
3 In the Name ID value column, select the user attribute in the service to map to the ID formats
displayed. You can add custom third-party name ID formats and map them to the user
attribute values in the service.
4 (Optional) Select the NameIDPolicy response identifier string format.
Users Select the Directories Management directories of the users that can authenticate using this
identity provider.
Configuring vRealize Automation
VMware, Inc. 118