nerdexam
Broadcom-VMware

2V0-15.25 · Question #14

An administrator attempts to add a new user (provideradmin05) within the VMware Cloud Foundation (VCF) Automation Provider Management Portal, however provideradmin05 cannot be found for import. The…

The correct answer is A. In VCF Operations, manually resync the directory. VMware Cloud Foundation (VCF) 9.x uses VMware Identity Broker (VIDB) as the central identity provider for the entire VCF fleet. VIDB synchronizes user and group metadata from the connected enterprise identity source, in this case Active Directory. When a user is added to an AD…

Section 5 – Troubleshoot VCF Support Solutions

Question

An administrator attempts to add a new user (provideradmin05) within the VMware Cloud Foundation (VCF) Automation Provider Management Portal, however provideradmin05 cannot be found for import. The following information is provided:

  • The existing VCF Fleet uses VMware Identity Broker (VIDB) for single

sign-on.

  • VIDB uses Active Directory as the identity provider.
  • A group named VCFA_ProviderAdmins was created in Active Directory,

populated with the appropriate user accounts and synchronized with VIDB.

  • Five days later provideradmin05 was added to VCFA_ProviderAdmins.

What will resolve this issue?

Options

  • AIn VCF Operations, manually resync the directory.
  • BIn the VCF Automation Provider Management Portal, enable the Advanced Rights Bundle Mode.
  • CIn VCF Operations, disable VCF SSO for VCF Automation.
  • DIn the VCF Automation Provider Management Portal, import provideradmin05 as an LDAP user.

How the community answered

(28 responses)
  • A
    82% (23)
  • B
    7% (2)
  • D
    11% (3)

Explanation

VMware Cloud Foundation (VCF) 9.x uses VMware Identity Broker (VIDB) as the central identity provider for the entire VCF fleet. VIDB synchronizes user and group metadata from the connected enterprise identity source, in this case Active Directory. When a user is added to an AD group after the group was already synced into VIDB, VIDB does not automatically resync group membership on demand unless a directory synchronization is performed. In this scenario, the group VCFA_ProviderAdmins was synchronized five days earlier. When the new user provideradmin05 was later added to the AD group, VIDB--and therefore the VCF Automation Provider Management Portal--does not recognize that new user until a manual directory resynchronization occurs from VCF Operations. This operation forces VIDB to: Requery Active Directory Update group membership information Repopulate available users for import into VCF Automation

Topics

#VIDB#Active Directory sync#identity provider#directory resync

Community Discussion

No community discussion yet for this question.

Full 2V0-15.25 Practice