7.1

Table Of Contents
3 Create a new Identity Provider for you deployment.
a Select Administration > Directories Management > Identity Providers.
b Click Add Identity Provider and complete the elds as appropriate.
Option Description
Identity Provider Name
Enter a name for the new identity provider
Identity Provider Metadata (URI or
XML)
Paste the contents of your Active Directory Federated Services
metadata le here.
Name ID Policy in SAML Request
(Optional)
If appropriate, enter a name for the identity policy SAML request.
Users
Select the domains to which you want users to have access privileges.
Process IDP Metadata
Click to process the metadata le that you added.
Network
Select the network ranges to which you want users to have access.
Authentication Methods
Enter a name for the authentication method used by this identity
provider.
SAML Context
Select the appropriate context for your system.
SAML Signing Certificate
Click the link beside the SAML Metadata heading to download the
Directories Management metadata.
c Save the Directories Management metadata le as sp.xml.
d Click Add.
4 Add a rule to the default policy.
a Select Administration > Directories Management > Policies.
b Click the default policy name.
c Click the + icon under the Policy Rules heading to add a new rule.
Use the elds on the Add a Policy Rule page to create a rule that species the appropriate primary
and secondary authentication methods to use for a specic network range and device.
For example, if the user's network range is "My Machine", and the user needs to access content from
"All Device Types," then, for a typical deployment, that user must authenticate using the
following method: ADFS Username and Password.
d Click Save to save your policy updates.
e On the Default Policy page, drag the new rule to the top of the table so that it takes precedence over
existing rules.
5 Using the Active Directory Federated Services management console, or another appropriate tool, set up
a relying party trust relationship with the vRealize Automation identity provider.
To set up this trust, you must import the Directories Management metadata that you previously
downloaded. See the Microsoft Active Directory documentation for more information about
conguring Active Directory Federated Services for bi-directional trust relationships. As part of this
process, you must do the following:
n
Set up a Relying Party Trust. When you set up this trust, you must import the VMware Identity
Provider service provider metadata XML le that you copied and saved
Chapter 2 Configuring Tenant Settings
VMware, Inc. 85