7.2

Table Of Contents
c Click Add Identity Provider and provide the configuration information.
Option Action
Identity Provider Name Enter a name for the new Identity Provider.
Identity Provider Metadata (URI or
XML) text box
Paste the contents of your SSO2 idp.xml metadata file in the text box and
click Process IDP Metadata.
Name ID Policy in SAML Request
(Optional)
Enter http://schemas.xmlsoap.org/claims/UPN.
Users Select the domains to which you want users to have access privileges.
Network Select the network ranges from which you want users to have access
privileges.
If you want to authenticate users from an IP addresses, select All Ranges.
Authentication Methods Enter a name for the authentication method. Then, use the SAML Context
drop down menu to the right to map the authentication method to
urn:oasis:names:tc:SAML:2.0:ac:classes:Password.
SAML Signing Certificate Click the link beside the SAML Metadata heading to download the Directories
Management metadata.
d Save the Directories Management metadata file as sp.xml.
e Click Add.
3 Update the relevant authentication policy using the Directories Management Policies page to redirect
authentication to the third party SSO2 identity provider.
a Select Administration > Directories Management > Policies.
b Click the default policy name.
c Click the authentication method under the Policy Rules heading to edit the existing
authentication rule.
d On the Edit a Policy Rule page, change the authentication method from password to the
appropriate method.
In this case, the method should be SSO2.
e Click Save to save your policy updates.
4 On the left navigation pane, select Administration > Single Sign On > Configuration, and click
Update to upload the sp.xml file to vSphere.
Add Users or Groups to an Active Directory Connection
You can add users or groups to an existing Active Directory connection.
The Directories Management user authentication system imports data from Active Directory when adding
groups and users, and the speed of the system is limited by Active Directory capabilities. As a result,
import operations may require a significant amount of time depending on the number of groups and users
being added. To minimize the potential for delays or problems, limit the number of groups and users to
only those required for vRealize Automation operation. If performance degrades or if errors occur, close
Configuring vRealize Automation
VMware, Inc. 106