Skip to main content

July 17, 2026

Dynamic Federation Setup

The dynamic (connectorless) type of federation setup involves configuring your third-party identity provider for dynamic user and group provisioning in Omnissa Connect.

General workflow

To set up dynamic federation, follow these general steps.

  1. Verify domains.
  2. Configure the identity provider.
    • Configure the identity provider as SAML-based authentication with JIT or SCIM dynamic provisioning.
    • Configure the identity provider as OIDC-based authentication with SCIM dynamic provisioning.
  3. Complete the setup by validating that users can log in, notifying users that they must log in, and activating the federation for the enterprise.
  4. Link your Omnissa account.

This content offers a high-level overview of the steps in the federation setup of the dynamic admin (user) and group provisioning workflow. Some of the steps are common for all IdP configurations.

Step 1: Verify domains.

In this step, you verify the ownership of the domains that you want to federate. The verification process involves adding DNS TXT records for your domains. Before you begin, verify that you can modify the DNS records for your corporate domains.

The domains you add in this step are the top-level public domains that your enterprise employees use to access Omnissa Connect. These domains are not your internal Active Directory domains.

Note: The verification does not happen automatically. It might take up to 72 hours after submitting the TXT records for the changes to take effect.

Step 2: Configure the identity provider.

In this step, you configure the identity provider (IdP). You can enable federation for your enterprise with any SAML 2.0-based third-party identity provider or one that supports OIDC. The self-service federation setup process provides guided configuration support for the following IdPs: Okta, PingIdentity, Microsoft Active Directory Federation Services, OneLogin, and Microsoft Entra ID.

To configure your third-party IdP for enterprise federation, you must have access to the identity provider console and the IdP's metadata URL.

Step 3: Validate users and activate federation.

In these steps of the federation setup, you must perform a list of actions.

Important Notes:

  • After enterprise federation is activated, users with federated domains can only access Omnissa Connect using their corporate accounts. They can no longer use other accounts to log in to Omnissa Connect.
  • Omnissa Connect does not allow changing the identity provider you configure in this step, after federation is activated. If you must change your identity provider later, file a support ticket
  1. Validate that the users from your enterprise can log in to Omnissa Connect by using your corporate IdP.
  2. Notify the enterprise users of the domains that you specified that they have to log in to Omnissa Connect by using their corporate credentials.
  3. Acknowledge the changes and activate the federation for your enterprise.

After you complete the federation setup, Enterprise Administrators can modify the initial setup from the Enterprise Federation dashboard.

In the last step of the workflow, you link your federated account to your Omnissa account. This step is necessary to complete for the following roles:

  • Enterprise Administrators, Owners who participated in the self-service federation setup.
  • Owners and Members who need access to billing information.
  • Owners and Members who want to be able to file support requests.

For details about linking your federated account with your Omnissa account, see Federated Accounts, Omnissa Accounts, and How to Link Them .

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…