Skip to main content

Enterprise Federation for Identity and Access Management

As an enterprise using Omnissa Cloud Services, you can set up federation with multiple corporate domains. By federating your corporate domains, you activate single sign-on for users in your enterprise. Enterprise federation with Omnissa Cloud Services supports integration with SAML 2.0 based identity providers.

Note: Due to the migration of identity systems, no new federations are allowed starting on March 15th, 2024, until further notice.

By adopting a federated identity access for Omnissa Cloud Services users and Organizations in your enterprise, you activate the following:

  • All users in your enterprise access Omnissa Cloud Services using their corporate account.
  • Organization Owners can control authentication to Organizations and services by assigning Organization and service roles to the groups synced from your corporate directory.
  • Your security team can set up and enforce enterprise-level security and access policies for Omnissa Cloud Services, including multi-factor authentication.

As an Organization Owner of an unfederated domain, you initiate your entire enterprise domain setup. After completing the setup, enterprise federation becomes available to all users from your corporate domain and applies to all services across all Organizations.

Attention: Your enterprise must own the domains you want to federate for access with Omnissa Cloud Services and you must verify the ownership during the first step. You cannot federate domains that belong to a service provider.

What is the difference between federated and unfederated authentication?

If your corporate domain is not federated, your access to Omnissa Cloud Services is authenticated through your Omnissa ID account. If you are new to Omnissa Cloud Services, visit Cloud Services to create an Omnissa ID.

If your corporate domain is federated, your access to Omnissa Cloud Services is authenticated through your corporate account. A hosted Omnissa Access tenant is used as an identity broker to set up federation with your identity provider. The hosted tenant is configured for validation with your corporate identity provider and active directory. You manage user and group access to Omnissa Cloud Services by configuring the Omnissa Access connector to sync users and groups from your corporate active directory. Only a subset of required user profile attributes, such as username, firstname, lastname, and email address, is configured to be synced. You can add more attributes later.

Note: User passwords are never synced, nor cached.

Can I undo the federation for my corporate domain?

If you decide to undo the federation setup or undo federation for any of the federated corporate domains you initially configured, you must file a support ticket.

What's involved in setting up enterprise federation

Setting up enterprise federation for your corporate domain is a self-service process that involves multiple steps, users, and roles.

Note: Due to the migration of identity systems, no new federations are allowed starting on March 15th, 2024, until further notice. Here's who and what's involved in federating your corporate domain with Omnissa Cloud Services.

Organization Owner

Organization Owner users of unfederated domains can kick off the federation setup from the Cloud Services Console. Any Organization Owner can initiate the self-service federation process and assign one or more Enterprise Administrators to complete the setup.

Organization Owners who hold system administrator roles with their enterprise and have sufficient knowledge of the enterprise directory service and identity provider configuration, can act as Enterprise Administrators for the federation setup.

Enterprise Administrator

The Enterprise Administrator is a system administrator who belongs to the central security team for your enterprise and manages the directory services and identity providers. As the designated person to set up enterprise federation for your corporate domain, the Enterprise Administrator completes the configuration and validation steps of the self-service setup process. Setting up enterprise federation might involve representatives of different security teams. The designated Enterprise Administrator can invite other administrators to help with the setup.

The Enterprise Federation dashboard

When an Organization Owner initiates the self-service federation workflow for their corporate domain by inviting one or more Enterprise Administrators, a special Management Organization is created. This Organization provides access to the Enterprise Federation dashboard. The purpose of the dashboard is to set up enterprise federation for the corporate domain and to modify the initial setup. Everyone involved in the self-service federation process receives an email notification with a link to access the Enterprise Federation dashboard in the Management Organization.

If your domain is federated, you can use the advanced Identity and Governance Administration (IGA) features to easily onboard non-Organization users to Omnissa Cloud Services.

One way to activate IGA is to ask an Enterprise Administrator to make the change in the Enterprise Federation Organization dashboard. Another way is to link your Organization to your Identity Provider (IdP). Only Organization Owners of federated domains can link their Organizations to their IdP.

  1. Log in to Cloud Services Console and click Organization > Details.
  2. In the Domains Linked to Identity Provider section, click Link Identity Provider.
    The IdP and domains associated with your Organization display in a pop-up window.
  3. Click Link, then click Continue.

Guides for configuration

For details about enterprise federation options and configurations, see Setting Up Enterprise Federation with Cloud Services

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…