7.1

Table Of Contents
The connector is the default identity provider. For the authentication methods the connector supports,
see VMware Identity Manager Administration. You can also use third-party identity providers that
support the SAML 2.0 protocol. Use a third-party identity provider for an authentication type the
connector does not support or for an authentication type the connector does support, if the third-party
identity provider is preferable based on your enterprise security policy.
N If you use third-party identity providers, you can either congure the connector to sync user and
group data or congure Just-in-Time user provisioning. See the Just-in-Time User Provisioning section
in VMware Identity Manager Administration for more information.
N Even if you use third-party identity providers, you must congure the connector to sync user
and group data.
Directory
The Directories Management service has its own concept of a directory, corresponding to the Active
Directory or LDAP directory in your environment. This directory uses aributes to dene users and groups.
n
Active Directory
n
Active Directory over LDAP. Create this directory type if you plan to connect to a single Active
Directory domain environment. For the Active Directory over LDAP directory type, the connector
binds to Active Directory using simple bind authentication.
n
Active Directory, Integrated Windows Authentication. Create this directory type if you plan to
connect to a multi-domain or multi-forest Active Directory environment. The connector binds to
Active Directory using Integrated Windows Authentication.
The type and number of directories that you create varies depending on your Active Directory
environment, such as single domain or multi-domain, and on the type of trust used between domains.
In most environments, you create one directory.
n
LDAP Directory
The service does not have direct access to your Active Directory or LDAP directory. Only the connector has
direct access. Therefore, you associate each directory created in the service with a connector instance.
Worker
When you associate a directory with a connector instance, the connector creates a partition for the associated
directory called a worker. A connector instance can have multiple workers associated with it. Each worker
acts as an identity provider. You dene and congure authentication methods per worker.
The connector syncs user and group data between your Active Directory or LDAP directory and the service
through one or more workers.
I You cannot have two workers of the Active Directory, Integrated Windows Authentication type
on the same connector instance.
Active Directory Environments
You can integrate the service with an Active Directory environment that consists of a single Active Directory
domain, multiple domains in a single Active Directory forest, or multiple domains across multiple Active
Directory forests.
Single Active Directory Domain Environment
A single Active Directory deployment allows you to sync users and groups from a single Active Directory
domain.
See “Congure a Link to Active Directory,” on page 79. For this environment, when you add a directory to
the service, select the Active Directory over LDAP option.
Configuring vRealize Automation
78 VMware, Inc.