Skip to main content

August 27, 2026

Step 4: Migrate to Omnissa Identity Service

The last task in the migration process is to migrate directory services from Workspace ONE UEM (and Omnissa Access, if applicable) to Omnissa Identity Service. You perform this task in stages and can roll back from some of the early stages. However, the final step of migrating user provisioning is irreversible, so proceed only when you are ready to complete the migration.

Migration stages include:

  • Prepare Workspace ONE UEM (and Omnissa Access, if applicable)

    Omnissa Identity Service user ID mappings are pushed to Workspace ONE UEM and Omnissa Access.

  • Switch authentication from Workspace ONE UEM (and Omnissa Access, if applicable) to Identity Service

    Federated users are authenticated by your identity provider through Identity Service, instead of being authenticated by Workspace ONE UEM or Omnissa Access. And, if you enabled the Basic user authentication for UEM option, Workspace ONE UEM Basic users are authenticated by Workspace ONE UEM.

    Access policies configured in Omnissa Access are applied.

    You test the user authentication flow now. There is no change to provisioning in this stage, and users continue to be provisioned from Active Directory to Workspace ONE UEM and Omnissa Access.

    Note: If the username format does not match between Workspace ONE UEM and Omnissa Identity Service, the Devices > Mobile Staging > Add Staging Device flow will not work during the Switch Authentication phase of the migration process.

    Important: You must communicate any changes in the authentication experience to your end users prior to performing this step.

  • Migrate user provisioning from Active Directory to Identity Service

    This step completes the migration process. Users are provisioned from your cloud identity provider to Workspace ONE UEM (and Omnissa Access, if applicable) through Identity Service. They are no longer synced from Active Directory. If you were using the AirWatch Provisioning app, users are no longer provisioned from the app and the app is deleted in Omnissa Access.

    Make sure that you perform this step only after you validate that end users can log in after authentication was switched in the previous step.

    Caution: This step is irreversible. You cannot roll back to using Workspace ONE UEM or Omnissa Access directory services after you perform this step. User attributes in Workspace ONE UEM and Omnissa Access will be overwritten with the values from Omnissa Identity Service.

Procedure

  1. In the Omnissa Connect console, select Identity Management > End User Management from the left pane.

  2. Click Launch End User Management.

    Omnissa Identity Service opens in a new tab in the browser.

  3. In the Omnissa Identity Service tab, in the Configuration Steps pane on the right, go to the Compare Directory Data step.

  4. On the Compare Directory Data page, click Proceed to Migration.

  5. Review the directory differences listed in the popup, and, if the differences are acceptable, click Proceed to Migration.

    If you want to try to resolve the differences, click Cancel to go back to the Compare Directory Data page.

  6. Click Migrate.

  7. On the Migrate to Identity Service page, click Prepare UEM or Prepare UEM and Access.

    Wait until the UEM prepared or UEM and Access prepared confirmation message appears before proceeding.

    **Note**: You can roll back this step to go back to the Compare Directory Data page. Typically, you would roll back if you want to change attribute mappings in your identity provider or make other changes that affect user or group attributes in Identity Service.
    
  8. Click Switch Authentication, and confirm your selection.

    Wait until the Authentication switched confirmation message appears before proceeding with testing.

    After you switch authentication, users are authenticated through Identity Service instead of Workspace ONE UEM or Omnissa Access. Federated users are redirected to your identity provider for authentication. If you enabled the Basic user authentication for UEM option, Workspace ONE UEM Basic users are authenticated by Workspace ONE UEM.

    Access policies configured in Omnissa Access are applied.

  9. Verify that users can log in successfully.

    Verify that when users log in, they are redirected to your identity provider to authenticate, and that they can log in successfully. All users that are reported as Existing users in the report (users that exist in both Workspace ONE UEM or Omnissa Access and Identity Service) should be able to log in.

    Note: Some users that are listed as new users in the report might also be able to log in. Missing users will not be able to log in. If a new user synced to Workspace ONE UEM or Omnissa Access from Active Directory after the report was generated and if Identity Service was able to match the user in the Identity Service directory, the user should be able to log in. Identity Service attempts to match new users periodically. This procedure can take up to one hour.

  10. After you complete your testing of the authentication flow:

    • If authentication failed, investigate the failures.

      One way of investigating the failures is to review audit events in the Omnissa Access console. In the Omnissa Connect home page, click the Access tile under Launch Services to access the console. See Generate an Audit Event Report in Omnissa Access for information about viewing audit events.

      If it appears that the failures are due to incorrect mapping between your identity provider and Omnissa Identity Service, you can roll back authentication, change the user attribute mappings, and go through the directory comparison again. To do that, click Roll back authentication and confirm your selection. This takes you back to the Prepare UEM (or Prepare UEM and Access) step. Click Roll back Preparation, then click Go to Reports to go back to the Compare Directory Data page. From that page, you can continue investigating the failures, reviewing the report, or running a new report to compare the Identity Service and Workspace ONE UEM or Omnissa Access directories.

      After you roll back authentication, users are authenticated through Workspace ONE UEM or Omnissa Access again.

    • If authentication succeeded and you are ready to proceed, check the I confirm that end users can log in through Identity Service check box, then click Next.

  11. When you are ready to complete the migration to Identity Service, click Migrate Provisioning in Step 3, Migrate User Provisioning.

    Caution: This is an irreversible step. After you click Migrate Provisioning, the migration process is complete, and you cannot roll back to a previous stage.

    This step might take some time to complete. You can leave the page and return later to check on the progress.

    During migration, users that have different attributes in the Workspace ONE UEM or Omnissa Access directory than in the Identity Service directory are updated in Workspace ONE UEM or Omnissa Access to match the Identity Service values. New users, which exist in the Identity Service directory only, are created in Workspace ONE UEM and Omnissa Access. Missing users, which exist in the Workspace ONE UEM or Omnissa Access directory only, are left untouched. We recommend that you delete the missing users in Workspace ONE UEM and Omnissa Access. Contact Support to request the relevant API documentation for deleting missing users. Also see the "Omnissa Identity Service Migration Phase" section in the Workspace ONE UEM documentation.

    Identity Service attempts to match every user, group, and membership once during this stage.

    After migration is complete, users are provisioned from your identity provider to Workspace ONE UEM and Omnissa Access through Identity Service. They are no longer synced from Active Directory.

Your Workspace ONE UEM directory (and Omnissa Access directory, if applicable) is now migrated to Omnissa Identity Service. Going forward, you manage the directory from Omnissa Identity Service, accessed from Identity Management > End User Management in Omnissa Connect, not from the Workspace ONE UEM or Omnissa Access console.

What to do next

  • Remove the urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:altExternalId mapping from the identity provider.

  • (Applicable when migrating both Workspace ONE UEM and Omnissa Access directories) Because Omnissa Access group names changed during migration, make sure that you update all SAML application, WS-Fed application, and SCIM connector configurations in Omnissa Access that use group names. You must update the configurations manually to use groupname instead of groupname@domain.

  • (Applicable when migrating both Workspace ONE UEM and Omnissa Access directories) If you updated any attributes during the migration process, make sure that you update all SAML applications, WS-Fed applications, and SCIM connector configurations in Omnissa Access that use those attributes.

  • (Applicable when migrating a Workspace ONE UEM directory and an Omnissa Access directory with the AirWatch Provisioning app configured) Delete the OAuth 2.0 client associated with the original directory (of type Other) in Omnissa Access. Also, in your identity provider, deactivate provisioning in the app that was used to provision users and groups to this directory.

    Caution: Be careful that you do not delete the new provisioning app that you created for Omnissa Identity Service.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…