Skip to main content

August 19, 2026

Troubleshooting Omnissa Identity Service

To troubleshoot provisioning and authentication errors for a directory provisioned from your identity provider to Omnissa Identity Service, review logs and audit events in the identity provider, Omnissa Identity Service, and Omnissa services such as Omnissa Access, Workspace ONE UEM, and Horizon Cloud.

Review Identity Provider Provisioning Logs

For provisioning errors, first review the provisioning logs in the identity provider to see if there were errors in provisioning users or groups to Omnissa Identity Service, and resolve the errors.

Microsoft Entra ID

In the Microsoft Entra admin console, you can find the provisioning logs on the provisioning app's Provisioning page.

Select Manage - Provisioning, then click the View provisioning logs link.

In the Provisioning Logs page, click on a user to see details.

The Provisioning log details pane shows details about the user.

Google Workspace

To find provisioning logs for Google Workspace, see Monitor automated user provisioning in the Google Workspace documentation.

Review Omnissa Identity Service Provisioning Logs

Review the provisioning logs in Omnissa Identity Service to see if there were errors in provisioning users from Omnissa Identity Service to services such as Omnissa Access and Workspace ONE UEM.

  1. Navigate to Omnissa Identity Service.

    • Cloud: Log in to the Omnissa Connect console, select Identity Management > End User Management from the left pane, then click Launch End User Management.
    • On premises: Log in to the Omnissa Access console, select Integrations > Identity Service, then click Configure SCIM Provisioning.

    Omnissa Identity Service opens in a new tab in the browser.

  2. Click View on the directory card.

  3. Select the Status tab to view the provisioning status and errors.

For more information, see Viewing Provisioning Status and Errors in Omnissa Identity Service.

The Status tab displays real-time errors. To view historical data, you can review audit events in the Events tab. See Viewing Audit Events in Omnissa Identity Service for information.

Review Workspace ONE UEM Logs

Use the following troubleshooting resources for Workspace ONE UEM:

  • Provisioning logs and initial configuration logs in the following folder:

    C:\AirWatch\Logs\AW_Core_Api

  • For configuration errors:

    • Use the following GET API for the configuration:

      Workspace_ONE_UEM_URL/api/system/provisioning/config/locationgroupuuid

    • Check the errors in the core API logs.

  • For provisioning issues, check the core API logs and look for errors or exceptions from the SCIM APIs.

Review Omnissa Access Audit Events

Review audit events in Omnissa Access for authentication failures.

  1. In the Omnissa Access console, select Monitor > Reports.

  2. Select Audit Events from the drop-down menu.

  3. Specify a user, select the type of event, specify a time frame, and click Show.

    For authentication failures, see the LOGIN and LOGIN_ERROR events.

Common Issues

Entra ID

  • Users cannot authenticate when Microsoft Entra ID is configured as the third-party identity provider using OpenID Connect

    Verify that you copied the correct values from the OpenID Connect app in Microsoft Entra ID to step 5, Configure OpenID Connect, in the Omnissa Identity Service wizard. Specifically, check the Client Secret and the Application (client) ID values. See Step 5: Configure Authentication.

  • Deleting a user in Microsoft Entra ID does not delete the user from Omnissa Identity Service

    When you delete a user in Microsoft Entra ID, the account is suspended for a specific period of time before being deleted. The user is deactivated in Omnissa Identity Service for that period of time. The username of the deleted user is also modified in Microsoft Entra ID, and the changes are reflected in Omnissa Identity Service. See How Microsoft Entra ID Users Are Deleted for more information.

  • Deleting user and group attribute values in Microsoft Entra ID does not delete the values in Omnissa Identity Service

    In Microsoft Entra ID, when you delete a user or group attribute value that was already synced to Omnissa Identity Service, the value is not deleted in Omnissa Identity Service and the Omnissa services integrated with it. Microsoft Entra ID does not propagate null values.

    As a workaround, instead of clearing the value completely, enter a space character.

  • Deleting an attribute mapping in Microsoft Entra ID or Okta does not remove the attribute from users in Omnissa Identity Service

    When you delete an attribute mapping from the provisioning app in Microsoft Entra ID or Okta, the changes are not propagated to Omnissa Identity Service. The attribute is not deleted for users in Omnissa Identity Service and the Omnissa services integrated with it.

  • Provisioning restart might be required in some cases

    If you make any changes in Omnissa Identity Service to groups provisioned from Microsoft Entra ID, for example, if you delete a user or group, and you want to restore the data, you might need to restart provisioning in the Microsoft Entra admin center. See Known issues for provisioning in Microsoft Entra ID in the Microsoft documentation for more information.

Okta

  • Group attribute mappings are not supported

    When Omnissa Identity Service is integrated with Okta, you cannot specify group attribute mappings in Okta to synchronize to Omnissa Identity Service. You can only map user attributes.

  • Deleting an attribute mapping in Microsoft Entra ID or Okta does not remove the attribute from users in Omnissa Identity Service

    When you delete an attribute mapping from the provisioning app in Microsoft Entra ID or Okta, the changes are not propagated to Omnissa Identity Service. The attribute is not deleted for users in Omnissa Identity Service and the Omnissa services integrated with it.

