7.1

Table Of Contents
Configure an Identity Provider Instance
vRealize Automation is supplied with a default identity provider instance. Users may want to create
additional identity provider instances.
vRealize Automation is supplied with an default identity provider. In most cases, the default provider is
sucient for customer needs. If you use an existing enterprise identity management solution, however, you
can set up a custom identity provider to redirect users to your existing identity solution.
Prerequisites
n
Congure the network ranges that you want to direct to this identity provider instance for
authentication. See Add or Edit a Network Range,” on page 111.
n
Access to the third-party metadata document. This can be either the URL to the metadata or the actual
metadata.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Navigate to the Administration > Directories Management > Identity Providers.
This page displays all congured Identity Providers.
2 Click Add Identity Provider and edit the identity provider instance seings.
Form Item Description
Identity Provider
Name
Enter a name for this identity provider instance.
SAML Metadata Add the third party IdPs XML-based metadata document to establish trust with the
identity provider.
1 Enter the SAML metadata URL or the xml content into the text box.
2 Click Process IdP Metadata. The NameID formats supported by the IdP are extracted
from the metadata and added to the Name ID Format table.
3 In the Name ID value column, select the user aribute in the service to map to the ID
formats displayed. You can add custom third-party name ID formats and map them to
the user aribute values in the service.
4 (Optional) Select the NameIDPolicy response identier string format.
Users Select the Directories Management directories of the users that can authenticate using this
identity provider.
Network The existing network ranges congured in the service are listed.
Select the network ranges for the users, based on their IP addresses, that you want to
direct to this identity provider instance for authentication.
Authentication
Methods
Add the authentication methods supported by the third-party identity provider. Select the
SAML authentication context class that supports the authentication method.
SAML Signing
Certicate
Click Service Provider (SP) Metadata to see URL to Directories Management SAML
service provider metadata URL . Copy and save the URL. This URL is congured when
you edit the SAML assertion in the third-party identity provider to map
Directories Management users.
Hostname If the Hostname eld displays, enter the hostname where the identity provider is
redirected to for authentication. If you are using a non-standard port other than 443, you
can set this as Hostname:Port. For example, myco.example.com:8443.
3 Click Add.
Configuring vRealize Automation
110 VMware, Inc.