7.1

Table Of Contents
Working With Active Directory Policies
Active Directory policies dene the properties of a machine record, for example, domain, as well as the
organizational unit in which the record is created using a vRealize Automation blueprint.
If you apply a policy to a business group, all the machine requests from the business group members are
added to the specied organizational unit. You can create dierent policies for dierent organizational units,
and then apply the dierent policies to dierent business groups.
Active Directory policies are a tech preview feature in vRealize Automation 7.1 and should not be used in a
production environment.
Using Custom Properties to Override an Active Directory Policy
Using the provided Active Directory custom properties, you can override the Active Directory policy,
domain, organizational unit, and other values on a particular blueprint when it is deployed.
The list of the provided Active Directory custom properties is included in the Custom Properties Reference.
The custom property prex is ext.policy.activedirectory.
In addition to the provided properties, you can create your own custom properties. You must prex you
custom properties with ext.policy.activedirectory. For example,
ext.policy.activedirectory.domain.extension or ext.policy.activedirectory.yourproperty. The
properties are passed to your custom vRealize Orchestrator Active Directory workows.
For more information about custom properties, see Custom Properties Reference. Depending on what values
you are overriding, you might need to create a property denition. For example, you might create a
property denition that retrieves the available Active Directory policies from vRealize Automation.
Alternatively, you might create denition that allows the requesting user to select from two or more
alternative organizational units. See Custom Properties Reference.
Create and Apply Active Directory Policies
You create one or more Active Directory policies so that you can assign dierent policies to dierent
business groups. You can use the dierent policies to add machine records to dierent organizational units
based on business group membership.
If necessary, you can override the assigned Active Directory policy.
Active Directory policies are a tech preview feature in vRealize Automation 7.1 and should not be used in a
production environment.
Procedure
1 Create an Active Directory Policy on page 235
You create an Active Directory policy to dene where records are added in an Active Directory
instance when your users deploy machines. You can assign a policy to a business group so that all
machines deployed by the business group members result in a record created in the specied
organizational unit.
2 Scenario: Add a Custom Property to Blueprints to Override an Active Directory Policy on page 236
As a blueprint architect for the development business group, you have a blueprint that includes an
application machine and a database machine. You want the database machine record added to an
organizational unit that is dierent from the applied Active Directory policy.
Configuring vRealize Automation
234 VMware, Inc.