7.4

Table Of Contents
n
OpenLDAP - You can use the open source version of LDAP to support Directories Management user
authentication.
After you select a communication protocol and configure an Active Directory link, you can specify the
domains to use with the Active Directory configuration and then select the users and groups to sync with
the specified configuration.
Configure an Active Directory over LDAP/IWA Link
You can configure an Active Directory over LDAP/IWA link to support user authentication using the
Directories Management feature to configure a link to Active Directory to support user authentication for
all tenants and select users and groups to sync with the Directories Management directory.
For information and instructions about using OpenLDAP with Directories Management, see Configure an
OpenLDAP Directory Connection.
For Active Directory (Integrated Windows Authentication), when you have multi-forest Active Directory
configured and the Domain Local group contains members from domains in different forests, make sure
that the Bind user is added to the Administrators group of the domain in which the Domain Local group
resides. If you fail to do this, these members will be missing from the Domain Local group.
Prerequisites
n
Select the required default attributes and add additional attributes on the User Attributes page. See
Select Attributes to Sync with Directory.
n
List of the Active Directory groups and users to sync from Active Directory.
n
If your Active Directory requires access over SSL or STARTTLS, the Root CA certificate of the Active
Directory domain controller is required.
n
Log in to vRealize Automation as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click Add Directory and select Add Active Directory over LDAP/IWA.
3 On the Add Directory page, specify the IP address for the Active Directory server in the Directory
Name text box.
4 Select the appropriate Active Directory communication protocol using the radio buttons under the
Directory Name text box.
Option Description
Windows Authentication Select Active Directory (Integrated Windows Authentication). For Active
Directory Integrated Windows Authentication, required information includes the
domain's Bind user UPN address and password.
LDAP Select Active Directory over LDAP. For Active Directory over LDAP, information
required includes the Base DN, Bind DN, and Bind DN password.
Configuring vRealize Automation
VMware, Inc. 88