7.1

Table Of Contents
Table 27. Default Active Directory Attributes to Sync to Directory (Continued)
Directory Attribute Name Default Mapping to Active Directory Attribute
lastName sn
rstName givenName
email mail
userName sAMAccountName
Managing Connectors
The Connectors page lists deployed connectors for your enterprise network. A connector syncs user and
group data between Active Directory and the Directories Management service, and when it is used as the
identity provider, authenticates users to the service.
In vRealize Automation, each vRealize Automation appliance contains its own connector, and these
connectors are suitable for most deployments.
When you associate a directory with a connector instance, the connector creates a partition for the associated
directory called a worker. A connector instance can have multiple workers associated with it. Each worker
acts as an identity provider. The connector syncs user and group data between Active Directory and the
service through one or more workers. You dene and congure authentication methods on a per worker
basis.
You can manage various aspects of an Active Directory link from the Connectors page. This page contains a
table and several buons that enable you to complete various management tasks.
n
In the Worker column, select a worker to view the connector's details and navigate to the Auth
Adapters page to see the status of the available authentication methods. For information about
authentication, see “Integrating Alternative User Authentication Products with Directories
Management,” on page 101.
n
In the Identity Provider column, select the IdP to view, edit or disable. See “Congure an Identity
Provider Instance,” on page 110.
n
In the Associated Directory column, access the directory associated with this worker.
n
Click Join Domain to join the connector to a specic Active Directory domain. For example when you
congure Kerberos authentication, you must join the Active Directory domain either containing users
or having trust relationship with the domains containing users.
n
When you congure a directory with an Integrated Windows Authentication Active Directory, the
connector joins the domain according to the conguration details.
Join a Connector Machine to a Domain
In some cases, you may need to join a machine containing a Directories Management connector to a domain.
For Active Directory over LDAP directories, you can join a domain after creating the directory. For Active
Directory (Integrated Windows Authentication) directories, the connector is joined to the domain
automatically when you create the directory. In both cases, you must supply the appropriate credentials.
To join a domain, you need Active Directory credentials that have the privilege to "join computer to AD
domain". This is congured in Active Directory with the following rights:
n
Create Computer Objects
n
Delete Computer Objects
When you join a domain, a computer object is created in the default location in Active Directory.
Configuring vRealize Automation
92 VMware, Inc.