EBC Identity Federation
EBC is configured to use the EBC Directory by default. This identity source is based on SAML and built upon Keycloak.
You have the option to use your own federation solution as an identity source. Examples of common identity sources that have SAML capabilities are:
-
Microsoft Active Directory Federation Services (ADFS)
-
Microsoft Azure AD
-
Redhat Single Sign-On
-
VMware Identity Manager
EBC Directory
Members of the “Organization Administrator” group in the EBC Directory can manage other user accounts.
This is performed by the following tasks.
-
Go to the Directory, enter your administrator credentials, and click Log In.
-
Go to Manage > Users and click View all users.
Click a user account to edit it. You can:
-
Edit name details
-
Reset Password
-
Add or Remove user accounts
-
Add or Remove group memberships (Organization Administrator, Catalog Author, Console Access Only, vApp Author and vApp user)
-
Access using a different identity source
Your organization is configured within the EBC Directory by default and you can access the directory through an alternate identity source. This directory supports:
-
User and group management
-
Multi-factor authentication
It is possible to move from the EBC Directory to another SAML based identity provider when required. Before changing the identity provider, you need to create a new vCloud Directory local user with Organization Administrator permissions and test that the user can login with the correct permissions.
Use the following link to bypass redirecting to the EBC Directory:
https://cloud.equinix-managed-services.nl/login/
API Access
Access to the EBC vCloud Directory API is required for automation purposes. Examples of automation tools that can be used are calls based on Terraform, Ansible, Python, or XML / JSON. API access is available, but filtered for security reasons.
Send your access request to our Support Desk and list the public IP addresses your company uses, to access the internet.
Create an internal user in the vCloud Directory for authentication to the API.