Omnissa Cloud Services users with a federated domain use their corporate credentials to log in to the Cloud Services Console across Organizations.
Note:Enterprise Federation setup is currently unavailable. We are in the process of migrating to Broadcom’s Identity system. If you have any questions, contact Support.
Setting up enterprise federation for your corporate domain is a self-service process that involves multiple steps, users, and roles.
As an Organization Owner user, you kick off the self-service federation workflow on behalf of your Organization and invite an Enterprise Administrator to complete the setup. The Enterprise Administrator must determine the type of federation setup that is most suitable for your enterprise. The following table explains the differences between the two setup options.
| Federation setup | Authentication method | User and group provisioning |
|---|---|---|
| Dynamic (connectorless) authentication setup | SAML 2.0 Identity Provider or OpenID Connect (OIDC) | Dynamic provisioning: SAML JIT for user and group provisioning Automated user management with SCIM provisioning |
| Connector-based authentication setup | SAML 2.0 Identity Provider OR Omnissa Access connector authentication methods | Pre-provisioning: syncing users and groups from the customer's Active Directory |
Dynamic (connectorless) authentication setup
When enterprise federation for your enterprise domain is set up to use your third-party identity provider, users accessing Omnissa Cloud Services from the federated domain are redirected to the log in screen of the identity provider for your enterprise.
Users authenticate directly with your identity provider through SAML or OIDC . User and groups can be provisioned with either SAML JIT or SCIM-based dynamic provisioning.
Connector-based authentication setup
In this federation setup, an on-premises instance of Omnissa Access connector syncs users and groups from your Active Directory to a dedicated instance of an Omnissa Access tenant. Only synced groups and users can log in to Omnissa Cloud Services with their corporate credentials. User authentication can be set up to use either a SAML 2.0 based IdP or the Omnissa Access connector authentication methods.
After setup completes successfully, enterprise federation becomes available to all users from your corporate domain and applies to all services across all Organizations.
Enterprise Federation dashboard
When an Organization Owner user initiates the self-service federation setup for their corporate domain by inviting one or more Enterprise Administrators, a Management Organization is automatically created and becomes immediately available to the Organization Owner user who started the federation and all Enterprise Administrators invited to complete the setup.
The purpose of the Management Organization is to provide access to the federation setup and to consolidate resource management of member Organizations. After completing the initial setup, Enterprise Administrators can access the Enterprise Federation dashboard to modify the federation setup.
How do I access to the Enterprise Federation dashboard?
To access the Enterprise Federation dashboard, you must be an Organization Owner user or an Organization Member user with Enterprise Administrator role in the Management Organization.
As an Organization Owner of a domain that is currently being federated, you can contact the Organization Owner of the Management Organization and request an access role within the Organization. To identify the contact person from your enterprise, do the following: On the Cloud Services Console menu, click Organization > Enterprise Management.
The Enterprise Federation tab displays status information for the federation setup of your corporate domain. If it is in progress, you can see the email of the Organization Owner within your enterprise who initiated the self-service workflow.
How do I access the special Management Organization?
If you already hold an Organization Owner or an Enterprise Administrator access role in the Management Organization, you can switch from your active Organization to the Management Organization by clicking the downward arrow next to your user name on the main menu bar. Alternatively, navigate to the Organization > Enterprise Management > Enterprise Federation tab and click the Launch button.
To distinguish the Management Organization from other Organizations in your enterprise, the Organization's display name on the Cloud Services Console menu has a shield icon before your company's name, and the word "Management" after it. See example below.
Who can be an Enterprise Administrator?
Any system administrator who belongs to the central security team in your enterprise and manages the directory services and identity providers, can be invited as an Enterprise Administrator user. Setting up enterprise federation might involve representatives of different security teams. As the designated person to set up enterprise federation for your corporate domain, the Enterprise Administrator completes the configuration and validation steps of the self-service setup process. The Enterprise Administrator can also invite other administrators to help with the setup.
Organization Owner users who hold system administrator roles with their enterprise and have sufficient knowledge of the enterprise directory service and identity provider configuration, can act as Enterprise Administrators for the federation setup.
Enterprise Administrator users involved in the setup must have Omnissa Cloud Services accounts with a Omnissa ID.
Was this page helpful?