7.3

Table Of Contents
action. If problems occur, close unneeded applications and verify that your deployment has appropriate
memory allocated to Active Directory. If problems continue, increase the Active Directory memory
allocation. For deployments with large numbers of users and groups, you might need to increase the
Active Directory memory allocation to as much as 24 GB.
When you sync a vRealize Automation deployment with a many users and groups, there might be a delay
before the Log details are available. The time stamp on the log file can differ from the completed time
displayed on the console.
If members of a group are not in the Users list, when you add the group from Active Directory, the
members are added to the list. When you sync a group, any users that do not have Domain Users as
their primary group in Active Directory are not synced.
Note You cannot cancel a synchronize action after you start the action.
Prerequisites
n
Connector installed and the activation code activated. Select the required default attributes and add
additional attributes on the User Attributes page.
See Select Attributes to Sync with Directory in Configuring vRealize Automation.
n
List of the Active Directory groups and users to sync from Active Directory.
n
For Active Directory over LDAP, information required includes the Base DN, Bind DN, and Bind DN
password.
n
For Active Directory Integrated Windows Authentication, the information required includes the
domain's Bind user UPN address and password.
n
If Active Directory is accessed over SSL, a copy of the SSL certificate is required.
n
If you have a multi-forest Active Directory integrated with Windows Authentication and the Domain
Local group contains members from different forests, do the following. Add the Bind user to the
Administrators group of the Domain Local group. If the Bind user is not added, these members are
missing from the Domain Local group.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click the desired directory name.
3 Click Sync Settings to open a dialog box with synchronization options.
4 Click the appropriate icon depending on whether you want to change the user or group configuration.
To edit the group configuration:
n
To add groups, click the + icon to add a line for group DN definitions and enter the appropriate
group DN.
n
If you want to delete a group DN definition, click the x icon for the desired group DN.
Configuring vRealize Automation
VMware, Inc. 106