Multi-tenancy overview for VMware Aria Suite Lifecycle products
VMware Aria Suite Lifecycle
productsThis section describes multi-tenancy concepts and terminology.
- Tenant - It is the highest level in an organizational structure inVMware Workspace ONE Access. All objects like directories, users, groups, third party IDPs are maintained individually for each tenant. Each tenant is isolated from the rest of the tenants and they do not share any resource with each other.
- Primary Tenant - There is always at least one tenant (primary, default or base) present in theVMware Workspace ONE Accesswhich is called as primary tenant.ForVMware Aria Automationusers, the primary tenant name is formed based on the firstVMware Workspace ONE Accessnode that get is deployed and bootstrapped. For example, ifidm1.vmwlab.localis the firstVMware Workspace ONE Accessnode deployed, when you bootstrapVMware Workspace ONE Access, the primary tenant is created with nameidm1. Nodes that are scaled out, such asidm2.vmwlab.localandidm3.vmwlab.localare not affected. The primary tenant name is formed only once and remains the same in a single or clustered instance.
- Primary Tenant Alias - You cannot create sub tenants inVMware Workspace ONE Accessunder the primary tenant until specific configurations are set and enabled. Setting an alias name for the primary tenant is required. You must create an alias on the primary tenant. The primary tenant should be accessed through the primary tenant alias FQDN on a single node or a clustered instance.
- Provider Admin - An admin who owns the management infrastructure, that includesVMware Workspace ONE Access,VMware Aria Automationand other products. The admin creates and manages all the tenants and associates products with tenants. TheVMware Aria Suite Lifecycleadmin user,admin@localis the only provider admin and is authorized to perform tenant management functionalities.
- Tenant Admin - An admin with the highest level of administrative permission in eachVMware Workspace ONE Accesstenant. This permission can be assigned to both localVMware Workspace ONE Accessusers and Active Directory users present within theVMware Workspace ONE Accesstenant.
- Tenant Aware Products - Products that support multi-tenancy and maintains proper isolation with each logical tenant instance are tenant aware products. They have one to one mapping withVMware Workspace ONE Accesstenants.
- VMware Aria AutomationOrganization and Organization Owner - InVMware Aria Automation, organization is the top-level construct and it maps 1:1 withVMware Workspace ONE Accesstenant. Organization Owner has administrative permission in theVMware Aria AutomationOrganization or tenant. While adding tenants and associatingVMware Aria Automationwith the newly added tenant, theVMware Workspace ONE Accesstenant admin becomes the organization owner for the new tenant. For more information on adding tenants, see Add tenants.
- Directory - Directories are second level of objects inVMware Workspace ONE Access. It represents an external identity store or provider like Active Directory (AD) or an OpenLDAP server. There are multiple variants of directory supported inVMware Workspace ONE Access. You can add Active Directory Over LDAP and Active Directory with IWA in the Directory Management section.
- Directory Synchronization - While adding directories, configuration options are provided to filter and synchronize the required users and groups from the identity store or provider to theVMware Workspace ONE Accessdatabase. Only after a successful sync, you can integrate the users and groups withVMware Workspace ONE Access.
- Directories in tenant - Each tenant can contain several directories. The same directory configuration can be present in multiple tenants, however, it is considered a separate directory. For example: You have added Directory A in primary tenant with some directory configurations (User DNs, Group DNs, Sync configurations). And you have two sub-tenants named Tenant-1 and Tenant-2. The same directory configurations of directory A can be used on to add directories A1 and A2 on each of the sub-tenants respectively, so that the same set of users and groups are synced in sub-tenants - Tenant-1 and Tenant-2. After adding, any changes to the sync configurations of directory A in primary tenant will not affect directories A1 and A2 and its synced users and groups in Tenant-1 and Tenant-2. All three directories and its configurations are independent of each other. All three directories are affected only if the external identity store or provider changes. For example, if users or groups are getting removed directly from the Identity provider then it influences all three directories in all three tenants.
Multi-Tenancy Model
