Skip to main content

July 17, 2026

Governance

Use the Governance area in Omnissa Connect to work with many basic Identity Governance and Administration (IGA) features like controlling role requests and default roles in IGA activated organizations, managing OAuth app and admin access violations, and managing API Tokens. If you want to use advanced IGA features, learn how you can get these features activated and linked for your federated domains.

Requirements to use IGA features

Your organization must have federated domains to use IGA features.

Benefits of using IGA features

As anwith basic IGAwith advanced IGA
Owner- Access the IGA dashboard Governance page in Omnissa Connect.
- Activate or deactivate your Members ability to submit self-service requests for additional roles.
- Govern access to services in your organization by managing incoming Organization and Service role requests.
- Monitor violations and immediately respond to threats.
Onboard a service in any governance activated organization linked to your corporate identity provider.
MemberIf activated in the organization, submit self-service access requests for additional Organization and Service roles.Onboard yourself in any governance activated organization linked to your corporate identity provider.

Advanced IGA

Enterprise Administrators of federated domains can activate or deactivate advanced IGA features for organizations in their enterprise from the Enterprise Federation dashboard in the Management Organization.

The Related Organizations section of the Enterprise Federation dashboard lets you view a list of the organizations in your federated domains for which advanced IGA features are activated or deactivated. As an Enterprise Administrator you manage access to the advanced IGA features for all organizations in your enterprise.

Activate advanced IGA features

An Enterprise Administrator must activate the advanced IGA features for some or all Omnissa Connect organizations that are linked to their corporate Identity Provider.

  1. Log in to the Management Organization.
  2. In the left navigation, go to Identity Management > Enterprise Federation. You are now in the Enterprise Federation dashboard.
  3. Select the Organization Linked to Corporate IdP tile.
  4. In the list of organizations that displays, select one or more organizations for which to activate advanced IGA features.
  5. Select Activate Advanced Features.

The Owners of the selected organizations are now able to use the advanced IGA features.

If your domain is federated, you can use the advanced Identity and Governance Administration (IGA) features to easily onboard non-organization admins to Omnissa Connect.

Link your organization to your Identity Provider (IdP). Only Owners of federated domains can link their organizations to their IdP.

  1. Log in to Omnissa Connect and select Organization Settings.
  2. Scroll down to the Domains Linked to Identity Provider section and select Link Identity Provider.
    The IdP and domains associated with your organization display in a pop-up window.
  3. Select Link, then choose Continue.

Advanced IGA features are now available for your organization if the Enterprise Administrator has activated advanced IGA features in the Enterprise Federation dashboard.

Requests

As an Owner of an Identity Governance and Administration (IGA) activated organization, you manage Organization and Service role requests through the Administrator Access > Governance > Requests area.

Activate or deactivate self-service requests

  1. Go to Administrator Access > Governance > Requests > Settings.
  2. In the Request for additional roles area, activate or deactivate the Status slide button.
  3. Select Save.

Process pending requests for additional roles

All incoming requests for Organization and Service role access are listed on the Administrator Access > Governance > Requests page, in the Pending Requests section. The Past Requests area lets you view historical data for all requests created in your organization.

To approve or deny requests, select one or several entries in the Pending Requests list and select the respective button. The admins requesting the role access receive an email notification when their request is approved or denied.

Can you modify access requests before you approve them?

As an Owner, you can modify the time period for Service role access requested by a Member. You view the time period of the original request by selecting the Request ID link. To change the requested time period, select Approve, then select Approve with modification. Change the setting and submit the change you made.

Note: The Approve with modification option is available only for Service role access requests and is not applicable for Organization roles.

Owners cannot modify the Service role access originally requested by the Member. If you want to provide guidance to the requester about the proper level of access you are willing to approve, you have the option to include a message when denying their request. The requester receives an email notification and can submit a new access request with the appropriate Organization and Service roles.

Requests and granting default roles (advanced IGA feature)

As an Owner in an Identity Governance and Administration (IGA) activated organization, you can assign default Organization and Service roles to admins in your organization by setting up a policy.

The default roles granted through that policy apply to all admins logging in the organization from a specified federated domain and cannot be edited at the admin level. To change the default role entitlements, you must modify the policy.

Known limitation

There is a known issue that as an Owner, you cannot view the admins in your organization who have been granted default roles based on the policy and who have no other roles in the organization. These admins will not display on the Administrators list in Omnissa Connect unless they request additional roles and the requests are approved. After admins with default roles obtain additional roles in the organization, they appear on the Administrators list. As an Owner, you can grant them additional roles.

Prerequisites

  • Your corporate identity provider is linked to Omnissa Connect.
  • Advanced IGA features are activated in the organization.
  • You have an Owner role in the organization.

Procedure

  1. Log in to Omnissa Connect.
  2. Navigate to Administrator Access > Governance and select the Requests tab.
  3. Select Settings.
  4. In the Grant Default Roles section, select the Add Domain Policy link.
  5. Complete the Add domain policy widget.
    1. Enter a name and description for the new policy.
    2. Select the domain to which you want to apply the policy.
    3. Select the Organization roles that you want to automatically assign to all admins logging into your organization from the specified domain.
    4. Select any additional roles from the Additional Roles list.
      • A Member needs the Developer role to create and manage OAuth apps.
      • An Administrator or a Member needs the Billing Read-only role to view billing.
    5. Select Save.

