7.0

Table Of Contents
Using Directories Management to Create an Active Directory Link
After you create vRealize Automation tenants, you must log in to the system console as a tenant
administrator and create an Active Directory link to support user authentication.
Configure a Link to Active Directory
You must use the Directories Management feature to configure a link to Active Directory to support user
authentication for all tenants and select users and groups to sync with the Directories Management
directory.
There are two Active Directory connection options: Active Directory over LDAP, and Active Directory
(Integrated Windows Authentication). An Active Directory over LDAP connection supports DNS Service
Location lookup by default. With Active Directory (Integrated Windows Authentication), you configure the
domain to join.
Prerequisites
n
Connector installed and the activation code activated.
n
Select the required default attributes and add additional attributes on the User Attributes page. See
Select Attributes to Sync with Directory.
n
List of the Active Directory groups and users to sync from Active Directory.
n
For Active Directory over LDAP, information required includes the Base DN, Bind DN, and Bind DN
password.
n
For Active Directory Integrated Windows Authentication, the information required includes the
domain's Bind user UPN address and password.
n
If Active Directory is accessed over SSL, a copy of the SSL certificate is required.
n
For Active Directory (Integrated Windows Authentication), when you have multi-forest Active Directory
configured and the Domain Local group contains members from domains in different forests, make
sure that the Bind user is added to the Administrators group of the domain in which the Domain Local
group resides. If this is not done, these members will be missing from the Domain Local group.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click Add Directory.
3 On the Add Directory page, specify the IP address for the Active Directory server in the Directory
Name text box.
Configuring vRealize Automation
VMware, Inc. 84