7.2

Table Of Contents
Add Users or Groups to an Active
Directory Connection 6
You can add users or groups to an existing Active Directory connection.
The Directories Management user authentication system imports data from Active Directory when adding
groups and users, and the speed of the system is limited by Active Directory capabilities. As a result, import
operations may require a signicant amount of time depending on the number of groups and users being
added. To minimize the potential for delays or problems, limit the number of groups and users to only those
required for vRealize Automation operation. If performance degrades or if errors occur, close any unneeded
applications and ensure that your deployment has appropriate memory allocated to Active Directory. If
problems persist, increase the Active Directory memory allocation as needed. For deployments with large
numbers of users and groups, you may need to increase the Active Directory memory allocation to as much
as 24 GB.
When running a synchronize operation for a vRealize Automation deployment with a many users and
groups, there may be a delay after the Sync is in progress message disappears before the Sync Log details
are displayed. Also, the time stamp on the log le may dier from the time that the user interface indicates
that the synchronize operation completed.
N You cannot cancel a synchronize operation after it has been initiated.
Prerequisites
n
Connector installed and the activation code activated. Select the required default aributes and add
additional aributes on the User Aributes page.
n
List of the Active Directory groups and users to sync from Active Directory.
n
For Active Directory over LDAP, information required includes the Base DN, Bind DN, and Bind DN
password.
n
For Active Directory Integrated Windows Authentication, the information required includes the
domain's Bind user UPN address and password.
n
If Active Directory is accessed over SSL, a copy of the SSL certicate is required.
n
For Active Directory Integrated Windows Authentication, when you have multi-forest Active Directory
congured and the Domain Local group contains members from domains in dierent forests, make
sure that the Bind user is added to the Administrators group of the domain in which the Domain Local
group resides. If this is not done, these members are missing from the Domain Local group.
n
Log in to the vRealize Automation console as a tenant administrator.
Procedure
1 Select Administration > Directories Management > Directories.
2 Click the desired directory name.
VMware, Inc.
47