For Horizon Cloud, perform the following steps to configure Omnissa Identity Service as your identity provider with either integrated Entra ID or integrated Okta.
Prerequisites
-
Verify that you have access to Horizon Cloud. To create a login, see Onboarding for Horizon Cloud Administrators.
-
Verify that you have configured an Omnissa Identity Service account. See Getting Started with Omnissa Identity Service.
For related information, see the Using Omnissa Identity Service with Horizon Cloud.
More information about configuring and using Omnissa Identity Service is available in the Configuring User Provisioning and Identity Federation with Omnissa Identity Service topic.
Integrate Omnissa Identity Service with Microsoft Entra ID
To integrate Omnissa Identity Service with Microsoft Entra ID as your identity provider for Horizon Cloud, follow the instructions provided at Integrating Omnissa Identity Service with Microsoft Entra ID in Omnissa Identity Management product documentation.
Integrate Omnissa Identity Service with Okta
To integrate Omnissa Identity Service with Okta as your identity provider for Horizon Cloud, follow the instructions provided at Integrating Omnissa Identity Service with Okta and Using Omnissa Identity Service with Horizon Cloud in Omnissa Identity Management product documentation.
The following attributes must be configured when using Okta with Omnissa Identity Services as the configured identity provider:
-
onPremisesSamAccountNameasactive_directory.samAccountName -
onPremisesSecurityIdentifierasactive_directory.objectSid -
onPremisesUserPrincipalNameasactive_directory.userName
Integrate Omnissa Identity Service with Google Identity (Google Workspace and Cloud Identity)
To integrate Omnissa Identity Service with Google Identity (Google Workspace and Cloud Identity) as your identity provider for Horizon Cloud, follow the instructions provided at Configuring User Provisioning and Identity Federation with Omnissa Identity Service in Omnissa Identity Management product documentation.
The following attributes must be configured when using Google Identity with Omnissa Identity Service as the configured identity provider:
-
userNameasBasic Information > Username -
name.givenNameasBasic Information > First name -
name.familyNameasBasic Information > Last name -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.userPrincipalNameas attribute mapped toonPremisesUserPrincipalName -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.onPremisesSamAccountNameas attribute mapped toonPremisesSamAccountName -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.onPremisesUserPrincipalNameas attribute mapped toonPremisesUserPrincipalName -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.onPremisesSecurityIdentifieras attribute mapped toonPremisesSecurityIdentifier -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.securityIdentifieras attribute mapped toonPremisesSecurityIdentifierNote:
- The last four of the above attributes (
userPrincipalName,onPremisesSamAccountName,onPremisesUserPrincipalName, andonPremisesSecurityIdentifier) require a custom schema to be created in Google Workspace before they can be mapped. These custom attributes are not available by default in the Google OIS SAML app. onPremisesSecurityIdentifierandsecurityIdentifierboth map to the same custom attribute, namelyonPremisesSecurityIdentifier.- GCDS automatically encodes binary attributes using Base64 URL no-padding encoding.
- The last four of the above attributes (
These attributes are critical for the following elements:
- Desktop assignment — used for matching the user to their AD identity.
- SSO — used for passing the correct identity token to the Horizon agent.
- Domain join validation — used for verifying the user's on-premises security context.
Was this page helpful?