7.1

Table Of Contents
Create an Active Directory Policy
You create an Active Directory policy to dene where records are added in an Active Directory instance
when your users deploy machines. You can assign a policy to a business group so that all machines
deployed by the business group members result in a record created in the specied organizational unit.
You create dierent Active Directory policies when you want machines deployed by dierent business
groups to have dierent domains or to be added to dierent Active Directory instances.
Prerequisites
n
Verify that you created an Active Directory endpoint. See “Congure the Active Directory Plug-In as an
Endpoint,” on page 227.
n
If you use an external vRealize Orchestrator server, verity that it is set up correctly. See “Congure an
External vRealize Orchestrator Server,” on page 153.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > AD Policies.
2
Click the New icon (
).
3 Congure the Active Directory policy details.
Option Description
ID
Enter the permanent value.
The value cannot include any spaces or special characters.
You cannot change this value at a later time. You can only re-create the
policy with a dierent ID.
Description
Describe of the policy.
Active Directory Endpoint
Select the Active Directory endpoint for which this policy is created.
Domain
Enter the root domain. The format is mycompany.com.
Organizational Unit
Enter the organizational unit distinguished name for this policy.
The hierarchy must be entered as a comma-separated list. For example,
ou=development,dc=corp,dc=domain,dc=com.
4 Click OK.
The vRealize Orchestrator Active Directory endpoint is added to the list. You can apply the policy in
business groups or use the policy in blueprints or business groups.
What to do next
n
To provide multiple policy options, create more policies.
n
To add records to Active Directory based on business group membership when a blueprint is deployed,
add the appropriate Active Directory policy to a business group. See “Create a Business Group,” on
page 129. You can apply the policy when you create the business group, or you can add it later.
n
To override the Active Directory policy for the business group for a particular blueprint, add Active
Directory custom properties to the blueprint. See “Scenario: Add a Custom Property to Blueprints to
Override an Active Directory Policy,” on page 236.
Chapter 3 Configuring Resources
VMware, Inc. 235