Configure Control Room for Active Directory: auto mode
Configure the Control Room to authenticate users using Active Directory by enabling the Control Room to discover and list domains and sites in your organization.
To configure the Control Room when you start it for the first time, do the following:
Double-click the Automation Anywhere
Control Room icon on your desktop.
The Configure Control Room settings page appears.
Type the repository path.
This is the location where the uploaded automation files, for example, IQ Bots, and TaskBots are stored. For example, C:\ProgramData\AutomationAnywhere\Server Files.
Enter the access URL.
This is the URL for accessing your installation of Control Room.
Click Save and continue.
Warning: The back button of your web browser is automatically disabled after you click Save and continue. This ensures that the Credential Vault Master Key that generates matches the repository path and Control Room access URL.The Credential Vault settings page appears.
To return to the Configure Control Room settings page, press Ctrl plus F5 and restart.
Select from the following options:
- Express mode: The system stores your master key to connect to the Credential Vault. This option is not recommended for a production environment.
- Manual mode: You store the Master Key
on your own, and then provide the Master Key when the Credential Vault is locked. Users use the Master Key
to connect to the Credential Vault to secure their credentials and
access them when creating and running TaskBots.Warning: If you lose the key, you will not be able to access the Control Room.
Click Save and continue.
Warning: The back button of the web browser is automatically disabled after you click Save and continue. No further changes to the Control Room configuration or Credential Vault settings are allowed.
To make changes, reinstall the Control Room.The Authentication type for Control Room users page appears.
Select Active Directory.
Automation Anywhere supports Active Directory Multi-Forest authentication for the Control Room. Before providing the Authentication Type, ensure the following:
- One-way or two-way trust is set up between all forests. For a one-way trust, this is from the Bot agent to the Control Room forest (Control Room forest must always be the trusting forest).
- Two-way trust is set up for every domain in a forest.
- The root certificate of the LDAP server is imported using the provided CertMgr tool via command.
- The provided LDAP URLs per forest cannot be behind a load balancer. Also, all LDAP URLs must point to the root (main) domain controllers.
- The node that runs the Control Room is in the same domain network where the Active Directory runs.
- The user is in the parent domain and the URL points to the parent.
This ensures that when there are two or more forests, and one of the forest has a sub-domain with a different name space, a user from the other forests does not have permission to access that sub-domain.
Type the Domain username.
Ensure you use the User Principal Name (UPN) in the email@example.com format.The username you enter is for a user who has access to all domains using the same credentials.
Type the Domain password.
This user is not expected to use the Control Room. Although you have an option to update the password, use an Account with the password never expires option. If it expires, it can be updated but with some downtime.
Click Discover connections.
All discovered Active Directory domains with one or more sites per domain are shown.By default, all domains and sites are selected. If only one domain and one site under it is discovered, then it is shown in read-only mode and cannot be edited.You can configure the maximum number of sites per domain that can be discovered across multiple domains by adding the following property in the um.properties file saved in <installation path>/config:
um.ldap.auto.discovery.find.max.sites=<number of sites>
For example, you can configure auto-discovery for a maximum of 15 sites per domain by adding the entry
um.ldap.auto.discovery.find.max.sites=15in the um.properties file. This means that for every domain that you have, a maximum of 15 associated sites can be discovered per domain.Note: If this property is not configured, by default, 10 sites per domain will be discovered.
Select the domains and sites to use for authentication.
Select the domains and sites to use for authentication. Select a minimum of one site for each domain that is selected
- Click Test connections to register the sites to use for authentication.
Click Check connection.
If Control Room is unable to connect to the Active Directory database, an error message appears.
The Control Room first administrator page appears.
- Select the Active Directory domain from the drop-down list and type the Control Room administrator username.
Click Check name in Active Directory.
If the username is in the Active Directory the following user details are shown:
- First name
- Last name
You can edit these pre-populated fields.
Click Save and log in.
You are logged in to the Control Room as an administrator. You can now configure and manage the overall RPA environment with Control Room and Bot agent.
After configuring the Control Room, install product licenses.