7.0

Table Of Contents
i Select the network ranges from which you want users to have access privileges to this identity
provider in the Network text box.
If you want to authenticate users from an IP addresses, select All Ranges.
j Enter a name for the authentication method in the Authentication Methods text box.
k Use the SAML Context drop down menu to the right of the Authentication Methods text box to
map the authentication method to urn:oasis:names:tc:SAML:2.0:ac:classes:Password.
l Click the link beside the SAML Metadata heading under the SAML Signing Certificate text box,
to download the Directories Management metadata.
m Save the Directories Management metadata file as sp.xml.
n Click Add.
3 Update the relevant authentication policy using the Directories Management Policies page to redirect
authentication to the third party SSO2 identity provider.
a Select Administration > Directories Management > Policies.
b Click the default policy name.
c Click authentication method under the Policy Rules heading to edit the existing authentication
rule.
Use the fields on the Edit a Policy Rule page to change the authentication method from password
to the appropriate method. In this case, the method should be SSO2.
d Click Save to save your policy updates.
4 On the left navigation pane, select Administration > Single Sign On > Configuration, and click
Update to upload the sp.xml file to vSphere.
Add Users or Groups to an Active Directory Connection
You can add users or groups to an existing Active Directory connection.
The Directories Management user authentication system imports data from Active Directory when adding
groups and users, and the speed of the system is limited by Active Directory capabilities. As a result,
import operations may require a significant amount of time depending on the number of groups and users
being added. To minimize the potential for delays or problems, limit the number of groups and users to
only those required for vRealize Automation operation. If performance degrades or if errors occur, close
any unneeded applications and ensure that your deployment has appropriate memory allocated to Active
Directory. If problems persist, increase the Active Directory memory allocation as needed. For
deployments with large numbers of users and groups, you may need to increase the Active Directory
memory allocation to as much as 24 GB.
Configuring vRealize Automation
VMware, Inc. 93