Skip to main content

Configure the Identity Provider Microsoft Entra ID

Configuring the identity provider (IdP) includes working in both the provider and Omnissa Cloud Services consoles, and this procedure outlines using Microsoft Entra ID as the IdP.

The Omnissa Access tenant is provisioned automatically to help with this step. Omnissa Access acts a service provider and the self-service federation provides a presentation layer to help simplify connecting your identity provider with your service provider.

General workflow

In general, whether you are configuring Microsoft Entra ID, Okta, or another identity provider, take the listed steps.

  1. Establish trust between your identity provider and the service provider.
  2. Configure how users and groups are identified for authentication.
  3. Configure single sign-on (SSO).

Microsoft documentation

Requirements

You must complete the Verify Domains step before you can access the Configure identity provider area of the Set up Enterprise Federation widget in Cloud Services.

Configuring SAML SSO with Microsoft Entra ID

Work in both the Cloud Services console and in the Microsoft Entra admin center. It is best to use two browser instances to facilitate copying and pasting values between the consoles.

  1. Open a browser instance and go to your Cloud Services console.

    1. Go to Set up Enterprise Federation > Configure identity provider and select Start.
      A screenshot of the next available step in federation setup after you verify domains.
    2. In Cloud Services, select to use Azure Active Directory as the identity provider. Azure Active Directory is the former name for Microsoft Entra ID.
  2. Open another browser instance and log in to your Microsoft Entra admin center with admin privileges.

    1. In Microsoft Entra ID, go to Identity > Applications > Enterprise Applications and select to add a new application.
      Screenshot of the Enterprise Applications page in Entra with + new application.
    2. Select to create your own application.
      An image of the create your own application menu option.
    3. Enter a name in the What's the name of your app? text field, choose Integrate any other application you don’t find in the gallery (Non-gallery), and select Create.
      An image of entering a name for the app, selecting the correct menu option to integrate any other app, and the create button.
    4. Select the app you just created from the All Applications list and then select Assign users and groups. Follow the instructions to assign users and groups that you want to have access to Omnissa Cloud Services through SSO.
      An image of the assign users and groups tile.
    5. In the app Overview page, select the Set up single sign on tile and then select SAML as the method.
      An image of the SSO tile in Entra ID.
  3. In Microsoft Entra ID, edit the Basic SAML Configuration. This step requires you to copy values from Cloud Services into Microsoft Entra ID.

    1. Go to the Cloud Services browser instance and select the Set up SAML within your identity provider step.
    2. Copy the Identifier and the Reply URL strings.
      A screenshot of the Set up SAML within your identity provider step where you can find the identifier and reply url values.
    3. Go back to your Microsoft Entra ID browser instance and paste the Identifier and Reply URL values you copied from Cloud Services to Microsoft Entra ID.
      An image of Microsoft Entra ID where you enter the copied values.
    4. Ignore optional steps, save your settings, and close the Basic SAML Configuration widget, but do not close the Microsoft Entra ID browser instance. Keep the Microsoft Entra admin center browser session open because you are going to edit Attributes and Claims next.
  4. In Cloud Services, move to the User attributes section that comes after the Cloud Services step where you were just copied the values in the Set up SAML within your identity provider step. The user attribute information is helpful to access while you edit the attributes and claims in Microsoft Entra ID.
    Move on to step 3 user attributes in Cloud Services.

  5. Go to your Microsoft Entra ID instance and edit Attributes and Claims.

    1. Required claim
      • For the Unique User Identifier (Name ID), the value user.userprincipalname works as long as you selected UPN (user principal name) in Cloud Services.
      • If you select email in Cloud Services, you must change the value of the Unique User Identifier to user.mail.
    2. Additional claims
      • Remove Attribute Namespace values that were assigned by Entra ID.
      • Add or edit the pre-populated additional claims so that the system recognizes them.
      • These strings are case sensitive.
        • Name: email, Source Attribute: user.mail
        • Name: firstName, Source Attribute: user.givenname
        • Name: lastName, Source Attribute: user.surname
        • Name: userName, Source Attribute: user.userprincipalname
        • Name: userPrincipalName, Source Attribute: user.userprincipalname
      • Optionally, you can add the name domain and map it to the applicable domain.
        An image of the additional claims you must edit so that the system recognizes them.
  6. Back in your Cloud Services console, in the User attributes step, select Next to access the Group attribute step.

    1. (Optional) Set up the Group attribute section if you plan to provision group memberships.
      A screenshot of step 4 in the self service federation process in Cloud Services, setting up the group attribute.
      • Ensure that the group attributes in Cloud Services and in Microsoft Entra ID match.
      • Some menu options in Microsoft Entra ID include the following.
        • If you have many admins, you can use groups to assign roles rather than assigning roles one admin at a time. For example, you may have a security group with many admins in it and all these admins can have the same roles.
        • For the Which groups associated with the user should be returned in the claim? option, select the applicable group. For example, select Security groups.
        • For the Source attribute option, select Group ID.
        • For the Advanced options > Customize the name of the group claim, you can activate this checkbox.
        • For the Name option, you can enter a name that matches what was entered in Cloud Services. Do not enter a standard name because the system does not recognize it.
  7. In Cloud Services, configure the Configure your identity provider step.

    1. Enter a name in the IdP Display Name text field.
    2. For the Metadata method of sharing, choose URL because Entra ID supports it.
      An image of the 5th step in Cloud Services' federation process where you enter the IdP name and select the method of sharing.
  8. Go to your Microsoft Entra ID instance, go to the Omnissa app you added, select Manage > Single sign-on, and copy the URL in the SAML Certificates > App Federation Metadata Url area.
    A screenshot of the url in Microsoft Entra ID to copy and paste in to Cloud Services.

  9. Go back to your Cloud Services instance, in the Configure your identity provider step, paste the copied app federation metadata URL in to the Metadata field.
    A screenshot of the Cloud Services step where you paste the copied app federation metadata URL.

    • Validation of the metadata starts automatically.
    • When validation finishes, a green check box icon indicates that the file was read and parsed successfully.
    • If the validation returns an error, check that the URL you entered is correct.
  10. In Cloud Services, enter the Name ID Format.

    • The Name ID Format is the value in the SAML response to identify the authenticated user.
    • The Authentication Method is automatically populated.
    • The Name ID format needs to match the nameID format you have chosen for the Required claim in Entra ID for your SAML application.
  11. In Cloud Services, from the SAML Context drop-down menu, select the type of user authentication for the IdP (you can choose unspecified if are not sure), and select Next to continue.

  12. In Cloud Services, in the Set user identification preference step, select how users of your enterprise are going to identify themselves when accessing Omnissa Cloud Services from the Cloud Services discovery page.

    • User identification is different from how the user authenticates against your enterprise identity provider.
    • Follow the examples shown on the screen to choose the correct one.
    • Consider that for all the options, the chosen value must end with @<DomainName.com > where domainName is the one you registered during the verification step.
      An image of the domain name's that must match the domain registered during verification.
  13. In Cloud Services, select Configure to complete the self-service federation process.

What to do next

In this step you configured Microsoft Entra ID as the IdP, selected the SAML user and group claims, and selected the value to be used for user identification. Move on to validating and activating your setup.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…