7.1

Table Of Contents
d Click Download adjacent to the Metadata for your SAML service provider heading.
The vsphere.local.xml le should begin downloading.
e Copy the contents of the vsphere.local.xml le.
2 On the vRealize Automation Directories Management Identity Providers page, create a new Identity
Provider.
a Log in to vRealize Automation as a tenant administrator.
b Select Administration > Directories Management > Identity Providers.
c Click Add Identity Provider and provide the conguration information.
Option Action
Identity Provider Name
Enter a name for the new Identity Provider.
Identity Provider Metadata (URI or
XML) text box
Paste the contents of your SSO2 idp.xml metadata le in the text box
and click Process IDP Metadata.
Name ID Policy in SAML Request
(Optional)
Enter http://schemas.xmlsoap.org/claims/UPN.
Users
Select the domains to which you want users to have access privileges.
Network
Select the network ranges from which you want users to have access
privileges.
If you want to authenticate users from an IP addresses, select All
Ranges.
Authentication Methods
Enter a name for the authentication method. Then, use the SAML
Context drop down menu to the right to map the authentication
method to urn:oasis:names:tc:SAML:2.0:ac:classes:Password.
SAML Signing Certificate
Click the link beside the SAML Metadata heading to download the
Directories Management metadata.
d Save the Directories Management metadata le as sp.xml.
e Click Add.
3 Update the relevant authentication policy using the Directories Management Policies page to redirect
authentication to the third party SSO2 identity provider.
a Select Administration > Directories Management > Policies.
b Click the default policy name.
c Click the authentication method under the Policy Rules heading to edit the existing authentication
rule.
d On the Edit a Policy Rule page, change the authentication method from password to the
appropriate method.
In this case, the method should be SSO2.
e Click Save to save your policy updates.
4 On the left navigation pane, select Administration > Single Sign On > , and click Update
to upload the sp.xml le to vSphere.
Chapter 2 Configuring Tenant Settings
VMware, Inc. 87