Other Issues

  • login_hint not sent

    When you integrate a third-party identity provider with Omnissa Identity Service using the OpenID Connect protocol, the login_hint feature does not work. If the relying party sends a login_hint, Omnissa Identity Service does not pass it to the identity provider.

  • You are not receiving token expiry notifications

    When your Omnissa Identity Service token is about to expire or has expired, you receive notifications, both as a banner in the Omnissa Connect console and by email. If you are not receiving any notifications, verify that Omnissa Identity Service is integrated with Workspace ONE Intelligence.

    1. Log in to Omnissa Connect.
    2. Select Integrations > Data Sources.
    3. Find the Omnissa Access card.
      Note: Omnissa Identity Service is co-located with the Omnissa Access service.
    4. Make sure the Omnissa Access card displays the status Authorized.
    5. If the Omnissa Access card does not display Authorized, click Set Up on the card.
    6. Click Get Started.
    7. Click Connect to Omnissa Access.
    8. Click Finish.

    If you can see the banner notification but do not receive email notifications, verify that you have opted in to receive email notifications. See How to enable email notifications.

  • You want to change the third-party identity provider after creating a directory

    After you enable Omnissa Identity Service, select the third-party SCIM 2.0 identity provider, and create a directory, you cannot change the identity provider selection. To change the identity provider, you must deactivate Omnissa Identity Service and then enable it again.

    To deactivate Omnissa Identity Service, follow the instructions in Deactivating Omnissa Identity Service.

  • After enabling Omnissa Identity Service, you want to deactivate it

    You might need to deactivate Omnissa Identity Service in scenarios such as the following:

    • You enabled Omnissa Identity Service to try it out and now want to deactivate it.
    • Your use cases are not supported by Omnissa Identity Service.
    • You want to sync users and groups directly from Active Directory, which is only supported when you configure your directory in Workspace ONE UEM, Omnissa Access, or Horizon Cloud instead of Omnissa Connect.

    To deactivate Omnissa Identity Service, follow the instructions in Deactivating Omnissa Identity Service. After you deactivate the service, you can configure directory services and identity federation in Workspace ONE UEM, Omnissa Access, and Horizon Cloud directly.

  • You get an error when you try to enable Omnissa Identity Service after deactivating it

    If you deleted your directory and deactivated Omnissa Identity Service, you might get an error when you try to enable it again.

    It takes some time for the directory to be deleted. Go to the Omnissa Access console and confirm that the directory is deleted before attempting to enable Omnissa Identity Service again.

Workspace ONE UEM Phone Number Format Issues

When you provision users to Workspace ONE UEM through Omnissa Identity Service, you might come across provisioning errors related to the phone number attribute, such as the following:

  • [400] {"detail":"Please provide a valid phoneNumber of type 'work'.","schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"scimType":"InvalidSyntax","status":"400"}

  • [400] {"detail":"1: The value for 'Value' can not have more than 20 characters. ","schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"status":"400"}

These errors occur if the phone number does not match the Workspace ONE UEM format or length requirements. Workspace ONE UEM requirements for phone numbers include the following:

  • Minimum length: Phone numbers must have at least 10 characters.
  • Maximum length: Phone numbers cannot exceed 20 characters.
  • Character Restrictions: Alphabetic characters are not allowed.

To resolve the issues, you can use expressions in your identity provider to convert the phone number attribute to a format that is accepted by Workspace ONE UEM. See the next section for more information.

Using Expressions to Fix Attribute Mapping Issues

If you encounter provisioning errors related to attributes, you can use an attribute mapping expression in your identity provider to reformat the attribute before it is provisioned to Omnissa Identity Service. Expression builders in identity providers such as Entra ID and Okta allow you to transform attribute values during the provisioning phase.

You can use the expression builders to fix issues such as:

  • Phone number format or length mismatch while provisioning to Workspace ONE UEM
  • Unsupported characters in any attribute value

Example: Configuring an Expression Mapping in Microsoft Entra ID

This example shows you how to configure an expression to convert telephone number attribute (SCIM attribute phoneNumbers[type eq "work"].value) values to a format that Workspace ONE UEM allows.

  1. In your provisioning app in Entra ID, select Manage > Provisioning.
  2. Under Mappings, click Provision Microsoft Entra ID Users.
  3. In the Attribute Mappings table, click the Edit button for the phoneNumbers[type eq "work"].value attribute.
  4. In the Edit Attribute Mapping page:
    1. Change Mapping type to Expression.

    2. In the Expression text box, enter the following expression:

      Replace([telephoneNumber], , "[^0-9\\+\\-\\s\\.#\\*]+", , "", , )

    3. Click OK, then click Save.

Any characters not allowed by the expression will be removed from phone numbers during provisioning.

Other Examples

Similarly, you can truncate phone numbers to 20 characters using the following expression:

IIF([telephoneNumber] > 20, Left([telephoneNumber], 20), [telephoneNumber])

Or, to replace the & character in an attribute such as department, use the following expression:

Replace([department], , "[&]", , "and", , )

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…