Results

The roles you specified become available to all admins from the specified domain upon their login to Omnissa Connect.

Violations

As an Owner in an Identity Governance and Administration (IGA) activated organization, you monitor access violations for admin logins and logins with OAuth apps and API tokens in your organization. You define and modify the policies for triggering violations.

You set up violation policies for logins in your IGA-activated organization by activating various triggers for OAuth apps and API tokens, such as inactive API tokens, inactive OAuth owners, broad service scopes, or insecure or unapproved URIs for OAuth apps.

Note: If a Source Domain authentication policy is activated, User Access violations are captured for all login attempts originating from domains that are not allowed by the policy setting.

Configure violation policies for OAuth apps

  1. Go to Administrator Access > Governance > Violations and use the Settings menu option.
  2. Configure OAuth Apps Settings page that opens, modify the settings for OAuth Apps as appropriate.
  3. Select Save.

Manage violations

As an Owner in an Identity Governance and Administration (IGA) activated organization that monitors violations, you can take action against the violations discovered in your organization. You access the full list of violations by navigating to Administrator Access > Governance > Violations.

The violations captured in your organization are grouped by the type of authentication method used to log in to Omnissa Connect that triggered the violation. Select the respective tab to view the full list and possible actions you can take to respond to a violation.

  • The Administrator Access > Governance > Violations > OAuth Apps tab displays the name of the app that triggered the violation, its severity, description, and email of the organization admin who created the OAuth app.
  • The Administrator Access > Governance > Violations > User Access tab displays the email of the organization admin whose login attempt triggered the violation, its severity, the date the violation took place, and the source domain from which it occurred. An admin access violation is captured for login attempts from any domain that is not allowed by the Source Domain authentication policy.
  • The Administrator Access > Governance > API Tokens tab displays the name of the API token that triggered the violation, its severity, description, and the email of the organization admin who created the API token.

The following table describes the actions you can take in response to violations in your organization.

To...Do the following...
Change the visibility of a violationThis action changes the visibility status of a violation from Active to Hidden. It does not delete the violation and can be reverted.

1. Locate the violation you want to hide and select its corresponding double arrow to expand its details.
2. Select the check box next to the active violation you want to hide.
3. Select Hide.

The violation is no longer displayed in the details section.
Display a violation that has been hiddenThis action displays violations with Hidden status.

Expand a violation's details section and toggle the Display All on. All violations that have been hidden are displayed.
Remove an OAuth app from your organizationThis action removes the OAuth app and blocks it from accessing the organization. The OAuth app is not deleted, yet no further violations will be reported from this app. The removal action cannot be reverted from the Violations page – to monitor violations from this OAuth app it has to be added to the organization again.

1. On the Violations page, open the OAuth Apps tab.
2. Locate the app you want to remove.
3. Select the check box next to its name.
4. Select Remove.
Edit the severity of a violationBased on your organization's needs, you can define the severity for any violation criterion.

1. On the Violations page, click Settings.
2. Use the Severity drop-down menu to change the setting for each violation criterion you want to modify.
3. Select Save.

API Tokens

As an Owner in an Identity Governance and Administration (IGA) activated organization, you monitor the API tokens created in your organization and set constraints for idle and maximum Time to live (TTL) policies for all newly created tokens.

To access the API Tokens dashboard, open Omnissa Connect and navigate to Administrator Access > Governance > API Tokens tab. The dashboard that opens gives you a list of all API tokens created by admins in your organization.

For each API token, you can view details, such as token name, name of the organization admin who created the API token, creation and expiration dates, the date the token was last used, and the scopes of the token – the Organization roles assigned to the token.

The API Tokens dashboard list displays an alert icon if the TTL policies for your organization have been violated. The TTL policies set for your organization apply to all new API tokens created by the admins in your organization. If you change a TTL policy, an alert icon will appear next to all previously created API tokens which are violating the new setting.

There are two TTL policy settings you can activate, deactivate, or modify:

  • Idle Token TTL: This setting defines what is the allowed idle Time to live for an API token before it violates the policy.
  • Max Token TTL: This setting defines what is the maximum allowed Time to live for any API token created in your organization. Organization admins will not be able to generate API tokens with a Max Token TTL greater than the one defined by this setting.

What can you do if an API token violates a policy or guideline?

If an API token violates a TTL policy in your organization or in any way looks suspicions to you, you can deactivate the token from the API Tokens dashboard. This way it cannot be used to access the resources in the organization.

  1. On the API Tokens dashboard, select the API token you want to deactivate.
  2. Select the Deactivate link.
    • The API token status changes from Activated to Deactivated.
    • The owner of the API token receives an email notification from Omnissa Connect that a token they've been using to access the organization has been deactivated by an Owner.
  3. To reactivate an API token that has been deactivated, select the API token on the dashboard, then select the Activate link.
    • The owner of the API token receives an email notification confirming the reactivation.

How do you change the TTL policies for API tokens?

To modify the API tokens TTL policies, do the following:

  1. In Administrator Access > Governance > API Tokens tab, select Settings.
    • To activate or deactivate a policy, use the Policy Status slider.
    • To change a TTL setting, enter a new value in the respective TTL setting section and select a time unit from the drop-down list. The time unit can be minutes, hours, or days.
  2. Select Save.

API Token validation runs occur once every 24 hours

Validation runs of existing tokens against the policies take place once every 24 hours. It might take some time before the API Tokens dashboard list of violations gets updated as a result of the change you made.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…