7.4

Table Of Contents
Table 28. User Authentication Types Supported by Directories Management (Continued)
Authentication Types Description
Mobile SSO (for iOS) Mobile SSO for iOS authentication is used for single sign-on authentication for AirWatch-
managed iOS devices. Mobile SSO (for iOS) authentication uses a Key Distribution
Center (KDC) that is part of the Directories Management service. You must initiate the
KDC service in the VMware Identity Manager service before you enable this
authentication method.
Mobile SSO (for Android) Mobile SSO for Android authentication is used for single sign-on authentication for
AirWatch-managed Android devices. A proxy service is set up between the
Directories Management service and AirWatch to retrieve the certificate from AirWatch for
authentication.
Password (AirWatch Connector) The AirWatch Cloud Connector can be integrated with the Directories Management
service for user password authentication. You configure the
Directories Managementservice to sync users from the AirWatch directory.
Users are authenticated based on the authentication methods, the default access policy rules, network
ranges, and the identity provider instance you configure. After the authentication methods are configured,
you create access policy rules that specify the authentication methods to be used by device type.
Configuring SecurID for Directories Management
When you configure RSA SecurID server, you must add the service information as the authentication
agent on the RSA SecurID server and configure the RSA SecurID server information on the service.
When you configure SecurID to provide additional security, you must ensure that your network is properly
configured for your Directories Management deployment. For SecurID specifically, you must ensure that
the appropriate port is open to enable SecurID to authenticate users outside your network.
After you run the Setup wizard and configured your Active Directory connection, you have the information
necessary to prepare the RSA SecurID server. After you prepare the RSA SecurID server for
Directories Management, you enable SecurID in the administration console.
n
Prepare the RSA SecurID Server
The RSA SecurID server must be configured with information about the appliance as the
authentication agent. The information required is the host name and the IP addresses for network
interfaces.
n
Configure RSA SecurID Authentication
After Directories Management is configured as the authentication agent in the RSA SecurID server,
you must add the RSA SecurID configuration information to the connector.
Prepare the RSA SecurID Server
The RSA SecurID server must be configured with information about the appliance as the authentication
agent. The information required is the host name and the IP addresses for network interfaces.
Configuring vRealize Automation
VMware, Inc. 126