7.1

Table Of Contents
Multi-Domain, Single Forest Active Directory Environment
A multi-domain, single forest Active Directory deployment allows you to sync users and groups from
multiple Active Directory domains within a single forest.
You can congure the service for this Active Directory environment as a single Active Directory, Integrated
Windows Authentication directory type or, alternatively, as an Active Directory over LDAP directory type
congured with the global catalog option.
n
The recommended option is to create a single Active Directory, Integrated Windows Authentication
directory type.
See “Congure a Link to Active Directory,” on page 79. When you add a directory for this
environment, select the Active Directory (Integrated Windows Authentication) option.
Multi-Forest Active Directory Environment with Trust Relationships
A multi-forest Active Directory deployment with trust relationships allows you to sync users and groups
from multiple Active Directory domains across forests where two-way trust exists between the domains.
See “Congure a Link to Active Directory,” on page 79. When you add a directory for this environment,
select the Active Directory (Integrated Windows Authentication) option.
Multi-Forest Active Directory Environment Without Trust Relationships
A multi-forest Active Directory deployment without trust relationships allows you to sync users and groups
from multiple Active Directory domains across forests without a trust relationship between the domains. In
this environment, you create multiple directories in the service, one directory for each forest.
See “Congure a Link to Active Directory,” on page 79. The type of directories you create in the service
depends on the forest. For forests with multiple domains, select the Active Directory (Integrated Windows
Authentication) option. For a forest with a single domain, select the Active Directory over LDAP option.
Using Directories Management to Create an Active Directory Link
After you create vRealize Automation tenants, you must log in to the system console as a tenant
administrator and create an Active Directory link to support user authentication.
Configure a Link to Active Directory
You must use the Directories Management feature to congure a link to Active Directory to support user
authentication for all tenants and select users and groups to sync with the Directories Management
directory.
There are two Active Directory communication protocol options: Active Directory over LDAP, and Active
Directory (Integrated Windows Authentication). An Active Directory over LDAP protocol supports DNS
Service Location lookup by default. With Active Directory (Integrated Windows Authentication), you
congure the domain to join. Active Directory over LDAP is appropriate for single domain deployments.
Use Active Directory (Integrated Windows Authentication) for all multi-domain and multi-forest
deployments.
After you select a communication protocol, you can specify the domains to use with the Active Directory
conguration and then select the users and groups to sync with the specied conguration.
Prerequisites
n
Connector installed and the activation code activated.
n
Select the required default aributes and add additional aributes on the User Aributes page. See
“Select Aributes to Sync with Directory,” on page 89.
n
List of the Active Directory groups and users to sync from Active Directory.
Chapter 2 Configuring Tenant Settings
VMware, Inc. 79