7.3

Table Of Contents
Setting up SAML between SSO2 and Directories Management involves configuration on the Directories
Management and SSO components.
Table 24. SAML Federation Component Configuration
Component Configuration
Directories Management Configure SSO2 as a third-party Identity Provider on Directories Management and update the
default authentication policy. You can create an automated script to set up
Directories Management.
SSO2 component Configure Directories Management as a service provider by importing the
Directories Management sp.xml file. This file enables you to configure SSO2 to use
Directories Management as the Service Provider (SP).
Prerequisites
n
Configure tenants for your vRealize Automation deployment. See Create Additional Tenants.
n
Set up an appropriate Active Directory link to support basic Active Directory user ID and password
authentication.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Download SSO2 Identity Provider metadata through the SSO2 user interface.
a Log in to vCenter as an administrator at https://<cloudvm-hostname>/ .
b Click the Log in to vSphere Web Client link.
c On the left navigation pane, select Administration > Single Sign On > Configuration.
d Click Download adjacent to the Metadata for your SAML service provider heading.
The vsphere.local.xml file should begin downloading.
e Copy the contents of the vsphere.local.xml file.
2 On the vRealize Automation Directories Management Identity Providers page, create a new Identity
Provider.
a Log in to vRealize Automation as a tenant administrator.
b Select Administration > Directories Management > Identity Providers.
Configuring vRealize Automation
VMware, Inc. 104