7.4

Table Of Contents
Procedure
1 Select Administration > AD Policies.
2
Click the New icon ( ).
3 Configure the Active Directory policy details.
Option Description
ID Enter the permanent value.
The value cannot include any spaces or special characters.
You cannot change this value at a later time. You can only re-create the policy
with a different ID.
Description Describe of the policy.
Active Directory Endpoint Select the Active Directory endpoint for which this policy is created.
Domain Enter the root domain. The format is mycompany.com.
Organizational Unit Enter the organizational unit distinguished name for this policy.
The hierarchy must be entered as a comma-separated list. For example,
ou=development,dc=corp,dc=domain,dc=com.
4 Click OK.
The vRealize Orchestrator Active Directory endpoint is added to the list. You can apply the policy in
business groups or use the policy in blueprints or business groups.
What to do next
n
To provide multiple policy options, create more policies.
n
To add records to Active Directory based on business group membership when a blueprint is
deployed, add the appropriate Active Directory policy to a business group. See Create a Business
Group. You can apply the policy when you create the business group, or you can add it later.
n
To override the Active Directory policy for the business group for a particular blueprint, add Active
Directory custom properties to the blueprint. See Scenario: Add a Custom Property to Blueprints to
Override an Active Directory Policy.
Scenario: Add a Custom Property to Blueprints to Override an Active Directory Policy
As a blueprint architect for the development business group, you have a blueprint that includes an
application machine and a database machine. You want the database machine record added to an
organizational unit that is different from the applied Active Directory policy.
You have an existing policy that is applied to the development business group. The policy adds machine
records to ou=development,dc=corp,dc=domain,dc=com. You want all database machines to be added to
ou=databases,dc=corp,dc=domain,dc=com. In a blueprint that includes a database server, you override
the Active Directory organizational unit to add the database machine record to
ou=databases,dc=corp,dc=domain,dc=com.
Configuring vRealize Automation
VMware, Inc. 342