The dynamic (connectorless) type of federation setup involves configuring your third-party identity provider for dynamic user and group provisioning in Omnissa Cloud Services.
General workflow
To set up dynamic federation, follow these general steps.
- Verify domains.
- Configure the identity provider that is SAML-based with JIT-based dynamic provisioning.
- Complete the setup by validating that users can log in, notifying users that they must log in, and activating the federation for the enterprise.
- Link your Omnissa account.
This content offers a high-level overview of the steps in the federation setup with dynamic user and group provisioning workflow. Some of the steps are common for all IdP configurations.
Step 1: Verify Domains
In this step, you verify the ownership of the domains that you want to federate. The verification process involves adding DNS TXT records for your domains. Before you begin, verify that you can modify the DNS records for your corporate domains.
The domains you add in this step are the top-level public domains that your enterprise employees use to access Omnissa Cloud Services. These domains are not your internal Active Directory domains.
Note: The verification does not happen automatically. It might take up to 72 hours after submitting the TXT records for the changes to take effect.
Step 2: Configure the identity provider as SAML-based with JIT-based dynamic provisioning
In this step, you configure the identity provider. You can enable federation for your enterprise with any SAML 2.0-based third-party identity provider. The self-service federation setup process provides guided configuration support for the following SAML-based IdPs: Okta, PingIdentity, Microsoft Active Directory Federation Services, OneLogin, and Microsoft Entra ID (formerly Azure Active Directory).
To configure your third-party IdP for an enterprise federation, you must have access to the identity provider console and the IdP's metadata URL.
Step 3: Validate and activate
In these steps of the federation setup, you must perform a list of actions.
Important Notes:
-
After enterprise federation is activated, users with federated domains can only access Omnissa Cloud Services using their corporate accounts. They can no longer use their my accounts to log in to Omnissa Cloud Services.
-
Cloud Services does not allow changing the Identity Provider you configure in this step, after the federation is set up is activated. If you must change your identity provider later, file a support ticket
-
Validate that the users from your enterprise can log in to Omnissa Cloud Services by using your corporate IdP.
-
Notify the enterprise users of the domains that you specified in Step 1 that they have to log in to Omnissa Cloud Services by using their corporate credentials.
-
Acknowledge the changes and activate the federation for your enterprise.
After you complete the federation setup, Enterprise Administrators can modify the initial setup from the Enterprise Federation dashboard.
Step 4: Link Your Omnissa Account
In the last step of the workflow, you link your federated account to your Omnissa ID account. This step is necessary to complete for the following roles:
- Enterprise Administrators, Organization Owner users who participated in the self-service federation setup.
- Organization Owner and Organization Member users who need access to billing information.
- Organization Owner and Organization Member users who want to be able to file support requests.
Was this page helpful?