SV-251789r916111_rule
V-251789
SRG-APP-000516-NDM-000336
TNDM-3X-000092
CAT I
10
To configure NSX-T to integrate with VMware Identity Manager or Workspace ONE Access as the authentication source, do the following:
From the NSX-T Manager web interface, go to System >> Users and Roles >> VMware Identity Manager and click "Edit".
If using an external load balancer for the NSX-T Management cluster, enable "External Load Balancer Integration". If using a cluster VIP, leave this disabled.
Click the toggle button to enable "VMware Identity Manager Integration".
Enter the VMware Identity Manager or Workspace ONE Access appliance name, OAuth Client ID, OAuth Client Secret, and certificate thumbprint as provided by the administrators.
Enter the NSX Appliance FQDN. For a cluster, enter the load balancer FQDN or cluster VIP FQDN.
Click "Save", import users and groups, and then assign them roles.
Ensure the VMware Identity Manager administrators have configured the certificate authentication adapter to provide two-factor authentication.
From the NSX-T Manager web interface, go to System >> Users and Roles >> VMware Identity Manager.
If the VMware Identity Manager integration is not enabled, this is a finding.
If the user is not redirected to VMware Identity Manager or Workspace ONE Access when attempting to log in to the NSX-T Manager web interface and prompted to select a certificate and enter a PIN, this is a finding.
V-251789
False
TNDM-3X-000092
From the NSX-T Manager web interface, go to System >> Users and Roles >> VMware Identity Manager.
If the VMware Identity Manager integration is not enabled, this is a finding.
If the user is not redirected to VMware Identity Manager or Workspace ONE Access when attempting to log in to the NSX-T Manager web interface and prompted to select a certificate and enter a PIN, this is a finding.
M
5449