7.2

Table Of Contents
any unneeded applications and ensure that your deployment has appropriate memory allocated to Active
Directory. If problems persist, increase the Active Directory memory allocation as needed. For
deployments with large numbers of users and groups, you may need to increase the Active Directory
memory allocation to as much as 24 GB.
When running a synchronize operation for a vRealize Automation deployment with a many users and
groups, there may be a delay after the Sync is in progress message disappears before the Sync Log
details are displayed. Also, the time stamp on the log file may differ from the time that the user interface
indicates that the synchronize operation completed.
Note You cannot cancel a synchronize operation after it has been initiated.
Prerequisites
n
Connector installed and the activation code activated. Select the required default attributes and add
additional attributes on the User Attributes page.
n
List of the Active Directory groups and users to sync from Active Directory.
n
For Active Directory over LDAP, information required includes the Base DN, Bind DN, and Bind DN
password.
n
For Active Directory Integrated Windows Authentication, the information required includes the
domain's Bind user UPN address and password.
n
If Active Directory is accessed over SSL, a copy of the SSL certificate is required.
n
For Active Directory Integrated Windows Authentication, when you have multi-forest Active Directory
configured and the Domain Local group contains members from domains in different forests, make
sure that the Bind user is added to the Administrators group of the domain in which the Domain Local
group resides. If this is not done, these members are missing from the Domain Local group.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click the desired directory name.
3 Click Sync Settings to open a dialog with synchronization options.
4 Click the appropriate icon depending on whether you want to change the user or group configuration.
To edit the group configuration:
n
To add groups, click the + icon to add a new line for group DN definitions and enter the
appropriate group DN.
n
If you want to delete a group DN definition, click the x icon for the desired group DN.
Configuring vRealize Automation
VMware, Inc. 107