7.1

Table Of Contents
12 Verify that the Directories Management directory aribute names are mapped to the correct Active
Directory aributes.
If the directory aribute names are not mapped correctly, select the correct Active Directory aribute
from the drop-down menu.
13 Click Next.
14
Click to select the groups you want to sync from Active Directory to the directory.
When you add a group from Active Directory, if members of that group are not in the Users list, they
are added.
N The Directories Management user authentication system imports data from Active Directory
when adding groups and users, and the speed of the system is limited by Active Directory capabilities.
As a result, import operations may require a signicant amount of time depending on the number of
groups and users being added. To minimize the potential for delays or problems, limit the number of
groups and users to only those required for vRealize Automation operation. If your system
performance degrades or if errors occur, close any unneeded applications and ensure that your system
has appropriate memory allocated to Active Directory. If problems persist, increase the Active Directory
memory allocation as needed. For systems with large numbers of users and groups, you may need to
increase the Active Directory memory allocation to as much as 24 GB.
15 Click Next.
16
Click to add additional users. For example, enter as
CN-username,CN=Users,OU-myUnit,DC=myCorp,DC=com.
To exclude users, click
to create a lter to exclude some types of users. You select the user aribute
to lter by, the query rule, and the value.
17 Click Next.
18 Review the page to see how many users and groups are syncing to the directory.
If you want to make changes to users and groups, click the Edit links.
19 Click Push to Workspace to start the synchronization to the directory.
The connection to the Active Directory is complete and the selected users and groups are added to the
directory.
What to do next
If your vRealize Automation environment is congured for high availability, you must specically congure
Directories Management for high availability. See “Congure Directories Management for High
Availability,” on page 83.
n
Set up authentication methods. After users and groups sync to the directory, if the connector is also
used for authentication, you can set up additional authentication methods on the connector. If a third
party is the authentication identity provider, congure that identity provider in the connector.
n
Review the default access policy. The default access policy is congured to allow all appliances in all
network ranges to access the Web browser, with a session time out set to eight hours or to access a client
app with a session time out of 2160 hours (90 days). You can change the default access policy and when
you add Web applications to the catalog, you can create new ones.
n
Apply custom branding to the administration console, user portal pages and the sign-in screen.
Configuring vRealize Automation
82 VMware, Inc.