Skip to main content

Configure the Identity Provider Okta

Configuring the identity provider (IdP) includes working in both the provider and Omnissa Cloud Services consoles, and this procedure outlines using Okta as the IdP.

The Omnissa Access tenant is provisioned automatically to help with this step. Omnissa Access acts a service provider and the self-service federation provides a presentation layer to help simplify connecting your identity provider with your service provider.

General workflow

In general, whether you are configuring Microsoft Entra ID, Okta, or another identity provider, take the listed steps.

  1. Establish trust between your identity provider and the service provider.
  2. Configure how users and groups are identified for authentication.
  3. Configure single sign-on (SSO).

Okta documentation

This topic outlines using Okta as the identity provider, but if you want the latest Okta documentation, see the Okta documentation site.

Requirements

You must complete the Verify Domains step before you can access the Configure identity provider area of the Set up Enterprise Federation widget in Cloud Services.

Configuring SAML SSO with Okta

Work in both the Cloud Services console and in Okta. It is best to use two browser instances to facilitate copying and pasting values between the consoles.

  1. Open a browser instance and go to your Cloud Services console.
    1. Go to Set up Enterprise Federation > Configure identity provider and select Start.
      A screenshot of the next available step in federation setup after you verify domains.
    2. In Cloud Services, select to use Okta as the identity provider.
  2. In another browser instance, log in to your Okta admin console with admin permissions and select the right Okta organization.
    1. In Okta, go to the Applications menu and select Create App Integration.
      An image of the Applications section in the Okta console and where to select to create the app integration.
    2. In the Create a new app integration widget, select SAML 2.0 and select Next.
      A screenshot of the Okta app integration widget with SAML 2.0 selected for the sign-in method.
    3. In the General Settings area of the Create SAML Integration widget, enter an App name and other details as needed and select Next.
      An image of entering an app name in the General Settings area.
  3. In Cloud Services, in the Set up SAML within your identity provider step, copy the Single sign-on URL and the Audience URI (SP Entity ID) values.
    A screenshot of Cloud Services where you get the URLs.
  4. Go to your Okta instance and paste the copied Cloud Services values in to the SAML Settings > General area, leaving other fields in Okta as they are.
    An image of Okta where you paste the copied URLs.
    1. In Okta, in the Attribute Statements section, add the required user attributes that match those in Cloud Services.
      An image of the Okta console where you add the matching Cloud Services attributes.
    2. Select to Add Group attribute Statements if you plan to provision group memberships.
    3. (Optional) Preview the XML that is used in SAML assertions to ensure everything looks right, then select Next to continue.
      An image of the Preview the SAML Assertion menu in Okta.
  5. Go to your Cloud Services instance, in the Configure your identity provider step, and enter a name for the provider to display in Cloud Services.
    1. Select URL as the method of sharing for the Metadata menu option.
      An image of the Okta IdP in Cloud Services.
  6. In Okta, go to the Assignments tab of your Omnissa app and assign users and groups to the application so that they can SSO in to Cloud Services.
    An image of Okta Assignments tab where you can assign users and groups.
    1. Go to your application's Sign On tab and copy the Metadata URL.
  7. Go back to Cloud Services, still on the Configure your identity provider step, and paste the copied Okta metadata URL in to the Metadata URL text field.
    A screenshot of where you paste the metadata URL in Cloud Services.
    1. Enter the Name ID Format.
      • The Name ID Format is the value in the SAML response to identify the authenticated user.
      • The Authentication Method is automatically populated.
    2. From the SAML Context drop-down menu, select the type of user authentication for the IdP (you can choose unspecified if are not sure), and select Next to continue.
  8. In Cloud Services, in the Set user identification preference step, select how users of your enterprise are going to identify themselves when accessing Omnissa Cloud Services from the Cloud Services discovery page.
    • User identification is different from how the user authenticates against your enterprise identity provider.
    • Follow the examples shown on the screen to choose the correct one.
    • Consider that for all the options, the chosen value must end with @<DomainName.com > where domainName is the one you registered during the verification step.
  9. In Cloud Services, select Configure to complete the self-service federation process.

What to do next

In this step you configured Okta as the IdP, selected the SAML user and group claims, and selected the value to be used for user identification. Move on to validating and activating your setup.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…