7.2

Table Of Contents
3 The service checks the rules in the policy and applies the policy with the ALL RANGES network
range since the user request is coming from a Web browser and from the ALL RANGES network
range.
The user logs in using the RSA SecurID authentication method, but the session just expired. The user
is redirected for reauthentication. The reauthentication provides the user with another four hour
session and the ability to launch the application. For the next four hours, the user can continue to
launch the application without having to reauthenticate.
Example 2 Stricter Web-Application-Specific Policy
For a stricter rule to apply to extra sensitve Web applications, you could require re-authentication With
SecureId on any device after 1 hour. The following is an example of how this type of policy access rule is
implemented.
1 User logs in from an inside the enterprise network using the password authentication method.
Now, the user has access to the apps portal for eight hours, as set up in Example 1.
2 The user immediately tries to launch a Web application with the Example 2 policy rule applied, which
requires RSA SecurID authentication.
3 The user is redirected to an identity provider that provides RSA SecurID authentication.
4 After the user successfully logs in, the service launches the application and saves the authentication
event.
The user can continue to launch this application for up to one hour but is asked to reauthenticate after
an hour, as dictated by the policy rule.
Manage the User Access Policy
vRealize Automation is supplied with a default user access policy that you can use as is or edit as needed
to manage tenant access to applications.
vRealize Automation is supplied with a default user access policy, and you cannot add new policies. You
can edit the existing policy to add rules.
Prerequisites
n
Select or configure the appropriate identity providers for your deployment. See Configure an Identity
Provider Instance.
n
Configure the appropriate network ranges for your deployment. See Add or Edit a Network Range.
n
Configure the appropriate authentication methods for your deployment. See Integrating Alternative
User Authentication Products with Directories Management.
n
If you plan to edit the default policy (to control user access to the service as a whole), configure it
before creating Web-application-specific policy.
n
Add Web applications to the Catalog. The Web applications must be listed in the Catalog page before
you can add a policy.
Configuring vRealize Automation
VMware, Inc. 121