Perform the necessary post-deployment configuration steps for the cross-region Workspace ONE Access cluster to enable identity management for the SDDC.
Procedure
Configure an Anti-Affinity Rule and a Virtual Machine Group for the Cross-Region Workspace ONE Access Cluster in Region A To protect the cross-region Workspace ONE Access nodes from a host-level failure, configure an affinity rule to run the virtual machines on different hosts in the first vSphere cluster of the Management domain. After that, you configure a VM group to define the startup order to ensure the vSphere High Availability powers on the cross-region Workspace ONE Access cluster members in the correct order.
Configure NTP on the Cross-Region Workspace ONE Access Cluster in Region A To keep the cross-region Workspace ONE Access cluster nodes synchronized with the other SDDC components, configure the time synchronization on each node in the cross-region Workspace ONE Access cluster.
Configure Custom Branding for the Cross-Region Workspace ONE Access Deployment in Region A To personalize the sign-in screen for your organization, you configure the branding of the cross-region Workspace ONE Access deployment.
Configure Identity Sources for the Cross-Region Workspace ONE Access Cluster in Region A You integrate your Active Directory with Workspace ONE Access and configure attributes to synchronize users and groups to enable identity and access management in the SDDC.
Add the Cross-Region Workspace ONE Access Nodes as Identity Provider Connectors in Region A To provide high availability for the identity and access management services of the cross-region Workspace ONE cluster, you join the cluster nodes to the rainpole.local
domain and add them as directory connectors.
Assign Roles to User Groups in Cross-Region Workspace ONE Access Workspace ONE Access uses role-based access control to manage administrator roles. You assign the Super Admin , Directory Admin , and ReadOnly roles to directory user groups to manage administrative access to the cross-region Workspace ONE Access cluster.
Assign Roles to User Groups in vRealize Suite Lifecycle Manager To enable identity and access management for vRealize Suite Lifecycle Manager, you integrate the component with the cross-region Workspace ONE Access deployment.