7.4

Table Of Contents
Procedure
1 Create an identity provider for Just-in-Time provisioning.
a Select Administration > Directories management > Identity Providers
b Click Add Identity Provider and edit the identity provider instance settings as appropriate.
n
For just in time provisioning, create a third party identity provider.
n
In the Create Just-in-Time Directory section, enter names for the directory and one or more
domains.
n
You must select a network for the third party identity provider configuration.
n
If you are using an external VMware Identity Manager as your third party identity provider,
and you are using userPrincipleName to authenticate users, you must change the Name ID
mapping configuration for userPrincipleName from the default of x509SubjectName to
unspecified.
See Configure a Third Party Identity Provider Connection for more information about creating
identity providers.
2 Configure SAML on the Just-in-Time identity provider.
a Copy IdP metadata from your identity provider.
b In vRealize Automation, select your identity provider and paste the IdP metadata into the Identity
Provider Metadata (URL or XML) text box.
c Click Save.
d In the Name ID policy in SAML Request (Optional) drop-down menu, select the appropriate
format.
For example, if you are using the emal address as the unique user identifier, you would select
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress.
e Select the appropriate directory under the Users heading.
f Select the networks for use by this identity provider under the Network heading.
g Specify an appropriate name in the Authentication Methods text box.
h In the SAML Context drop down, select urn:oasis:names:tc:SAML:
2.0:ac:classes:PasswordProtectedTransport
i Right-click the Service Provider (SP) Metadata link, and open it in a separate browser tab.
j Use this metadata to configure the SAML connection on your identity provider.
If you are using VMware Identity Manager see the VMware Identity Manager documentation for
complete instructions on configuring SAML.
3 Click Add.
The new directory is created using the Directory Name provided.
Configuring vRealize Automation
VMware, Inc. 108