Skip to main content

How Do I Modify The Enterprise Federation Setup

As an Enterprise Administrator for your federated domains, you modify the initial federation setup through the Enterprise Federation dashboard in Omnissa Cloud Services.

Who can modify setup?

  • Enterprise Administrators can modify the federation setup.
  • Organization Owner users who hold system administrator roles with their enterprise and have sufficient knowledge of the enterprise directory service can also modify the federation setup.

How to access

To access the Enterprise Federation dashboard, you must log in to the Management Organization in Omnissa Cloud Services with your federated account.

Note: When logging in to the Enterprise Federation dashboard, use a regular browser mode. Some of the features may not work properly in incognito mode.

Available changes to federation setup

The Enterprise Federation dashboard provides an overview of the current federation setup for your enterprise. The current setup includes the listed data.

  • The enterprise directories configured for users and groups sync.
  • The number of synced users and groups.
  • The identity provider and corporate domains configured for federation.
  • The user identification method.

As an Enterprise Administrator, you can make the following changes to the federation configuration setup.

  • Add more domains or sub-domains.
  • Sync more groups and users.
  • Make changes to your directory settings, such as change sync frequency.
  • Modify the display name of the identity provider.
  • Grant other Enterprise Administrators access to the Enterprise Federation dashboard in the Management Organization.
  • Activate member Organizations for Identity Governance and Administration.

Caution: All users with the Enterprise Administrator role can make changes to the federation configuration. These changes are domain wide and impact all users or groups across any Omnissa Cloud Services Organization with users from federated domains. For example, if an Enterprise Administrator removes a group that was previously synced, any Organization using the group is impacted.

Can I make changes to the identity provider configuration?

Once your federation setup is activated, you are no longer able to make changes to the identity provider configuration. You cannot change your identity provider to a different one or modify the authentication method configured for your identity provider. The Enterprise Federation dashboard only lets you change the display name of your already configured identity provider.

To make changes to the identity provider settings in your enterprise federation setup, you must file a support ticket. For more information, see Get Support.

Make changes to synced groups and users

You can sync more users and groups from your enterprise to use their federated accounts for access to Omnissa Cloud Services.

From the Enterprise Federation dashboard in your Management Organization, you can:

  • View users and groups that are synced with your corporate Active Directory to troubleshoot problems with federated accounts.
  • Sync additional users and groups to access Omnissa Cloud Services with their federated accounts.

Prerequisites

To make changes to the initial federation setup, you must be logged in the Management Organization for your enterprise as an Enterprise Administrator.

Procedures

  1. In the Cloud Services Console, click Enterprise Federation.
    The Enterprise Federation dashboard displays.
  2. Do one of the following:
ToDo this:
View users and groups.1. In the Synced Users and Groups section of the Enterprise Federation dashboard, click the Users or Groups tile. The list of synced users or groups display.
2. View, search, or filter the list entries.
Sync more users from your Active Directory with the Omnissa Access connector.1. In the Directories section of the Enterprise Federation dashboard, click the directory for which you want to sync more users.
2. In the Sync settings > Users and Groups > Users section, click Edit.
3. Click Add.
4. Enter the user DN pattern.
5. Click Save.
6. Click Sync Now for the directory.

The number of total users is refreshed.
Sync more groups from your Active Directory with the Omnissa Access connector.1. In the Directories section of the Enterprise Federation dashboard, click the directory for which you want to sync more groups.
2. In the Sync settings > Users and Groups > Groups section, click Edit.
3. To add more groups to an existing Group DN, click the Edit icon, select additional groups from the list that appears, then click Save.
4. To add more groups from a new Group DN, click Add.
5. Enter the group DN pattern.
6. Click the Select Groups link that appears next to the new entry.
7. In the groups list that opens, select the groups you want to sync.
8. Click Save.
9. In the Directory section of the page, click Sync Now.

The number of total users and groups is refreshed.

Make changes to your directory settings

You can modify your initial Active Directory setup or add a new directory to sync groups and users.

From the Enterprise Federation dashboard in your Management Organization, you can:

  • Ensure groups and users from your Active Directory are synced regularly for federation with Omnissa Cloud Services by configuring the desired sync frequency.
  • Reduce risk of errors during directory syncs you set safeguards that limit the number of changes that can be made to users and groups. By default, there are no pre-set safeguards to your federation setup.
  • Modify the mapping of the attributes from your directory services to the attributes that are configured to sync with the hosted Omnissa Access tenant.
  • Add multiple directories for group and user sync with your federated domains.

Prerequisites

To make changes to the initial federation setup, you must be logged in the Management Organization for your enterprise as an Enterprise Administrator.

Procedures

  1. In the Cloud Services Console, click Enterprise Federation.
    The Enterprise Federation dashboard displays.
  2. Do one of the following:
ToDo this:
Add a new directory.1. In the Directories section of the Enterprise Federation dashboard, click Add Directory.
2. Follow the prompts in the Add a Directory workflow that opens.

The steps for adding a new directory to your enterprise setup are the same as those you followed in the initial setup.

After completing the workflow, the synced new directory appears in the Directories section of the dashboard.
Change the sync frequency of a directory.1. In the Directories section of the Enterprise Federation dashboard, click the tile of the directory for which you want to change the sync frequency.
2. In the Sync settings section, click the Sync frequency tab.
3. Click Edit.
4. Select a menu item from the Sync frequency drop-down menu.
5. If applicable, select Day and Time.
6. Click Save.
Add or change sync safeguards of a directory.1. In the Directories section of the Enterprise Federation dashboard, click the tile of the directory for which you want to add safeguards.
2. In the Sync settings section, click the Safeguards tab.
3. Click Edit.
4. Using the drop-down menus, set the preferred sync failure limits. Each line of drop-down menus corresponds to one safeguard setting.
5. To create additional safeguards, click Add.
6. When ready, click Save.

The safeguards you defined are displayed as a list of entries in the Safeguards tab for the directory.

You edit or delete safeguards by clicking Edit.
Adjust the mapped attributes of a directory.1. In the Directories section of the Enterprise Federation dashboard, click the tile of the directory for which you want to modify attributes mapping.
2. In the Sync settings section, click the Mapped Attributes tab.

You see two lists of attribute names. The attributes listed in the Attribute name column are mapped to the attributes in your active directory displayed in the Attribute name in Active Directory column.

3. To modify the mapping for an attribute, click Edit.
4. Use the drop-down menu arrow in the right column to select a different attribute mapping from your active directory.

Note: You can't change userName attribute mapping.

5. Click Save.

Add new domains for enterprise federation

You can add new domains or subdomains to your initial enterprise federation setup from the Enterprise Federation dashboard.

Restriction

There is one restriction that applies to adding domains to a direct federation setup. If you are using Username@Domain as identification preference for user logins, you are not allowed to add more domains or subdomains to the existing federation setup.

Each domain or subdomain that you add to your existing enterprise federation setup must pass verification of the domain's ownership and verification of user login using your corporate identity provider.

Important: After you add a domain or subdomain to the federation setup, it can no longer be modified or removed. If you have to make a change, you must file a support ticket.

Prerequisites

To make changes to the initial federation setup, you must be logged in the Management Organization for your enterprise as an Enterprise Administrator.

Procedure

  1. In the Cloud Services Console, click Enterprise Federation.
  2. In the Domains section of the Enterprise Federation dashboard, click Add domains or Add subdomains.
  3. Complete the steps in the workflow that opens.
    The steps for adding a domain or subdomain to your current federation setup are identical to the steps you followed for the initial federation setup.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…