You can configure Omnissa Access as an identity provider for Apple Business Manager or Apple School Manager so that end users can log into Apple devices and services using their Omnissa Access credentials. This enables users' Omnissa Access accounts to be used as Managed Apple Accounts.
The integration process involves the following main tasks:
- Configuring your Omnissa Access directory for the Apple Business Manager or Apple School Manager integration
- Configuring federated authentication, with Omnissa Access as the identity provider for Apple Business Manager or Apple School Manager
- Configuring user provisioning to sync users from Omnissa Access to Apple Business Manager or Apple School Manager
- Configuring the Omnissa Security Events Service to transmit Omnissa Access security events to Apple
Note: While integration with both Apple Business Manager and Apple School Manager is supported, this document uses Apple Business Manager as an example.
Prerequisites
-
You have the following services:
- Omnissa Access Cloud
- Omnissa Connect
- Omnissa Intelligence
- Omnissa Security Events Service
- Apple Business Manager or Apple School Manager
-
You have the following privileges:
- Administrator role in Omnissa Access
- Organization Owner role in Omnissa Connect
- Administrator role in Apple Business Manager or Apple School Manager
- Active Directory Bind User credentials (required to update the directory configuration in Omnissa Access)
-
You have installed the Omnissa Access connector, including the following services:
- Directory Sync Service
- User Auth Service
-
You have created a directory in Omnissa Access that syncs with your Active Directory, and have verified that users and groups have been synced successfully to Omnissa Access.
-
You have added and verified your domain in Apple Business Manager or Apple School Manager. See Step 1: Verify a domain in the Apple documentation, Use federated authentication with your identity provider in Apple Business Manager.
Step 1: Configure the Omnissa Access Directory for the Apple Business Manager Integration
Configure the Omnissa Access directory to generate security events that are required for the integration with Apple Business Manager. Also, specify email as the login identifier for users because Apple supports only email for login.
Procedure
-
Log into the Omnissa Access console as an administrator.
-
Map the user attributes that are required for the integration.
-
Navigate to the Integrations > Directories page and click the directory that you are integrating with Apple Business Manager.
-
In the directory page, select the Sync Settings tab, then select Mapped Attributes.

-
Specify the following mappings:
-
disabled: userAccountControl
-
Password Last Set: Select Custom Value and enter pwdLastSet
Important: Make sure that you enter the value exactly as it is shown here. The value is case sensitive.
-
-
Click Save.
-
-
Select the SSF Integration option for the directory.
-
In the directory page, select the Settings tab.
-
In the Directory Sync and Authentication section, enable the SSF Integration option.

-
In the Bind User Details, enter the Bind user password, which is required to update the directory settings.
-
Click Save.
-
-
Set email as the login identifier for users.
Important: Apple supports only email for login. You must set email as the login identifier in Omnissa Access, otherwise login will fail.
-
Navigate to the Settings > Login Preferences page.
-
Click Edit.
-
In the User Sign-in Unique Identifier section, set Unique user sign-in identifier to email.

- Click Save.
-
Step 2: Create an ABM SCIM Provisioning app in Omnissa Access
The ABM SCIM Provisioning app in the Omnissa Access catalog provides both authentication and provisioning capabilities for the integration with Apple Business Manager or Apple School Manager. The app uses the OpenID Connect protocol for authentication and SCIM 2.0 for provisioning.
In this step, you create the app and configure the authentication settings. You will configure provisioning later in the process.
-
Log into Omnissa Access as an administrator.
-
Navigate to the Resources > Web Apps page.
-
Click New.
-
On the Definition page of the wizard:
-
Search for and select ABM SCIM Provisioning from the catalog.
-
Enter a name and, optionally, a description for the app, and click Next.

-
-
On the Single Sign-On page, enter the following values:
- Target URL: https://business.apple.com
- Redirect URL: https://gsa-ws.apple.com/grandslam/GsService2/acs
- Client ID: Enter a name for the client ID. The name must contain only alphanumeric (A-Z, a-z, 0-9), period (.), underscore (_), hyphen (-), and at sign (@) characters.
- Client Secret: Enter a client secret.
Important: Save the secret in a safe place. You will not be able to retrieve it from the user interface after you leave the page. - SSF Integration: Enabled by default to ensure that the required security events are passed from Omnissa to Apple; required for the integration
For example:

-
Save the Client ID and Client Secret values in a text file. You will need these values later in the process.
-
Click Next.
-
On the Access Policies page, select the access policy that you want to apply to the app if you do not want to use the default access policy.
-
Click Next till you reach the Summary page, then click Save & Assign.
-
On the Assign page, assign the app to the Omnissa Access administrator user account that you are using to configure the integration.
- Start typing the user name in the Users / Users Groups text box to search for and select the user.
- Click Save.

