Before you deploy and configure vRealize Automation in Cloud Foundation, you must provide specific configuration for an Active Directory user. This user acts as a service account for authentication in cross-application communication.

The service account provides non-interactive and non-human access to services and APIs to the vRealize Automation components of Cloud Foundation.

The service account is a standard Active Directory account that you configure in the following way:

  • The password never expires.
  • The user cannot change the password.
Source Destination Description Required Role
vRealize Automation Active Directory Service account for performing Active Directory domain join operations for computer accounts used by vRealize Automation IaaS components.
  • Account Operators Group
  • Delegation to Join Computers to Active Directory Domain
vRealize Automation
  • vRealize Automation
  • Microsoft SQL Server
Service account for access from vRealize Automation to vCenter Server and the Microsoft SQL Server instance.
  • Administrator
  • vRealize Orchestrator Administrator
Note: Delegation to Join Computers to Active Directory Domain is only required to deploy vRealize Automation. After deployment, it is no longer required.