7.4

Table Of Contents
Option Description
Authentication Methods Add the authentication methods supported by the third-party identity provider. Select the SAML
authentication context class that supports the authentication method.
SAML Signing Certificate Click Service Provider (SP) Metadata to see URL to Directories Management SAML service
provider metadata URL . Copy and save the URL. This URL is configured when you edit the
SAML assertion in the third-party identity provider to map Directories Management users.
Hostname If the Hostname field displays, enter the hostname where the identity provider is redirected to for
authentication. If you are using a non-standard port other than 443, you can set this as
Hostname:Port. For example, myco.example.com:8443.
5 Click Add.
What to do next
n
Copy and save the Directories Management service provider metadata that is required to configure
the third-party identity provider instance. This metadata is available either in the SAML Signing
Certificate section of the Identity Provider page.
n
Add the authentication method of the identity provider to the services default policy.
See the Setting Up Resources in Directories Management guide for information about adding and
customizing resources that you add to the catalog.
Configure Additional Workspace Identity Providers
When you configure a Directories Management connector to authenticate users, a Workspace IDP is
created and password authentication is enabled.
You can configure additional connectors to operate behind multiple load balancers. When your
deployment includes more than one load balancer, you can configure additional Workspace identity
providers for authentication in each load balancer configuration.
Procedure
1 Select Administration > Directories Management > Identity Providers.
This page displays all configured Identity Providers.
2 Click Add Identity Provider.
A menu appears with Identity Provider options.
3 Select Create Workspace IDP.
4 Enter the appropriate information to configure the identity provider.
Option Description
Identity Provider Name Enter the name for this built-in identity provider instance.
Users Select the users to authenticate. The configured directories are listed.
Users Select the group of users who can authenticate using this Workspace identity provider.
Configuring vRealize Automation
VMware, Inc. 123