View an example of how to download and install an on-premises Omnissa Access connector so that you can use it for connector-based federation setup in Omnissa Connect.
General workflow
The Omnissa Access connector you install in this task is used to continuously sync groups and users from your enterprise Active Directory with the Omnissa Access tenant. The Omnissa Access tenant instance is created and configured as part of the self-service federation workflow. It acts as an identity broker (service provider) to your identity provider and is not involved in the actual user authentication.
Note: By default, the Omnissa Access connector syncs newly added groups and users from your enterprise Active Directory once per week. Post-federation, sync frequency can be modified or sync can be run manually.
In this task, you configure a password that is used to encrypt the contents of the configuration file you download with the Omnissa Access connector installer. When you run the installer, you will be prompted for the location of the downloaded configuration file and the password to decrypt the file contents and get the connection details of the Omnissa Access tenant. The connector uses these details to establish a secure communication with the Omnissa Access instance.
To complete this step, you must step out of the self-service federation workflow and complete the installation and configuration of the Omnissa Access connector on an on-premises Windows machine.
Kerberos needed or not
Not required: If your enterprise uses a third-party IdP for user authentication, the federation setup requires you to create a default installation of the Omnissa Access connector with User Auth Service and Directory Sync Service. For this type of setup, you do not need to install the Kerberos Auth Service.
Required: If your enterprise does not use a SAML 2.0 based IdP for user authentication, you can use the authentication methods supported by the Omnissa Access connector. You can install the Kerberos Auth Service and use it for cloud-based user authentication. For detailed installation information, see Installing Omnissa Access Connector.
- Internally, the connector establishes an intranet connection with your enterprise Active Directory.
Note: If you are using security policies to control access to the machine hosting your enterprise Active Directory, make sure you include the machine on which you install Omnissa Access connector in the allowed list of your AD host. - Externally, the connector establishes a secure outbound connection to a hosted instance of an Omnissa Access tenant created for your enterprise as part of the self-service federation process.
- The hosted instance of the Omnissa Access tenant acts as an identity broker (service provider) to your third-party SAML 2.0 IdP. It is not involved in the actual user authentication.
- If the Omnissa Access based authentication method is used, then the Omnissa Access tenant authenticates users directly against your enterprise Active Directory through the on-premises connector.
Important: Omnissa Access tenant or Omnissa Access connector does not persist any user credentials.
Prerequisites
- You must have verified domains.
- Verify that you have access to a machine with installed MS Windows Server 2008 or later.
- Verify that you can access your enterprise Active Directory from the host Windows machine.
- The host Windows machine must have a static IP address and a DNS resolvable FQDN.
- The connector must have network access to Active Directory on ports 389/636.
- Verify that your corporate firewall is configured to make an outbound connection from the Omnissa Access connector to port 443 for interaction with the hosted Omnissa Access tenant service.
- If you already have the Omnissa Access Connector installation file, verify that you have the latest version.
Caution: The configuration file contains sensitive information, such as the tenant URL, tenant ID, the client ID, and client secret for each of the enterprise services, and the password hash. It is critical that you do not share the file or expose it publicly.
Important:
- The password you generate in this step is stored in the configuration file you download with the Omnissa Access connector installer. You must provide this password during the installation of the connector to validate that the user who created the configuration file is the same as the user installing the connector. Make sure the password you create is safely stored and accessible.
- If connection status does not change to Connector Installed Successfully, you can file a ticket with Support.
Notes:
- You need an Omnissa account to download the Omnissa Access connector installation file. Ignore this step for all other Omnissa Access connector versions.
- If your Windows server host setup uses a normal or an authenticated proxy, you must select the Custom Installation menu item. If you decide to switch from a non-proxy default connector installation to a proxy custom installation setup, you can run the installation file again and make the necessary changes.
Procedure
- In Omnissa Connect, in the Install Omnissa Access connector section, select Start.
The Set connector password section expands. - Select one of the options to generate a password and save it.
- Select Next.
The Download installer and configuration section expands. - Download the Omnissa Access connector installer.
- If you must run the installer on a different machine than the one from which you access the self-service federation workflow, copy the link to the Omnissa Access connector installer.
- You can then open the link in a browser window on your target Windows machine.
- Check the version of the Omnissa Access connector installer you downloaded.
- If you downloaded version 21.08.0.0 or later, you must deselect the Virtual App service.
- This action is emphasized later in this procedure.
- Download the encrypted configuration file.
- On your Windows server, open the installer file location.
- Run the Omnissa Access connector installer as an administrator.
- On the Welcome page, select Next.
- Read and accept the license agreement, and select Next.
- Select Directory Sync Service and User Auth Service for the installation.
- If the connector version is 21.08.0.0 or later, deselect the Virtual App service.
- Select Next.
- By default, the services are installed in C:\Program Files.
- To change the installation folder, select Change and select a new folder.
- On the Specify Configuration File page:
- Select the configuration file that you downloaded from the Install Omnissa Access connector > Download installer and configuration files step of the self-service federation workflow.
- Enter the password you set for the configuration file.
- Select Next.
- For the purposes of this example, select the Default installation menu item and select Next again.
- In the Ready to Install the Program page, review your selections and then select Install.
The installation takes a few minutes. - After the installation finishes successfully, verify that the services you installed are running on the Windows server.
- The following services must be running on the Windows server.
- Directory Sync Service
- User Auth Service
- After the installation, the enterprise services that you installed are registered with the Omnissa Access tenant.
- The following services must be running on the Windows server.
- Open Omnissa Connect and log in to the ACME Management Organization.
- Navigate to Install Omnissa Access connector > Run installer and configuration and select Check Connection.
The status of the connection changes to Connector Installed Successfully. - Select Continue.
Results
The Home page of the self-service federation workflow displays.
What to do next
The next step of the self-service federation setup is to sync groups and users between your enterprise Active Directory and the Omnissa Access tenant.
Was this page helpful?