7.0

Table Of Contents
Table 24. SAML Federation Component Configuration
Component Configuration
Directories Management Configure SSO2 as a third-party Identity Provider on Directories Management and update the
default authentication policy. You can create an automated script to set up
Directories Management.
SSO2 component Configure Directories Management as a service provider by importing the
Directories Management sp.xml file. This file enables you to configure SSO2 to use
Directories Management as the Service Provider (SP).
Prerequisites
n
You have configured tenants for your vRealize Automation deployment set up an appropriate Active
Directory link to support basic Active Directory user ID and password authentication.
n
Active Directory is installed and configured for use on your network.
n
Obtain the appropriate Active Directory Federated Services (ADFS) metadata.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Download SSO2 Identity Provider metadata through the SSO2 user interface.
a Login to vCenter as a an Administrator at https://<cloudvm-hostnamte>/.
b Click the Log in to vSphere Web Client link
c On the left navigation pane, select Administration > Single Sign On > Configuration.
d Click Download adjacent to the Metadata for your SAML service provider heading.
The vsphere.local.xml file should begin downloading.
e Copy the contents of the vsphere.local.xml file.
2 Use the vRealize Automation Directories Management Identity Providers page to create a new
Identity Provider.
a Log in to vRealize Automation as a tenant administrator.
b Select Administration > Directories Management > Identity Providers.
c Click Add Identity Provider.
d Enter a name for the new Identity Provider in the Identity Provider Name text box.
e Paste the contents of your SSO2 idp.xml metadata file into the Identity Provider Metadata
(URI or XML) text box.
f Click Process IDP Metadata.
g Enter the following in the Name ID Policy in SAML Request (Optional) text box.
http://schemas.xmlsoap.org/claims/UPN
h Select the domains to which you want users to have access privileges in the Users text box.
Configuring vRealize Automation
VMware, Inc. 92