Workspace ONE Access Implementation

Workspace ONE Access
provides identity and access management services for the vRealize Suite of products. You use
vRealize Suite Lifecycle Manager
to deploy a
Workspace ONE Access
instance. You then perform the necessary post-deployment configurations and customization.
VMware Cloud Foundation
supports both standard and clustered
Workspace ONE Access
deployments.
  • Download the installation binary directly from
    vRealize Suite Lifecycle Manager
    . See "Configure Product Binaries" in the
    vRealize Suite Lifecycle Manager Installation, Upgrade, and Management Guide
    for the version of
    vRealize Suite Lifecycle Manager
    listed in the
    VMware Cloud Foundation
    BOM.
  • Allocate IP addresses:
    Standard Deployment
    Clustered Deployment
    One IP address from the cross-instance NSX segment and prepare both forward (A) and reverse (PTR) DNS records.
    Five IP addresses from the cross-instance NSX segment and prepare both forward (A) and reverse (PTR) DNS records.
    • Three IP addresses for the clustered
      Workspace ONE Access
      instance.
    • One IP address for the embedded Postgres database for the
      Workspace ONE Access
      instance.
    • One IP address for the
      NSX
      external load balancer virtual server for clustered
      Workspace ONE Access
      instance.
  • Ensure you have enough storage capacity:
    • Required storage per node: 100 GB
    • Virtual disk provisioning: Thin
  • Verify that the management domain
    vCenter Server
    is operational.
  • Verify that the cross-instance NSX segment is available.
  • Verify that the
    NSX Manager
    is operational.
  • Verify the
    Prerequisite Checklist
    sheet in the
    Planning and Preparation Workbook
    .
  • Verify that required Active Directory bind service account is created.
    Verify that required Active Directory security groups are created.
  • Download the
    CertGenVVS
    tool and generate the signed certificate for the
    Workspace ONE Access
    instance. See KB 85527.