7.4

Table Of Contents
11 Click + to add additional users. For example, enter
CN=username,CN=Users,OU=myUnit,DC=myCorp,DC=com.
You can add organizational units as well as individual users here.
You can create a filter to exclude some types of users. Select the user attribute to filter by, the query
rule, and the value.
12 Click Next.
13 Review the page to see how many users and groups will sync to the directory and to view the default
sync schedule.
To make changes to users and groups, or to the sync frequency, click the Edit links.
14 Click Sync Directory to start the directory sync.
The connection to the LDAP directory is established and users and groups are synced from the LDAP
directory to the Directories Management directory.
You can now assign user and groups to the appropriate vRealize Automation roles by selecting
Administration > Users and Groups > Directory Users and Groups. See Assign Roles to Directory
Users or Groups for more information.
Limitations of LDAP Directory Integration
There are several important limitations related to LDAP Directory integration in Directories Management.
n
You can only integrate a single-domain LDAP directory environment.
To integrate multiple domains from an LDAP directory, you need to create additional
Directories Management directories, one for each domain.
n
The following authentication methods are not supported for Directories Management directories of
type LDAP directory.
n
Kerberos authentication
n
RSA Adaptive Authentication
n
ADFS as a third-party identity provider
n
SecurID
n
Radius authentication with Vasco and SMS Passcode server
n
You cannot join an LDAP domain.
n
Integration with View or Citrix-published resources is not supported for Directories Management
directories of type LDAP directory.
n
User names must not contain spaces. If a user name contains a space, the user is synced but
entitlements are not available to the user.
Configuring vRealize Automation
VMware, Inc. 97