You can set up vRealize Automation to use an external vRealize Orchestrator server.

System administrators can configure the default vRealize Orchestrator server globally for all tenants. Tenant administrators can configure the vRealize Orchestrator server only for their tenants.

Connections to external vRealize Orchestrator server instances require the user account to have view and run permissions in vRealize Orchestrator.

  • Single Sign-On authentication. The user information is passed to vRealize Orchestrator with the XaaS request and the user is granted view and run permissions for the requested workflow.
  • Basic authentication. The provided user account must be a member of a vRealize Orchestrator group with view and run permissions or the member of the vcoadmins group.


  • Install and configure an external vRealize Orchestrator Appliance. See Installing and Configuring vRealize Orchestrator in the vRealize Orchestrator product documentation.
  • Log in to the vRealize Automation console as a system administrator or tenant administrator.


  1. Select Administration > vRO Configuration > Server Configuration.
  2. Click Use an external Orchestrator server.
  3. Enter a name and, optionally, a description.
  4. Enter the IP or the DNS name of the machine on which the vRealize Orchestrator server runs in the Host text box.
    Note: If the external vRealize Orchestrator is configured to work in cluster mode, enter the IP address or host name of the load balancer virtual server that distributes the client requests across the vRealize Orchestrator servers in the cluster.
  5. Enter the port number to communicate with the external vRealize Orchestrator server in the Port text box.
    8281 is the default port for vRealize Orchestrator.
  6. Select the authentication type.
    Option Description
    Single Sign-On Connects to the vRealize Orchestrator server by using vCenter Single Sign-On.

    This option is applicable only if you configured the vRealize Orchestrator and vRealize Automation to use a common vCenter Single Sign-On instance.

    Basic Connects to the vRealize Orchestrator server with the user name and password that you enter in the User name and Password text boxes.

    The account that you provide must be a member of the vRealize Orchestrator vcoadmins group or a member of a group with view and run permissions.

  7. Click Test Connection.
  8. Click OK.
  9. Import the xaas.package package.
    1. Log in to the vRealize Automation Appliance as root.
    2. Locate the xaas.package package in the /usr/lib/vcac/content/o11n/ folder.
    3. Import the xaas.package package to the external Client.


You configured the connection to the external vRealize Orchestrator server, and imported the vCAC workflows folder and the related utility actions. The vCAC > ASD workflows folder contains workflows for configuring endpoints and creating resource mappings.

What to do next

Log in to the vRealize Orchestrator Client.