Omnissa Connect provides authentication features to help secure your environment. You can enforce the use of multi-factor authentication (MFA), you can also enter specific addresses and ranges to allow or block access, or you can lock source domains. To add further identity control, configure timeout session preferences to control authentication.
Multi-factor authentication
Omnissa Connect provides multi-factor authentication (MFA) that each individual user can turn on in their profile to add another level of authentication to log in to their services. However, as an Owner, you can enforce MFA for all eligible users to ensure that each user can only log in after providing a second factor authentication code.
If the organization belongs to a federated domain, then only non-federated users are enforced with MFA. All federated users follow the authentication policies set within the Identity Provider (IdP), including MFA.
Supported TOTP authenticators
Omnissa Connect supports commonly used time-based one-time password (TOTP) authenticators including Microsoft Authenticator, Google Authenticator, and Okta Authenticator. Download the applicable authenticator app from its respective app store.
Prerequisites
Meet the listed prerequisites so that you can enforce MFA at the organization level.
- You must be an Owner.
- You must set up MFA for your individual account. See Security and Third-Party Authenticators for instructions on adding your MFA device.
Enforce MFA
To set MFA for your organization use the Identity Management area.
- Go to Identity Management > Authentication Policies.
- Select the Multi-Factor Authentication tab.
- Activate MFA for console authentication.

Selecting IP address/range to allow or disallow access
Use IP address/ranges to allow or deny user logins from specific IP addresses. This feature provides additional security to organizations to safeguard access to the service through known, safe IP address ranges.
Two authentication preferences - block or allow
As an Owner, you can manage access to your organization by defining IP addresses or IP ranges to either block or allow user access from specific IPs.
Apply an authentication preference to block or allow user access from an IP range or specific IP address. If your authentication preference is defined for an IP range, you can set exceptions for specific IPs within the range. For example, if you apply block authentication to an IP range, you can then set an exception for one or more IPs within that range that will be allowed access to Omnissa Connect.
Note: The IP address you enter must follow CIDR notation for IPv4 and IPv6 IP addresses.
There are two authentication preference options you can define:
- Block IP: User logins from specific IP addresses/ranges are blocked access to the organization.
- Allow IP: User logins from specific IP addresses/ranges are allowed access to the organization.
You can have only one preference activated in your organization. You can switch between the two preferences, but you can't have both of them activated at the same time.
Note: It may take up to 30 minutes for your policy settings to take effect in the organization.
Set an IP authentication preference for your organization
Here is an example of setting the authentication preference to block IPs.
- In Omnissa Connect, go to Identity Management > Authentication Policies and select the IP address/range tab.
- Select the Block IP button and then select Activate.
- In the User IP Authentication Preference area, see that the Block IP pill button is active.
- You can use the Change menu option here to select the Allow IP preference.
- In the Users with an IP address/range specified in the list are denied access to your organization area, select Add and enter an IP address or range.
- In the Add block IP address/range window, enter the IP address range and select Add.
- The address or range you entered is added to the list of blocked addresses and ranges specified for your organization.
- To allow an IP address access in a blocked IP range, use the Exception area.
Add an exception to your block authentication preference
Continuing with an example to block IP ranges, you define exception rules for allowed IP addresses from a blocked IP range.
- In Omnissa Connect, go to Identity Management > Authentication Policies and select the IP address/range tab.
- In the Exception section, select Add an Exception.
- In the Add an exception window, type the IP addresses you want to add as exceptions to the authentication policy in your organization. These IP addresses are allowed access to the organization.
Pay attention to the authentication preference - block or allow
If you activated the Allow IP preference, the system denies users accessing Omnissa services from the IPs on the exceptions list. Conversely, if you activated the Block IP preference, the system allows users access to the organization from the IPs on the exceptions list.
Modify the IP addresses, ranges, or exceptions for your authentication preference
Once you activated an IP authentication policy, you can add additional IPs, IP ranges, and exceptions. You can also modify or remove existing IPs and ranges from the policy.
To make a change, first select the IP address or range from the list, then apply the appropriate action.
Change your IP authentication preference
If you want to switch the authentication preference in your organization from Block IP to Allow IP or vice versa, you must first remove all IP addresses and ranges specified for the current authentication preference.
- In Omnissa Connect, go to Identity Management > Authentication Policies and select the IP address/range tab.
- Select all currently defined IP addresses and ranges.
- Select Remove.
- Select Change in the User IP Authentication Preference area.
- In the User IP Authentication Preference window, select the new option, then select Save.
- To define new IP addresses or ranges for the newly selected policy setting, select Add and enter them.
I accidentally blocked myself and want to unblock my IP
If you accidentally added your IP in the Block IP list for your organization, you must file a support ticket to unblock it. Go to Omnissa Customer Connect to get support. You might need another Owner to file the ticket for you if you cannot access Customer Connect.
Does blocking a user IP address in my organization block them from accessing other organizations to which they are members?
The answer is No. If a user belongs to multiple organizations and an IP based policy is enforced in one of these organizations, their access is blocked in that particular organization. However, they can switch to a different organization and access those services in that organization.
Selecting source domains to restrict access
Source domains allow only users from the specified source domains and subdomains to access the organization.
How do you manage user access at the domain level
As an Owner, you can determine the domains allowed to access your Omnissa Connect organization.
When the source domain authentication policy is activated, only users from the domains you specify can access your organization. Access from all other domains is locked even if the groups and users are added or invited in your organization.
- In Omnissa Connect, navigate to Identity Management > Authentication Policies and select the Source Domain tab.
- To activate the policy, slide the button to either lock or unlock source domains.
- If you slide the button to the Source domains are locked position, enter the domain name you are allowing access to the organization.
- Optionally, to add more domains and sub-domains to the allowed domains list, click the + Add Domains link.
- Select Save.
Source domains are now activated for the domains and subdomains you specified. Only Members logging in from the allowed domains can access your organization. Access for users logging in from a different domain is locked.
Note: It may take up to 30 minutes for the policy to take effect in the organization.
If you or another Owner accidentally locks you out from accessing the organization by not including your domain in the list of source domains that are allowed access to the organization, open a Customer Connect ticket.
Changing the Session Timeout setting
As an Owner, you can determine session timeout intervals. The system logs a user accessing your organization out when the timeout interval is met. The user must re-log in to Omnissa services.
Important: Some Omnissa services have not been enabled to use the Idle Session Timeout feature in Omnissa Connect. To learn if a service you are using in the organization can utilize this setting, contact Customer Connect.
By default the session timeout setting is deactivated. When you activate it, you can modify the following values.
| Setting | Minimum Value | Maximum Value | Default Value |
|---|---|---|---|
| Idle session timeout is the maximum time a logged in user is allowed to stay idle before the session is terminated and they are required to re-authenticate. | 5 minutes | 24 hours | 30 minutes |
| Max session timeout is the maximum time a user is allowed to stay actively logged in to Omnissa services before they are required to re-authenticate. | 30 minutes | 24 hours | 24 hours |
Configuring session timeout
- In Omnissa Connect, navigate to Identity Management > Authentication Policies and select the Session Timeout tab.
- Modify the Idle Session Timeout setting.
- Use the Policy Status slider to activate the setting.
- Define the time values for the setting in the Idle Time fields.
- Select Save.
Was this page helpful?