In this step example of the connector-based federation setup for Omnissa Connect, you set up federation with your corporate identity provider (IdP) and configure the IdP settings on the Omnissa Access tenant created for your enterprise.
You can use any SAML 2.0 compliant third-party IdP to set up enterprise federation with Omnissa Connect. Setup is available as part of the self-service federation workflow for the following providers: Okta, PingIdentity, Microsoft Active Directory Federation Services (ADFS), OneLogin, and Microsoft Entra ID.
To configure a different SAML 2.0 compliant third-party IdP that is not part of this list, select Other.
For this example procedure, ACME enterprise is using Okta.
Procedure
Open two browser instances so that you can work in Omnissa Connect and in your IdP.
- In Omnissa Connect, in the Configure identity provider section of the Set up Enterprise Federation page, select Start.
The Select your identity provider section displays. - In Omnissa Connect, from the list of available third-party identity providers, select Okta.
- Select Next.
The Set up SAML within your identity provider section expands. - In Omnissa Connect, select the View SAML Service Provider Metadata link and download the metadata file.
- If your identity provider supports a URL format, you can also copy the Metadata URL.
- You use the metadata file or the URL to configure your identity provider to establish trust with the Omnissa Access tenant.
- In Omnissa Connect, copy the Single Sign On URL and Audience URI path.
- Open your IdP's admin console, which is Okta for this example.
- Paste the Single Sign On URL and Audience URI you copied from Omnissa Connect.
- Upload the metadata file you downloaded from Omnissa Connect.
- Copy the Name ID configured on your IdP and keep for further reference.
- Download the IdP's metadata file to upload to Omnissa Connect.
- Go back to the self-service federation workflow in Omnissa Connect, expand the Set up SAML within your identity provider section, and select Next.
The Configure your identity provider section of the workflow expands. - In Omnissa Connect, in the IdP Display Name text box, enter a user-friendly name for your IdP.
The system displays this name to the users of Omnissa Connect at login and logout. - In Omnissa Connect, in the Metadata text box, enter the IdP Metadata URL or select XML and paste the Identity Provider Metadata XML file.
- Validation of the metadata starts automatically.
- When validation finishes, a green check box icon indicates that the file was read and parsed successfully.
- If the validation returns an error, check if the URL you entered is correct.
- Ensure that there are not extra spaces or characters in the IdP metadata XML file.
- In Omnissa Connect, select the Name ID Format from the drop-down menu.
The Name ID Format is the value in the SAML response to identify the authenticated user. - In Omnissa Connect, select the Name ID Format and Name ID Value from the drop-down menu that is applicable for your identity provider.
The Authentication Method is automatically populated. - In Omnissa Connect, from the SAML Context drop-down menu, select the type of user authentication for the IdP.
- Select Next.
- The User attributes section expands to display a list of the mandatory and non-mandatory user attributes that you can look for in the SAML response from your identity provider.
- (Optional) In Omnissa Connect, to add a custom user attribute that is not in the list, select Add User Attribute and enter a value matching exactly its name on your IdP.
- Select Next.
- (Optional) In Omnissa Connect, if you indicated that your setup with an identity provider supports group attribute in SAML response, the Group attributes section of the workflow expands, where you add a group attribute and group names to be called for in the SAML request.
- From the drop-down menu, select a group attribute and group names.
- In Omnissa Connect, in the Set user identification preference section, select how users of your enterprise are going to identify themselves when accessing Omnissa Connect from the Omnissa Connect discovery page.
User identification is different from how the user authenticates against your enterprise identity provider. - Select Configure to complete setup.
Results
In this step, you added your identity provider to the Omnissa Access tenant configuration, configured the Omnissa Access tenant as a service provider on your IdP, selected the value to be used for identifying the user in the SAML response, and specified the authentication method to be used to authenticate the user on the identity provider.
What to do next
Was this page helpful?