7.1

Table Of Contents
Table 28. User Authentication Types Supported by Directories Management (Continued)
Authentication Types Description
Mobile SSO (for Android) Mobile SSO for Android authentication is used for single sign-on authentication
for AirWatch-managed Android devices. A proxy service is set up between the
Directories Management service and AirWatch to retrieve the certicate from
AirWatch for authentication.
Password (AirWatch Connector) The AirWatch Cloud Connector can be integrated with the
Directories Management service for user password authentication. You congure
the Directories Managementservice to sync users from the AirWatch directory.
Users are authenticated based on the authentication methods, the default access policy rules, network
ranges, and the identity provider instance you congure. After the authentication methods are congured,
you create access policy rules that specify the authentication methods to be used by device type.
Configuring SecurID for Directories Management
When you congure RSA SecurID server, you must add the Directories Management service information as
the authentication agent on the RSA SecurID server and congure the RSA SecurID server information on
the Directories Management service.
When you congure SecurID to provide additional security, you must ensure that your network is properly
congured for your Directories Management deployment. For SecurID specically, you must ensure that the
appropriate port is open to enable SecurID to authenticate users outside your network.
After you run the Directories Management Setup wizard and congured your Active Directory connection,
you have the information necessary to prepare the RSA SecurID server. After you prepare the RSA SecurID
server for Directories Management, you enable SecurID in the administration console.
n
Prepare the RSA SecurID Server on page 102
The RSA SecurID server must be congured with information about the Directories Management
appliance as the authentication agent. The information required is the host name and the IP addresses
for network interfaces.
n
Congure RSA SecurID Authentication on page 103
After Directories Management is congured as the authentication agent in the RSA SecurID server,
you must add the RSA SecurID conguration information to the connector.
Prepare the RSA SecurID Server
The RSA SecurID server must be congured with information about the Directories Management appliance
as the authentication agent. The information required is the host name and the IP addresses for network
interfaces.
Prerequisites
n
Verify that one of the following RSA Authentication Manager versions is installed and functioning on
the enterprise network: RSA AM 6.1.2, 7.1 SP2 and later, and 8.0 and later. The Directories Management
server uses AuthSDK_Java_v8.1.1.312.06_03_11_03_16_51 (Agent API 8.1 SP1), which only supports the
preceding versions of RSA Authentication Manager (the RSA SecurID server). For information about
installing and conguring RSA Authentication Manager (RSA SecurID server), see RSA documentation.
Configuring vRealize Automation
102 VMware, Inc.