To import your users and groups into vRealize Automation using the Directories Management capability, you must connect to your Active Directory link.

Perform this procedure for each of your tenants.


Verify that you have access privileges to the Active Directory.


  1. Log in to the vRealize Automation console at: https://vra-appliance/vcac/org/tenant_name.
  2. Select Administration > Directories Management > Directories.
  3. Click Add Directory and select Add Active Directory over LDAP/IWA.
  4. Enter your Active Directory account settings.
    • Non-Native Active Directories


    Sample Input

    Directory Name

    Enter a unique directory name.

    Select Active Directory over LDAP when using non-Native Active Directory.

    This Directory Supports DNS Services

    Deselect this option.

    Base DN

    Enter the Distinguished Name (DN) of the starting point for directory server searches.

    For example, cn=users,dc=rainpole,dc=local.

    Bind DN

    Enter the full distinguished name (DN), including common name (CN), of an Active Directory user account that has privileges to search for users.

    For example, cn=config_admin infra,cn=users,dc=rainpole,dc=local.

    Bind DN Password

    Enter the Active Directory password for the account that can search for users.

    • Native Active Directories


    Sample Input

    Directory Name

    Enter a unique directory name.

    Select Active Directory (Integrated Windows Authentication) when using Native Active Directory.

    Domain Name

    Enter the name of the domain to join.

    Domain Admin Username

    Enter the user name for the domain admin.

    Domain Admin Password

    Enter the password for the domain admin account.

    Bind User UPN

    Use the email address format to enter the name of the user who can authenticate the domain.

    Bind DN Password

    Enter the Active Directory bind account password for the account that can search for users.

  5. Click Test Connection to test the connection to the configured directory.
  6. Click Save & Next.

    The Select the Domains page appears, and displays the list of domains.

  7. Accept the default domain setting and click Next.
  8. Verify that the attribute names are mapped to the correct Active Directory attributes, and click Next.
  9. Select the groups and users to synchronize.
    1. Click the New icon.
    2. Enter the user domain and click Find Groups.

      For example, enter dc=vcac,dc=local.

    3. To select the groups to synchronize, click Select and click Next.
    4. On the Select Users page, select the users to synchronize and click Next.
  10. Review the users and groups are syncing to the directory, and click Sync Directory.

    The directory synchronization takes some time and runs in the background.

  11. Select Administration > Directories Management > Identity Providers, and click your new identity provider.

    For example, WorkspaceIDP__1.

  12. Scroll to the bottom of the page, and update the value for the IdP Hostname property to point to the FQDN for the vRealize Automation load balancer.
  13. Click Save.
  14. Repeat steps 11–13 for each tenant and identity provider.
  15. After you upgrade all vRealize Automation nodes, log in to each tenant and select Administration > Directories Management > Identity Providers.

    Each identity provider has all vRealize Automation connectors added to it.

    For example, if your deployment has two vRealize Automation appliances, the identity provider has two associated connectors.