Identity and access management services in the SDDC are provided by VMware Workspace ONE Access. You use vRealize Suite Lifecycle Manager to deploy the cross-region Workspace ONE Access cluster. You then perform the necessary post-deployment configurations and customization.
Procedure
Deploy the Cross-Region Workspace ONE Access Cluster in Region A You configure deployment details and deploy the cross-region Workspace ONE Access cluster by using vRealize Suite Lifecycle Manager.
Post-Deployment Configuration of the Cross-Region Workspace ONE Access Cluster in Region A Perform the necessary post-deployment configuration steps for cross-region Workspace ONE Access to enable identity management for the SDDC.
Configure Identity Sources for the Cross-Region Workspace ONE Access Cluster in Region A To enable identity and access management in the SDDC, you integrate your Active Directory with the cross-region Workspace ONE Access and configure attributes to synchronize users and groups.
Add the Cross-Region Workspace ONE Access Nodes as Identity Provider Connectors in Region A To provide high availability for the identity and access management services of the cross-region Workspace ONE cluster, you join the cluster nodes to the Rainpole.io domain and add them as directory connectors.
Assign Roles to User Groups in Cross-Region Workspace ONE Access in Region A Workspace ONE Access uses role-based access control to manage administrator roles. You assign the Directory Admin and ReadOnly roles to directory user groups to manage administrative access to the cross-region Workspace ONE Access cluster.
Assign Roles to User Groups in vRealize Suite Lifecycle Manager in Region A To enable identity and access management for vRealize Suite Lifecycle Manager, you integrate the component with Workspace ONE Access.