7.1

Table Of Contents
8 Click Sync  > Mapped .
9 In the drop-down menu for the aributes that you added, select the Active Directory aribute to map
to.
10 Click Save.
The directory is updated the next time the directory syncs to the Active Directory.
Applying the Default Access Policy
The Directories Management service includes a default access policy that controls user access to their apps
portals. You can edit the policy to change the policy rules as necessary.
When you enable authentication methods other than password authentication, you must edit the default
policy to add the enabled authentication method to the policy rules.
Each rule in the default access policy requires that a set of criteria be met in order to allow user access to the
apps portal. You apply a network range, select which type of user can access content and select the
authentication methods to use. See “Managing Access Policies,” on page 96.
The number of aempts the service makes to login a user using a given authentication method varies. The
services only makes one aempt at authentication for Kerberos or certicate authentication. If the aempt is
not successful in logging in a user, the next authentication method in the rule is aempted. The maximum
number of failed login aempts for Active Directory password and RSA SecurID authentication is set to ve
by default. When a user has ve failed login aempts, the service aempts to log in the user with the next
authentication method on the list. When all authentication methods are exhausted, the service issues an
error message.
Apply Authentication Methods to Policy Rules
Only the password authentication method is congured in the default policy rules. You must edit the policy
rules to select the other authentication methods you congured and set the order in which the
authentication methods are used for authentication.
Prerequisites
Enable and congure the authentication methods that your organization supports. See “Integrating
Alternative User Authentication Products with Directories Management,” on page 101
Procedure
1 Select Administration > Directories Management > Policies
2 Click the default access policy to edit.
3 To open a policy rule page to edit, click the authentication name in the Authentication Method column,
or to add a new policy rule, click the + icon.
a Verify that the network range is correct. If adding a new rule, select the network range for this
policy rule.
b Select which type of device that this rule manages from the and the user is trying to access content
from... drop-down menu.
c Congure the authentication order. In the then the user must authenticate using the following
method drop-down menu, select the authentication method to apply rst.
To require users to authenticate through two authentication methods, click + and enter a second
authentication method.
d (Optional) To congure additional authentication methods if the rst authentication fails, select
another enabled authentication method from the next drop-down menu.
You can add multiple fallback authentication methods to a rule.
Chapter 2 Configuring Tenant Settings
VMware, Inc. 113