To import your users and groups into vRealize Automation using the Directories Management capability, you must connect to your Active Directory link.

About this task

Perform this procedure for each of your tenants.


Verify that you have access privileges to the Active Directory.


  1. Log in to the vRealize Automation console at: https://vra-appliance/vcac/org/tenant_name
  2. Select Administration > Directories Management > Directories.
  3. Click Add Directory.
  4. Enter your Active Directory account settings.
    • Non-Native Active Directories


    Sample Input

    Directory Name

    Enter a unique directory name.

    Select Active Directory over LDAP when using non-Native Active Directory.

    This Directory Supports DNS Services

    Deselect this option.

    Base DN

    Enter the distinguished name (DN) of the starting point for directory server searches.

    For example, cn=users,dc=rainpole,dc=local.

    Bind DN

    Enter the full distinguished name (DN), including common name (CN), of an Active Directory user account that has privileges to search for users.

    For example, cn=config_admin infra,cn=users,dc=rainpole,dc=local.

    Bind DN Password

    Enter the Active Directory password for the account that can search for users.

    • Native Active Directories


    Sample Input

    Directory Name

    Enter a unique directory name.

    Select Active Directory (Integrated Windows Authentication) when using Native Active Directory.

    Domain Name

    Enter the name of the domain to join.

    Domain Admin Username

    Enter the user name for the domain admin.

    Domain Admin Password

    Enter the password for the domain admin account.

    Bind User UPN

    Use the email address format to enter the name of the user who can authenticate the domain.

    Bind DN Password

    Enter the Active Directory bind account password for the account that can search for users.

  5. Click Test Connection to test the connection to the configured directory.
  6. Click Save & Next.

    The Select the Domains page appears, and displays the list of domains.

  7. Accept the default domain setting and click Next.
  8. Verify that the attribute names are mapped to the correct Active Directory attributes, and click Next.
  9. Select the groups and users to synchronize.
    1. Click the New icon.
    2. Enter the user domain and click Find Groups.

      For example, enter dc=vcac,dc=local.

    3. To select the groups to synchronize, click Select and click Next.
    4. On the Select Users page, select the users to synchronize and click Next.
  10. Review the users and groups you are syncing to the directory, and click Sync Directory.

    The directory synchronization takes some time and runs in the background.

  11. Select Administration > Directories Management > Identity Providers, and click your new identity provider.

    For example, WorkspaceIDP__1.

  12. Within the identity provider that you selected, add a connector for each node.
  13. Repeat steps 1-12 for each vRealize Automation appliance.
  14. Scroll to the bottom of the page, and update the value for the IdP Hostname property to point to the fully qualified domain name (FQDN) for the vRealize Automation load balancer.
  15. Click Save.
  16. Repeat steps 14–15 for each tenant and identity provider.

What to do next

Migrate a vRealize Automation Environment