Step 3: Configure the Omnissa Security Events Service to transmit security events to Apple
The Omnissa Security Events Service enables you to integrate the Omnissa platform with third-party identity and security products to exchange security events using standard protocols. For the Omnissa Access integration with Apple Business Manager or Apple School Manager, you configure Apple as a subscriber in the Omnissa Security Events Service to transmit the required security events signals to Apple.
Procedure
-
Log in to Omnissa Connect.
-
From the menu at the top-right corner, select Intelligence.

-
In the Intelligence console, select Workspace Security > Security Events from the left pane.

-
Select the Subscribers tab.
Note: If this is the first time that you are configuring the Security Events Service, the Getting Started wizard appears instead of the tabs. Follow the wizard, using the information in the steps below. While the wizard user interface is slightly different, the configuration is the same.
Note: Omnissa Access is configured as a source by default in the Security Events Service. You do not need to select it explicitly as a source in the console.
-
Click Add and add Apple as a subscriber.
-
For Subscriber Name, enter a descriptive name by which you can easily identify the subscriber in the Security Events Service console.
-
For Partner, select Apple.
-
For Client ID, copy and paste the Client ID from the ABM SCIM app that you created in Omnissa Access. See Create an ABM SCIM Provisioning App in Omnissa Access.
-
For Source events, select the WS1 Access - Session Revoked and WS1 Access - Credential Change events.
The Session Revoked event signals that a user's session has been revoked and the Credential Change event indicates that a user's credentials changed. These events correspond to the CAEP Session Revoked and Credential Change events respectively in the OpenID Shared Signals and Events Framework (SSF) standard.
-
Carefully review the text about the permissions you are granting, then select the check box to authorize the events to be transmitted.

-
Click Save.
-
Copy and save the SSF Well-Known URL in a text file. You will need it to configure Apple Business Manager in the next step.

-
For more information about the Security Events Service, see Configuring the Omnissa Security Events Service.
Step 4: Configure Federated Authentication and Shared Signals in Apple Business Manager
In Apple Business Manager, configure Omnissa Access as an identity provider. You will require the values from Omnissa Access and Omnissa Security Events Service that you saved in previous steps. After you configure federated authentication and log in as an Omnissa Access administrator to test the integration, turn on federated authentication.
-
Follow the instructions in Step 3: Configure federated authentication and test authentication with a single IdP user account in the Apple documentation, Use federated authentication with your identity provider in Apple Business Manager.
Use the following values for Step 3: Configure federated authentication and test authentication with a single IdP user account:
- Client ID: Paste the Client ID from the Omnissa Access ABM SCIM app.
- Client Secret: Paste the Client Secret that you set for the Omnissa Access ABM SCIM app.
- SSF Config URL: Paste the SSF Well-Known URL from the Omnissa Security Events Service.
- OpenID Config URL: Enter https://example.com/.well-known/openid-configuration, replacing example.com with the fully-qualified domain name (FQDN) of your Omnissa Access tenant.
Note: In anticipation of the upcoming URL migration changes described in KB article 6001062, if your Access tenant FQDN falls in the list of environments under Category 2 - Certificate Branding and URL Change, use the corresponding new FQDN listed in the New URL column. In both the SSF Config URL and OpenID Config URL, replace the FQDN with the new FQDN. The new FQDN has been made available for the "Omnissa Access as an Identity Provider for Apple Business Manager or Apple School Manager" use case ahead of the migration for your convenience. Do not use it for any other use cases. The migration timeline will be communicated to all customers through the KB article.
Important: When you are prompted to log into Omnissa Access, you must log in with your Omnissa Access administrator account. If you do not use an administrator account, the integration will not work. Also make sure that the Omnissa Access administrator is assigned to the ABM SCIM Provisioning app in Omnissa Access.
-
Follow the instructions in Step 4: Turn on federated authentication in the Apple documentation, Use federated authentication with your identity provider in Apple Business Manager.
Step 5: Verify Event Stream in Omnissa Security Events Service
When you successfully complete the integration with Apple Business Manager in the previous step, an event stream is created in the Omnissa Security Events service to transmit security events to Apple. Verify that the stream was created.
-
In the Omnissa Intelligence console, select Workspace Security > Security Events from the left pane.
-
In the Active Streams tab, select the subscriber you created for Apple.
-
Verify that an event stream appears.
-
Expand the stream and verify that a Last Verification Date value appears.

