Configure an Identity Source for Workspace
ONE Access
To enable identity and access management in the SDDC, you integrate your Active
Directory with
Workspace
ONE Access
and configure
attributes to synchronize users and groups.- In a web browser, log in toWorkspace ONE Accessby using the administration interface to theSystem Domainwithconfigadminuser (https://<wsa_fqdn>/admin).
- On the main navigation bar, clickIdentity and access management.
- Click theDirectoriestab, and from theAdd directorydrop-down menu, selectAdd Active Directory over LDAP/IWA.
- On theAdd directorypage, configure the following settings, clickTest connectionand clickSave and next.SettingValueDirectory nameEnter a name for directory.For example,sfo.rainpole.io.Active Directory over LDAPSelectedSync connectorSelect the FQDN ofvidm-primaryDo you want this connector to also perform authentication?YesDirectory search attributeSAMAccountNameThis Directory requires all connections to use STARTTLS (Optional)If you want to secure communication betweenWorkspace ONE Accessand Active Directory select this option and paste the Root CA certificate in the SSL Certificate box.Base DNEnter the Base Distinguished Name from which to start user searches.For example,cn=Users,dc=sfo,dc=rainpole,dc=io.Bind DNEnter the DN for the user to connect to Active Directory.For example,cn=svc-wsa-ad,ou=Service Accounts,dc=sfo,dc=rainpole,dc=io.Bind user passwordEnter the password for the Bind user.For example:svc-wsa-ad_password.
- On theSelect the domainspage, review the domain name and clickNext.
- On theMap user attributespage, review the attribute mappings and clickNext.
- On theSelect the groups (users) you want to syncpage, enter the distinguished name for the folder containing your groups (For exampleOU=Security Groups,DC=sfo,DC=rainpole,DC=io) and clickSelect.
- For eachGroup DNyou want to include, select the group to use byWorkspace ONE Accessfor each of the roles, and clickSavethenNext.ProductRole Assigned via GroupWorkspace ONE AccessSuper AdminDirectory AdminReadOnly AdminvRealize Suite Lifecycle ManagerVCF RoleContent AdminContent Developers
- On theSelect the Users you would like to syncpage, enter the distinguished name for the folder containing your users (e.g.OU=Users,DC=sfo,DC=rainpole,DC=io) and clickNext.
- On theReviewpage, clickEdit, from theSync frequencydrop-down menu, selectEvery 15 minutes, and clickSave.
- To initialize the directory import, clickSync directory.