7.3

Table Of Contents
d Specify the number of hours a Web application session open.
e Click Save.
6 Configure additional rules as appropriate.
7 Click Save.
Configuring Additional Identity Provider Connections
You can configure additional identity provider connections as needed to support different identity
management scenarios, including additional built-in identity providers and third-party identity providers.
You can create three types of identity provider connections using Directories Management.
n
Create Third-Party IDP - Use this item to create a connection to an external third-party identity
provider. Ensure that you have following before adding a third-party identity provider instance.
n
Verify that the third-party instances are SAML 2.0 compliant and that the service can reach the
third-party instance.
n
Obtain the appropriate third-party metadata information to add when you configure the identity
provider in the administration console. The metadata information you obtain from the third-party
instance is either the URL to the metadata or the actual metadata.
n
Create Workspace IDP - When you enable a connector to authenticate users during Directories
Management configuration, a Workspace IDP is created as the identity provider and password
authentication is enabled. You can configure additional workspace identity providers behind different
load balancers.
n
Create Built-in IDP - Built in Identity Providers use the internal Directories Management mechanisms
to support authentication. You can configure built-in identity providers to use authentication methods
that do not require the use of an on premises connector. When you configure the built-in provider, you
associate the authentication methods to use with the provider.
n
Configure a Third Party Identity Provider Connection
vRealize Automation is supplied with a default identity provider connection instance. Users may
want to create additional identity provider connections to support just-in-time user provisioning or
other custom configurations.
n
Configure Additional Workspace Identity Providers
When you configure a Directories Management connector to authenticate users, a Workspace IDP is
created and password authentication is enabled.
n
Configure a Built-in Identity Provider Connection
You can configure multiple built-in identity providers and associate authentication methods with
them.
Configure a Third Party Identity Provider Connection
vRealize Automation is supplied with a default identity provider connection instance. Users may want to
create additional identity provider connections to support just-in-time user provisioning or other custom
configurations.
Configuring vRealize Automation
VMware, Inc. 121