7.1

Table Of Contents
9 Add Certicate to the policy rules and make it the rst authentication method.
Certicate must be the rst authentication method listed in the policy rule, otherwise certicate
authentication fails.
Create a Multi Domain or Multi Forest Active Directory Link
As a system administrator, you need to congure a multi domain or multi forest Active Directory link.
The procedure for conguring a multi domain or multi forest Active Directory link is essentially the same.
For a multi forest link, bi-directional trust is required between all applicable domains.
Prerequisites
n
Install a distributed vRealize Automation deployment with appropriate load balancers. See Installing
vRealize Automation 7.1.
n
Log in to the vRealize Automation console as a tenant administrator.
n
Congure the appropriate domains and Active Directory forests for your deployment.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click Add Directory.
3 On the Add Directory page, specify a name for the Active Directory server in the Directory Name text
box.
4 Select Active Directory (Integrated Windows Authentication) under the Directory Name heading.
5 Congure the connector that synchronizes users from the Active Directory to the VMware
Directories Management directory in the Directory Sync and Authentication section.
Option Description
Sync Connector
Select the appropriate connector to use for your system. Each vRealize
Automation appliance contains a default connector. Consult your system
administrator if you need help in choosing the appropriate connector.
Authentication
Click the appropriate radio buon to indicate whether the selected
connector also performs authentication.
Directory Search Attribute
Select the appropriate account aribute that contains the user name.
Depending on your deployment conguration, you will have one or more connectors available for use.
6 Enter the appropriate join domain credentials in the Domain Name, Domain Admin User Name, and
Domain Admin Password text boxes.
As an example, you might enter something like the following: Domain Name: hs.trcint.com, Domain
Admin Username: devadmin, Domain Admin Password: xxxx.
7 In the Bind User Details section, enter the appropriate Active Directory (Integrated Windows
Authentication) credentials to facilitate directory synchronization.
Option Description
Bind User UPN
Enter the User Principal Name of the user who can authenticate with the
domain. For example, UserName@example.com.
Bind DN Password
Enter the Bind User password.
8 Click Save & Next.
The Select the Domains page appears with the list of domains.
Configuring vRealize Automation
126 VMware, Inc.