Step 6: Configure Provisioning
To provision users from Omnissa Access to Apple Business Manager, you create a SCIM client in Apple Business Manager and edit the ABM SCIM app in Omnissa Access to enable provisioning.
Copy the Omnissa Access authorization callback URL
-
In the Omnissa Access console, navigate to the Resources > Web Apps page, and click the ABM SCIM app that you created for the Apple Business Manager integration.
-
In the navigation pane of the wizard, select Configuration.
-
Enable Show Provisioning Options.

Additional pages, related to provisioning, appear in the wizard.
-
In the navigation pane, select Provisioning.
-
Copy the Sign-in redirects uri value by clicking the copy icon.

-
In the URL, replace the Access tenant FQDN with the new FQDN, if required.
In anticipation of the upcoming URL migration changes described in KB article 6001062, if your Access tenant FQDN falls in the list of environments under Category 2 - Certificate Branding and URL Change, use the corresponding new FQDN listed in the New URL column. The new FQDN has been made available for the "Omnissa Access as an Identity Provider for Apple Business Manager or Apple School Manager" use case ahead of the migration for your convenience. Do not use it for any other use cases. The migration timeline will be communicated to all customers through the KB article.
You will use the URL in the next step.
Configure provisioning in Apple Business Manager
Follow the instructions in the "Create and copy SCIM client information to your IdP" section in the Apple documentation: Sync user accounts from your identity provider in Apple Business Manager.
Use the Omnissa Access authorization callback URL that you obtained in the previous step.
Edit the Omnissa Access ABM SCIM App to Configure User Provisioning
Earlier in the integration process, you created the ABM SCIM app in the Omnissa Access console and configured its authentication settings. Now, you configure the provisioning settings.
-
In the Omnissa Access console, navigate to the Resources > Web Apps page, select the app you created, and click Edit.
-
In the navigation pane, select Provisioning.
-
Configure the provisioning adapter.
-
Enter the following values:
- SCIM 2.0 provider base URL: Accept the default value - https://federation.apple.com/feeds/business/scim
- Access token end point URL: Accept the default value - https://appleid.apple.com/auth/oauth2/v2/token
- Authorization token end point URL: Accept the default value - https://appleid.apple.com/auth/oauth2/v2/authorize
- Client ID: The Client ID of the SCIM application in Apple Business Manager
- Client Secret: The Client Secret of the SCIM application in Apple Business Manager
-
Enable the Enable Provisioning option.

-
Click Next.
-
-
On the Authentication page, click Authenticate.
You are prompted to log into Apple Business Manager.
-
Log into Apple Business Manager using your Apple Business Manager administrator account.
-
On the WS1A SCIM Application wants to access Apple Business Manager page that appears, click Allow to allow users to be provisioned from Omnissa Access to Apple Business Manager.

-
In the Omnissa Access app, click Next to go to the User Provisioning page, and add or edit user attribute mappings, if required.
Important: Do not change the default value of the SCIM 2.0 userName attribute. It must be mapped to ${user.email}.
-
Click Save on the Summary page to save your changes.
-
Assign the users and groups that you want to provision to Apple Business Manager to the app.
Important: When you assign a group to the app, all its users are provisioned to Apple Business Manager. The group itself is not provisioned, nor are its memberships.
-
Navigate to the Resources > Web Apps page, select the app, and click Assign.
-
Assign users and groups.
-
After users are provisioned to Apple Business Manager, they can log into Apple devices and services with their Omnissa Access credentials, and they will be redirected to Omnissa Access to authenticate. Their Omnissa Access credentials are now their Managed Apple Accounts.
Important:
- Users must use their email to log in.
- Before users can log into iCloud, they must first log in successfully to any Apple device with their Managed Apple Account. For example, on Mac, go to System Settings, click Sign in with your Apple ID, and sign in with your Omnissa Access credentials. Expect that the first login to an Apple device might take about 15-20 seconds.
Was this page helpful?