Configure AirWatch and Sync AD Users to Main IDM Tenant

Now that you have logged in and accessed the Administrator Console for both your Main IDM Tenant and IDP IDM Tenant, we will configure AirWatch to sync our corp.local domain users to the Main IDM Tenant.  

1. Configure Directory Services

In the AirWatch Console,

  1. Click Groups & Settings.
  2. Click All Settings.

1.1. Override Directory Services

  1. Click System.
  2. Click Enterprise Integration.
  3. Click Directory Services.
  4. Click Override for Current Setting.

1.2. Configure Directory Services Manually

Click Skip wizard and configure manually.

1.3. Save Directory Services

You'll notice that all of the Directory Services settings are still configured from our parent configuration.  You won't need to make any additional configurations.

  1. Scroll down to the bottom.
  2. Click Test Connection.
  3. Ensure you receive the Connection successful with the given server name, bind user name, and password confirmation message.
  4. Click Save.

Question - Why are we overriding the Directory Services settings if we are not making any changes at our Organization Group level?

To establish integration with VMware Identity Manager, which we will be doing soon to sync our corp.local AD users, Directory Services must be configured at that same Organization Group level.  Directory Services cannot be inherited for this integration to work, so we are only overriding the settings so that we can also establish a connection to our Main VMware Identity Manager Tenant from AirWatch in the upcoming steps.

1.4. Close the Directory Services Settings

  1. Confirm the Saved Successfully prompt is shown.
  2. Click Close.

2. Add User Group

  1. Click Accounts.
  2. Click User Groups.
  3. Click List View.
  4. Click Add.
  5. Click Add User Group.

2.1. Search for the Users Organizational Unit

  1. Select Directory for the Type.
  2. Select Organizational Unit for the External Type.
  3. Enter "Users" for the Search Text.
  4. Click Search.
  5. Select Users.

2.2. Use Custom User Group Settings

  1. Scroll down to the bottom.
  2. Select Custom for User Group Settings.

NOTE - DO NOT click Save yet.

2.3. Configure Custom User Group Settings

  1. Set Auto Merge Changes to Enabled.
  2. Set Maximum Allowable Changes to "100".
  3. Set Add Group Members Automatically to Enabled.
  4. Click Save.

2.4. Sync User Group to Add Users

  1. Click the checkbox by the Users user group you created to select it.
  2. Click Sync.
  3. Click OK when asked to confirm the Sync action.

2.5. Confirm Users Were Added

  1. You may need to scroll to the right to view the Users count for the Users group.
  2. Confirm the Users count shows 26.

3. Integrate VMware Identity Manager

  1. Click Getting Started.
  2. Click the Getting Started dropdown.
  3. Click Workspace ONE.
  4. You may need to expand the SETUP section by clicking the Plus button.
  5. Click Configure under Enterprise Connector & Directory.

3.1. Connect to Your MAIN VMware Identity Manager Tenant

  1. Enter your Main IDM Tenant URL for the Tenant URL field.  This should be "https://{yourTenant}.vidmpreview.com".  DO NOT use the Tenant URL that contains "-idp.vidmpreview.com".
  2. Enter "Administrator" for the User name.
  3. Enter "VMware1!" for the Password.
  4. Click Test Connection.
  5. Ensure the Test connection successful! prompt displays.
  6. Click Continue.

3.2. Configure and Save VMware Identity Manager Integration

  1. Select Yes for Do you want to use AirWatch to authenticate users.
  2. Click Save.
  3. Click Finish.
  1. Click Groups & Settings.
  2. Click All Settings.

3.4. Sync VMware Identity Manager

  1. Click System.
  2. Click Enterprise Integration.
  3. Click VMware Identity Manager.
  4. Scroll down to the bottom.
  5. Click Sync Now.
  6. Click Close.

4. Confirm Users Have Synced to Main VMware Identity Manager Tenant

  1. Click the tab for your Main IDM Tenant Administrator Console.
    NOTE - Be sure you are accessing your MAIN IDM Tenant.  The URL should be https://{tenantName}.vidmpreview.com.
  2. Click Users & Groups.
  3. Confirm you see the 4 corp.local users synced from AirWatch.

0 Comments

Add your comment

E-Mail me when someone replies to this comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.