7.1

Table Of Contents
Table 1. Tenant Configuration
Configuration Area Description
Login URL Each tenant has a unique URL to the vRealize Automation console.
n
The default tenant URL is in the following format: hps://hostname/vcac
n
The URL for additional tenants is in the following format:
hps://hostname/vcac/org/tenantURL
Identity stores Each tenant requires access to one or more directory services, such as
OpenLDAP or Microsoft Active Directory servers, that are congured to
authenticate users. You can use the same directory service for more than one
tenant, but you must congure it separately for each tenant.
Branding A tenant administrator can congure the branding of the vRealize Automation
console including the logo, background color, and information in the header
and footer. System administrators control the default branding for all tenants.
Notication providers System administrators can congure global email servers that process email
notications. Tenant administrators can override the system default servers, or
add their own servers if no global servers are specied.
Business policies Administrators in each tenant can congure business policies such as approval
workows and entitlements. Business policies are always specic to a tenant.
Service catalog oerings Service architects can create and publish catalog items to the service catalog and
assign them to service categories. Services and catalog items are always specic
to a tenant.
Infrastructure resources The underlying infrastructure fabric resources, for example, vCenter servers,
Amazon AWS accounts, or Cisco UCS pools, are shared among all tenants. For
each infrastructure source that vRealize Automation manages, a portion of its
compute resources can be reserved for users in a specic tenant to use.
About the Default Tenant
When the system administrator congures an Active Directory link using Directories management during
the installation of vRealize Automation, a default tenant is created with the built-in system administrator
account to log in to the vRealize Automation console. The system administrator can then congure the
default tenant and create additional tenants.
The default tenant supports all of the functions described in Tenant Conguration. In the default tenant, the
system administrator can also manage system-wide conguration, including global system defaults for
branding and notications, and monitor system logs.
User and Group Management
All user authentication is handled by Active Directory links that are congured through Directories
Management. Each tenant has one or more Active Directory links that provide authentication on a user or
group level.
The system administrator performs the initial conguration of single sign-on and basic tenant setup,
including designating at least one Active Directory link and a tenant administrator for each tenant.
Thereafter, a tenant administrator can congure additional Active Directory links and assign roles to users
or groups as needed.
Tenant administrators can also create custom groups within their own tenants and add users and groups to
those groups. Custom groups can be assigned roles or designated as the approvers in an approval policy.
Tenant administrators can also create business groups within their tenants. A business group is a set of
users, often corresponding to a line of business, department or other organizational unit, that can be
associated with a set of catalog services and infrastructure resources. Users and custom groups can be added
to business groups.
Foundations and Concepts
VMware, Inc. 11