7.2

Table Of Contents
Table 23. Directories Management Settings (Continued)
Setting Description
Identity Providers The Identity Providers page lists identity providers that are available on your system. vRealize
Automation systems contain a connector that serves as the default identity provider and that
suffices for many user needs. You can add third-party identity provider instances or have a
combination of both.
See Configure an Identity Provider Instance.
Policies The Policies page lists the default access policy and any other web application access policies you
created. Policies are a set of rules that specify criteria that must be met for users to access their
application portals or to launch Web applications that are enabled for them. The default policy
should be suitable for most vRealize Automation deployments, but you can edit it if needed. See
Manage the User Access Policy.
Important Concepts Related to Active Directory
Several concepts related to Active Directory are integral to understanding how Directories Management
integrates with your Active Directory environments.
Connector
The connector, a component of the service, performs the following functions.
n
Syncs user and group data your active Directory or LDAP directory to the service.
n
When being used as an identity provider, authenticates users to the service.
The connector is the default identity provider. For the authentication methods the connector supports,
see VMware Identity Manager Administration. You can also use third-party identity providers that
support the SAML 2.0 protocol. Use a third-party identity provider for an authentication type the
connector does not support or for an authentication type the connector does support, if the third-party
identity provider is preferable based on your enterprise security policy.
Note If you use third-party identity providers, you can either configure the connector to sync user
and group data or configure Just-in-Time user provisioning. See the Just-in-Time User Provisioning
section in VMware Identity Manager Administration for more information.
Note Even if you use third-party identity providers, you must configure the connector to sync user
and group data.
Directory
The Directories Management service has its own concept of a directory, corresponding to the Active
Directory or LDAP directory in your environment. This directory uses attributes to define users and
groups.
n
Active Directory
n
Active Directory over LDAP. Create this directory type if you plan to connect to a single Active
Directory domain environment. For the Active Directory over LDAP directory type, the connector
binds to Active Directory using simple bind authentication.
Configuring vRealize Automation
VMware, Inc. 89