7.0

Table Of Contents
Select Attributes to Sync with Directory
When you set up the Directories Management directory to sync with Active Directory, you specify the user
attributes that sync to the directory. Before you set up the directory, you can specify on the User Attributes
page which default attributes are required and, if you want, add additional attributes that you want to map
to Active Directory attributes.
When you configure the User Attributes page before the directory is created, you can change default
attributes from required to not required, mark attributes as required, and add custom attributes.
For a list of the default mapped attributes, see Managing User Attributes that Sync from Active Directory.
After the directory is created, you can change a required attribute to not be required, and you can delete
custom attributes. You cannot change an attribute to be a required attribute.
When you add other attributes to sync to the directory, after the directory is created, go to the directory's
Mapped Attributes page to map these attributes to Active Directory Attributes.
Procedure
1 Log in to vRealize Automation as a system or tenant administrator.
2 Click the Administration tab.
3 Select Directories Management > User Attributes
4 In the Default Attributes section, review the required attribute list and make appropriate changes to
reflect what attributes should be required.
5 In the Attributes section, add the Directories Management directory attribute name to the list.
6 Click Save.
The default attribute status is updated and attributes you added are added on the directory's Mapped
Attributes list.
7 After the directory is created, go to the Identity Stores page and select the directory.
8 Click Sync Settings > Mapped Attributes.
9 In the drop-down menu for the attributes that you added, select the Active Directory attribute to map
to.
10 Click Save.
The directory is updated the next time the directory syncs to the Active Directory.
Applying the Default Access Policy
The Directories Management service includes a default access policy that controls user access to their
apps portals. You can edit the policy to change the policy rules as necessary.
When you enable authentication methods other than password authentication, you must edit the default
policy to add the enabled authentication method to the policy rules.
Configuring vRealize Automation
VMware, Inc. 121