7.4

Table Of Contents
When using a custom identity provider, Directories Management uses SAML metadata from that provider
to establish a trust relationship with the provider. After this relationship is established, Directories
Management maps the users from the SAML assertion to the list of internal vRealize Automation users
based the subject name ID.
Prerequisites
n
Configure the network ranges that you want to direct to this identity provider instance for
authentication. See Add or Edit a Network Range.
n
Access to the third-party metadata document. This can be either the URL to the metadata or the
actual metadata.
n
Log in to vRealize Automation as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Identity Providers.
This page displays all configured Identity Providers.
2 Click Add Identity Provider.
A menu appears with Identity Provider options.
3 Select Create Third Party IDP.
4 Enter the appropriate information to configure the identity provider.
Option Description
Identity Provider Name Enter a name for this identity provider instance.
SAML Metadata Add the third party IdPs XML-based metadata document to establish trust with the identity
provider.
1 Enter the SAML metadata URL or the xml content into the text box.
2 Click Process IdP Metadata. The NameID formats supported by the IdP are extracted from
the metadata and added to the Name ID Format table.
3 In the Name ID value column, select the user attribute in the service to map to the ID formats
displayed. You can add custom third-party name ID formats and map them to the user
attribute values in the service.
4 (Optional) Select the NameIDPolicy response identifier string format.
Users Select the Directories Management directories of the users that can authenticate using this
identity provider.
Just-in-Time User
Provisioning
Select the appropriate options to support just-in-time provisioning using an appropriate third party
identity provider.
Enter the Directory Name to use for just-in-time provisioning.
Enter one or more Domains that exist within the external identity provider that you will use for
just-in-time provisioning.
Network The existing network ranges configured in the service are listed.
Select the network ranges for the users, based on their IP addresses, that you want to direct to
this identity provider instance for authentication.
Configuring vRealize Automation
VMware, Inc. 122