The Active Directory with LDAP authentication and VMware Enterprise Systems Connector provides the same functionality as traditional AD & LDAP authentication. This model functions across the cloud for Software as a Service (SaaS) deployments.


  • End users authenticate with existing corporate credentials.
  • Requires no firewall changes, as communication is initiated from the VMware Enterprise Systems Connector within your network.
  • Transmission of credentials is encrypted and secure.
  • Offers secure configuration to other infrastructure such as BES, Microsoft ADCS, SCEP, and SMTP servers.
  • Can be used for Workspace ONE ™ Direct Enrollment.


  • Requires VMware Enterprise Systems Connector to be installed behind the firewall or in a DMZ.
  • Requires extra configuration.

SaaS Deployment Model

This diagram shows the VMware cloud connector serving Workspace ONE in the cloud through the firewall while at the same time accessing internal network resources.

On-premises Deployment Model

This diagram shows a device accessing device services in a DMZ which is being served through a firewall by internal network resources.