7.1

Table Of Contents
Table 23. Directories Management Settings
Setting Description
Directories The Directories page enables you to create and manage Active Directory links to support
vRealize Automation tenant user authentication and authorization. You create one or more
directories and then sync those directories with your Active Directory deployment. This
page displays the number of groups and users that are synced to the directory and the last
sync time. You can click Sync Now, to manually start the directory sync.
See “Using Directories Management to Create an Active Directory Link,” on page 79.
When you click on a directory and then click the Sync  buon, you can edit the
sync seings, navigate the Identity Providers page, and view the sync log.
From the directories sync seings page you can schedule the sync frequency, see the list of
domains associated with this directory, change the mapped aributes list, update the user
and groups list that syncs, and set the safeguard targets.
Connectors The Connectors page lists deployed connectors for your enterprise network. A connector
syncs user and group data between Active Directory and the Directories Management
service, and when it is used as the identity provider, authenticates users to the service. Each
vRealize Automation appliance contains a connector by default. See “Managing
Connectors,” on page 92.
User Aributes The User Aributes page lists the default user aributes that sync in the directory and you
can add other aributes that you can map to Active Directory aributes. See “Select
Aributes to Sync with Directory,” on page 89.
Network Ranges This page lists the network ranges that are congured for your system. You congure a
network range to allow users access through those IP addresses. You can add additional
network ranges and you can edit existing ranges. See Add or Edit a Network Range,” on
page 111.
Identity Providers The Identity Providers page lists identity providers that are available on your system.
vRealize Automation systems contain a connector that serves as the default identity
provider and that suces for many user needs. You can add third-party identity provider
instances or have a combination of both.
See “Congure an Identity Provider Instance,” on page 110.
Policies The Policies page lists the default access policy and any other web application access
policies you created. Policies are a set of rules that specify criteria that must be met for
users to access their application portals or to launch Web applications that are enabled for
them. The default policy should be suitable for most vRealize Automation deployments,
but you can edit it if needed. See “Manage the User Access Policy,” on page 100.
Important Concepts Related to Active Directory
Several concepts related to Active Directory are integral to understanding how Directories Management
integrates with your Active Directory environments.
Connector
The connector, a component of the service, performs the following functions.
n
Syncs user and group data your active Directory or LDAP directory to the service.
n
When being used as an identity provider, authenticates users to the service.
Chapter 2 Configuring Tenant Settings
VMware, Inc. 77