7.1

Table Of Contents
Configure the Active Directory Plug-In as an Endpoint
You add an endpoint and congure the Active Directory plug-in to connect to a running Active Directory
instance and manage users and user groups, Active Directory computers, organizational units, and so on.
After you add an Active Directory endpoint, you can update it at any time.
Prerequisites
n
Verify that you have access to a Microsoft Active Directory instance. See the Microsoft Active Directory
documentation.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > vRO  > Endpoints.
2
Click the New icon ( ).
3 In the Plug-in drop-down menu, select Active Directory.
4 Click Next.
5 Enter a name and, optionally, a description.
6 Click Next.
7 Congure the Active Directory server details.
a Enter the IP address or the DNS name of the host on which Active Directory runs in the Active
Directory host IP/URL text box.
b Enter the lookup port of your Active Directory server in the Port text box.
vRealize Orchestrator supports the Active Directory hierarchical domains structure. If your domain
controller is congured to use Global Catalog, you must use port 3268. You cannot use the default
port 389 to connect to the Global Catalog server. In addition to ports 389 and 3268, you can use 636
for LDAPS.
c Enter the root element of the Active Directory service in the Root text box.
For example, if your domain name is mycompany.com, then your root Active Directory is
dc=mycompany,dc=com.
This node is used for browsing your service directory after entering the appropriate credentials.
For large service directories, specifying a node in the tree narrows the search and improves
performance. For example, rather than searching in the entire directory, you can specify
ou=employees,dc=mycompany,dc=com. This root element displays all the users in the Employees
group.
d (Optional) To activate encrypted certication for the connection between vRealize Orchestrator and
Active Directory, select Yes from the Use SSL drop-down menu.
The SSL certicate is automatically imported without prompting for conrmation even if the
certicate is self-signed.
e (Optional) Enter the domain in the Default Domain text box.
For example, if your domain name is mycompany.com, type @mycompany.com.
Chapter 3 Configuring Resources
VMware, Inc. 227