Omnissa Cloud Services users with a federated domain use their corporate credentials to log in to the Cloud Services Console across Organizations.
Setting up enterprise federation for your corporate domain is a self-service process that involves multiple steps, users, and roles.
As an Organization Owner user, you kick off the self-service federation workflow on behalf of your Organization and invite an Enterprise Administrator to complete the setup. The Enterprise Administrator must determine the type of federation setup that is most suitable for your enterprise. The following table explains the differences between the two setup options.
| Federation setup | Authentication method | User and group provisioning |
|---|---|---|
| Dynamic (connectorless) authentication setup | SAML 2.0 Identity Provider | Dynamic provisioning - SAML JIT for user and group provisioning |
| Connector-based authentication setup | SAML 2.0 Identity Provider OR Omnissa Access connector authentication methods | Pre-provisioning - syncing users and groups from the customer's Active Directory |
Dynamic (connectorless) authentication setup
When enterprise federation for your enterprise domain is set up to use your third-party identity provider, users accessing Omnissa Cloud Services from the federated domain are redirected to the log in screen of the identity provider for your enterprise.
Users authenticate directly with their identity provider through SAML. Users and groups can be provisioned with SAML JIT.
Connector-based authentication setup
In this federation setup, an on-premises instance of Omnissa Access connector syncs users and groups from your Active Directory to a dedicated instance of an Omnissa Access tenant. Only synced groups and users can log in to Omnissa Cloud Services with their corporate credentials. User authentication can be set up to use either a SAML 2.0 based IdP or the Omnissa Access connector authentication methods.
After setup completes successfully, enterprise federation becomes available to all users from your corporate domain and applies to all services across all Organizations.
What's involved in setting up enterprise federation
Setting up enterprise federation for your corporate domain is a self-service process that involves multiple steps, users, and roles.
Here's who and what's involved in federating your corporate domain with Omnissa Cloud Services.
Organization Owner
Organization Owner users of unfederated domains can kick off the federation setup from the Cloud Services Console. Any Organization Owner can initiate the self-service federation process and assign one or more Enterprise Administrators to complete the setup.
Organization Owners who hold system administrator roles with their enterprise and have sufficient knowledge of the enterprise directory service and identity provider configuration, can act as Enterprise Administrators for the federation setup.
Enterprise Administrator
The Enterprise Administrator is a system administrator who belongs to the central security team for your enterprise and manages the directory services and identity providers. As the designated person to set up enterprise federation for your corporate domain, the Enterprise Administrator completes the configuration and validation steps of the self-service setup process. Setting up enterprise federation might involve representatives of different security teams. The designated Enterprise Administrator can invite other administrators to help with the setup.
The Enterprise Federation dashboard
When an Organization Owner initiates the self-service federation workflow for their corporate domain by inviting one or more Enterprise Administrators, a special Management Organization is created. This Organization provides access to the Enterprise Federation dashboard. The purpose of the dashboard is to set up enterprise federation for the corporate domain and to modify the initial setup. Everyone involved in the self-service federation process receives an email notification with a link to access the Enterprise Federation dashboard in the Management Organization.
Linking corporate accounts to Omnissa accounts
Many Omnissa services like creating support requests or viewing and managing subscriptions require Omnissa ID-based user accounts. However, federated accounts do not provide access to these services, so you must link your federated account to the Omnissa account.
Linking the federated account to the Omnissa account for existing users of Omnissa Cloud Services happens automatically if the federated email was used to create the Omnissa account. If the Omnissa account uses a different email account from the federated email account, the customers must link their corporate accounts to their Omnissa accounts in order to access the services in their Organization.
New users with federated accounts must create an Omnissa account only if they need to view billing information or file support tickets.
Omnissa Access tenant
Setting up federated identity management requires the customer to configure and manage an Omnissa Access tenant. The tenant is created as part of the self-service federation process. The Omnissa Access tenant acts as an identity broker (service provider) to your identity provider and is not involved in the actual user authentication.
The self-service federation setup workflow
The self-service federation setup involves multiple steps that can be performed at various times by different Enterprise Administrators. The workflow resumes from the place it was left last. Enterprise Administrator users involved in the setup must have Omnissa Cloud Services accounts linked to their Omnissa accounts. All steps in the federation setup are completed through the set up Enterprise Federation workflow in the special Management Organization. The system automatically creates the Management Organization when an Enterprise Federation process is started.
Was this page helpful?