Skip to main content

August 24, 2026

Unlock a Desktop With True SSO

True SSO unlock lets users unlock their desktop by reauthenticating in a browser with the same logon credentials used for True SSO login. It is compatible with Workspace ONE Access. On Horizon Windows Client only, it also supports SP-initiated SSO with any third-party Identity Provider (IdP) that accepts an HTTP POST-bound SAML AuthnRequest.

Prerequisites

True SSO unlock in Horizon has supported Workspace ONE Access as the identity provider on Horizon Client for Windows, Mac, Linux, and iOS. See the requirements below for the minimum Horizon and client versions needed for each platform.

True SSO unlock now also supports SP-initiated SSO with any third-party Identity Provider that accepts an HTTP POST-bound SAML AuthnRequest. This third-party IdP support is currently available only on Horizon Client for Windows.

General requirements:

  • Horizon 7.8 or later
  • Workspace ONE Access 19.03 or later, using Workspace ONE Access as the identity provider
  • Horizon Client for Mac 2306 or later, if using Horizon Client for Mac
  • Horizon Client for Linux version 2306 or later, if using Horizon Client for Linux
  • Horizon Client for iOS 2512 or later, if using Horizon Client for iOS

Additional requirements for third-party IdP support:

  • Horizon Client for Windows 2606 or later
  • Horizon Connection Server 2606 or later
  • The third-party IdP must support SP-initiated SSO with an HTTP POST-bound SAML AuthnRequest“

Procedure

  1. Enable Workspace ONE Access, or your third-party IdP (Windows Client only), and configure it for use with Connection Server.

    See the Workspace ONE documentation on the Omnissa Product Documentation portal or your IdP's SAML SP-initiated SSO configuration documentation..

  2. Configure Horizon Connection Server for True SSO.

    See Configure Horizon Connection Server for True SSO.

  3. To start virtual or published desktops, connect to a Connection Server that has True SSO configured, in Workspace ONE mode. If using Horizon Client for Windows, you can alternatively connect in an SP-initiated SSO mode configured with your third-party IdP.See the Horizon Client documentation on the Omnissa Product Documentation portal.

  4. Start virtual or published desktops from the Workspace ONE portal so that the user can use single sign on with True SSO. If using Horizon Client for Windows with a third-party IdP, start the desktop directly from Horizon Client, which initiates SP-initiated SSO with your third-party IdP.

  5. Lock the desktop.

  6. To unlock the desktop, on the lock screen displayed by the Horizon Agent, select True SSO User and click Submit.

    Horizon Client opens a browser on your local client device to re-authenticate with Workspace ONE Access. If using Horizon Client for Windows with a third-party IdP, the browser instead re-authenticates with your third-party Identity Provider.

  7. Enter your credentials for the locked desktop, and complete any additional authentication required by your identity provider.

What to do next

You can disable this feature by setting a registry key on the machine where Horizon Agent is installed:

  • Key: HKLM\Software\Omnissa\Horizon\Agent\CertSSO (also supported under HKLM\Software\Policies\Omnissa\Horizon\Agent\CertSSO for centralized Group Policy deployment)
  • Value name: DisableCertSSOUnlock (REG_SZ)
  • Value data: true (or false to re-enable)

Note: DisableCertSSOUnlock is a REG_SZ string type, where the value is set to true or false to enable or disable the feature. You can also disable this feature on the Horizon Client you are using.

Horizon ClientSteps to disable feature
Horizon Windows Client Set the registry key DisabledFeatures=TrueSSOUnlock in the following locations: [HKEY_CURRENT_USER\Software\Omnissa\Horizon\Client] or [HKEY_LOCAL_MACHINE\Software\Omnissa\Horizon\Client].

Value name: DisabledFeatures (REG_SZ)
Value data: TrueSSOUnlock (or a semicolon-separated list to disable multiple features, e.g. TrueSSOUnlock;OtherFeature)

If the registry key is set, the Horizon True SSO User option does not appear when the user unlocks the desktop. This applies regardless of whether Workspace ONE Access or a third-party IdP is configured.
Horizon Linux ClientSet view.enableTrueSSOUnlock=‘FALSE'
Horizon Mac ClientEnableTrueSSOUnlock = ‘0’ in plist
Horizon iOS Client
  1. Create a local text file named config.txt.
  2. Add this line to the file and save it: EnableTrueSSOUnlock=0.
  3. Sync this file to the public folder for Omnissa Horizon Client for iOS. (Horizon Client for iOS has published its Document directory and it is visible in the Files app).

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…