Integration between Omnissa Horizon and Omnissa Access (formerly called Workspace ONE) uses the SAML 2.0 standard to establish mutual trust, which is essential for single sign-on (SSO) functionality. When SSO is enabled, users who log in to Omnissa Access or Workspace ONE with Active Directory credentials can launch remote desktops and applications without having to go through a second login procedure.
When Omnissa Access and Omnissa Horizon are integrated, Omnissa Access generates a unique SAML artifact whenever a user logs in to Omnissa Access and clicks a desktop or application icon. Omnissa Access uses this SAML artifact to create a Universal Resource Identifier (URI). The URI contains information about the Omnissa Horizon Connection Server instance where the desktop or application pool resides, which desktop or application to launch, and the SAML artifact.
Omnissa Access sends the SAML artifact to the Horizon client, which in turn sends the artifact to the Horizon Connection Server instance. The Horizon Connection Server instance uses the SAML artifact to retrieve the SAML assertion from Omnissa Access.
After a Horizon Connection Server instance receives a SAML assertion, it validates the assertion, decrypts the user's password, and uses the decrypted password to launch the desktop or application.
Setting up Omnissa Access and Omnissa Horizon integration involves configuring Omnissa Access with Omnissa Horizon information and configuring Omnissa Horizon to delegate responsibility for authentication to Omnissa Access.
To delegate responsibility for authentication to Omnissa Access, you must create a SAML authenticator in Omnissa Horizon. A SAML authenticator contains the trust and metadata exchange between Omnissa Horizon and Omnissa Access. You associate a SAML authenticator with a Horizon Connection Server instance.
Note: If you intend to provide access to your desktops and applications through Omnissa Access, verify that you create the desktop and application pools as a user who has the Administrators role on the root access group in Omnissa Horizon Console. If you give the user the Administrators role on an access group other than the root access group, Omnissa Access will not recognize the SAML authenticator you configure in Omnissa Horizon, and you cannot configure the pool in Omnissa Access.
Was this page helpful?