7.2

Table Of Contents
n
In the Identity Provider column, select the IdP to view, edit or disable. See Configure an Identity
Provider Instance.
n
In the Associated Directory column, access the directory associated with this worker.
n
Click Join Domain to join the connector to a specific Active Directory domain. For example when you
configure Kerberos authentication, you must join the Active Directory domain either containing users
or having trust relationship with the domains containing users.
n
When you configure a directory with an Integrated Windows Authentication Active Directory, the
connector joins the domain according to the configuration details.
Connectors in a Clustered Environment
In a distributed, vRealize Automation deployment, all available connectors perform any required user
authorization, while a single designated connector handles all configuration synchronization. Typically,
synchronization would include additions, deletions, or changes to the user configuration, and
synchronization occurs automatically as long as all connectors are available. There are some specific
situations in which automatic synchronization may not occur.
For changes related to directory configuration, such as base dn, vRealize Automation attempts to
automatically push updates to all connectors in a cluster. If a connector is inoperable or unreachable for
some reason, that connector will not receive the update, even when it resumes online operation. To
implement configuration changes to connectors that may not have received them automatically, system
administrators must manually save the changes to all applicable connectors.
For directory sync profile related changes, vRealize Automation attempts to automatically push updates
to all connectors as well. If the sync connector is operational, the update is saved and pushed to all
available authorization connectors. If one or more connectors is unreachable, the system admin receives
a warning indicating that not all connectors were updated. If the sync connector is inoperable, the update
fails and an error occurs. If the system admin changes the connector designated as the sync connector,
the new sync connector receives the latest available profile information, and this information is pushed to
all applicable, and available, connectors.
Join a Connector Machine to a Domain
In some cases, you may need to join a machine containing a Directories Management connector to a
domain.
For Active Directory over LDAP directories, you can join a domain after creating the directory. For Active
Directory (Integrated Windows Authentication) directories, the connector is joined to the domain
automatically when you create the directory. In both cases, you must supply the appropriate credentials.
To join a domain, you need Active Directory credentials that have the privilege to "join computer to AD
domain". This is configured in Active Directory with the following rights:
n
Create Computer Objects
n
Delete Computer Objects
When you join a domain, a computer object is created in the default location in Active Directory.
Configuring vRealize Automation
VMware, Inc. 112