Skip to main content

July 1, 2026

Using SAML Authentication for Omnissa Workspace ONE Access Integration

Integration between Horizon 8 and Omnissa Workspace ONE Access (formerly called Workspace ONE) uses the SAML 2.0 standard to establish mutual trust, which is essential for single sign-on (SSO) functionality. When SSO is enabled, users who log in to Workspace ONE Access or Workspace ONE with Active Directory credentials can launch remote desktops and applications without having to go through a second login procedure.

When Workspace ONE Access and Horizon 8 are integrated, Workspace ONE Access generates a unique SAML artifact whenever a user logs in to Workspace ONE Access and clicks a desktop or application icon. Workspace ONE Access uses this SAML artifact to create a Universal Resource Identifier (URI). The URI contains information about the Connection Server instance where the desktop or application pool resides, which desktop or application to launch, and the SAML artifact.

Workspace ONE Access sends the SAML artifact to the Horizon client, which in turn sends the artifact to the Connection Server instance. The Connection Server instance uses the SAML artifact to retrieve the SAML assertion from Workspace ONE Access.

After a Connection Server instance receives a SAML assertion, it validates the assertion, decrypts the user's password, and uses the decrypted password to launch the desktop or application.

Setting up Workspace ONE Access and Horizon integration involves configuring Workspace ONE Access with Horizon 8 information and configuring Horizon 8 to delegate responsibility for authentication to Workspace ONE Access.

To delegate responsibility for authentication to Workspace ONE Access, you must create a SAML authenticator in Horizon 8. A SAML authenticator contains the trust and metadata exchange between Horizon 8 and Workspace ONE Access. You associate a SAML authenticator with a Connection Server instance.

Note: If you intend to provide access to your desktops and applications through Workspace ONE Access, verify that you create the desktop and application pools as a user who has the Administrators role on the root access group in Horizon Console. If you give the user the Administrators role on an access group other than the root access group, Workspace ONE Access will not recognize the SAML authenticator you configure in Horizon 8, and you cannot configure the pool in Workspace ONE Access.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…