7.2

Table Of Contents
In addition to the provided properties, you can create your own custom properties. You must prefix you
custom properties with ext.policy.activedirectory. For example,
ext.policy.activedirectory.domain.extension or
ext.policy.activedirectory.yourproperty. The properties are passed to your custom
vRealize Orchestrator Active Directory workflows.
For more information about custom properties, see Custom Properties Reference. Depending on what
values you are overriding, you might need to create a property definition. For example, you might create a
property definition that retrieves the available Active Directory policies from vRealize Automation.
Alternatively, you might create definition that allows the requesting user to select from two or more
alternative organizational units. See Custom Properties Reference.
Create and Apply Active Directory Policies
You create one or more Active Directory policies so that you can assign different policies to different
business groups. You can use the different policies to add machine records to different organizational
units based on business group membership.
If necessary, you can override the assigned Active Directory policy.
Active Directory policies are a tech preview feature in vRealize Automation 7.1 and should not be used in
a production environment.
Procedure
1 Create an Active Directory Policy
You create an Active Directory policy to define where records are added in an Active Directory
instance when your users deploy machines. You can assign a policy to a business group so that all
machines deployed by the business group members result in a record created in the specified
organizational unit.
2 Scenario: Add a Custom Property to Blueprints to Override an Active Directory Policy
As a blueprint architect for the development business group, you have a blueprint that includes an
application machine and a database machine. You want the database machine record added to an
organizational unit that is different from the applied Active Directory policy.
Create an Active Directory Policy
You create an Active Directory policy to define where records are added in an Active Directory instance
when your users deploy machines. You can assign a policy to a business group so that all machines
deployed by the business group members result in a record created in the specified organizational unit.
You create different Active Directory policies when you want machines deployed by different business
groups to have different domains or to be added to different Active Directory instances.
Prerequisites
n
Verify that you created an Active Directory endpoint. See Configure the Active Directory Plug-In as an
Endpoint.
Configuring vRealize Automation
VMware, Inc. 318