Skip to main content

August 19, 2026

Integrate Omnissa Identity Service with Microsoft Entra ID

After enabling Omnissa Identity Service in Omnissa Connect, set up the integration with Microsoft Entra ID.

  1. In the Omnissa Identity Service Getting Started wizard, click Start in step 2, Integrate a SCIM 2.0-Based Identity Provider.""

  2. Click Set Up on the Microsoft Entra ID card.

    ""

  3. Follow the wizard to set up the integration with Microsoft Entra ID.

Step 1: Create a Directory

As the first step in setting up user provisioning and identity federation with Omnissa Identity Service, create a directory in the Omnissa Connect console for users and groups provisioned from your identity provider.

Caution: After you create a directory, you cannot change your identity provider selection. Make sure that you select the appropriate identity provider before proceeding.

Procedure

  1. In step 1, General Information, of the wizard, enter the name that you want to use for the provisioned directory in Omnissa Identity Service.

    The name can have a maximum length of 128 characters. Only the following characters are allowed: letters (a-z or equivalent in other languages), digits (0-9), space, hyphen (-), and underscore (_).

    Important: You cannot change the name of the directory after it is created.

  2. For Domain Name, enter the primary domain name of your source directory, including the extension such as .com or .net.

    Omnissa Identity Service currently supports only one domain. Provisioned users and groups are associated with this domain in Omnissa services.

    The domain name can have a maximum length of 100 characters. Only the following characters are allowed: letters (a-z or equivalent in other languages), digits (0-9), space, hyphen (-), underscore (_), and period (.).

    For example:

    In this example, the directory name is Demo and the domain name is example.com.

  3. Click Save, and confirm your selection.

What to do next

Set up user and group provisioning.

Step 2: Set up User and Group Provisioning

After you create a directory in Omnissa Identity Service, set up user and group provisioning. You start the process in Omnissa Identity Service by generating the admin credentials required for provisioning, then create a provisioning app in Microsoft Entra ID to provision users and groups to Omnissa Identity Service.

Prerequisites

You have an administrator account in Microsoft Entra ID with the privileges required to set up provisioning.

Procedure

  1. In the Omnissa Connect console, after creating a directory, review and copy the values generated in step 2, Configure Microsoft Entra Enterprise Application, of the wizard.

    You require these values to configure the provisioning app in Microsoft Entra ID.

    • Tenant URL: Your Omnissa Identity Service tenant's SCIM 2.0 endpoint. Copy the value.

    • Token Lifespan: The period for which the secret token is valid.

      By default, Omnissa Identity Service generates the token with a lifespan of six months. To change the token lifespan, click the down arrow, select another option, and click Regenerate to regenerate the token with the new value.

      Important: Whenever you update the token lifespan, the previous token becomes invalid and provisioning of users and groups from Microsoft Entra ID fails. You must regenerate a new token and copy and paste the new token to the Microsoft Entra ID app.

    • Secret token: The token required by Microsoft Entra ID to provision users to Omnissa Identity Service. Copy the value by clicking the copy icon.

      Important: Make sure you copy the token before clicking Next. After you click Next, the token will no longer be visible and you will have to generate a new token. If you regenerate the token, the previous token becomes invalid and provisioning fails. Make sure that you copy and paste the new token to the Microsoft Entra ID app.

    For example:

    Step 2 displays a tenant URL, a token lifespan of 6 months, and a secret token.

    When the token is about to expire, a banner notification will appear in Omnissa Identity Service. If you also want to receive email notifications, make sure that you opt in to receive emails. See How to enable email notifications.

  2. Create the provisioning app in Microsoft Entra ID.

    1. Log in to the Microsoft Entra admin center.

    2. Select Enterprise applications in the left navigation pane.

    3. On the Enterprise applications > All applications page, click + New application.

      ""

    4. Click Create your own application.

    5. In the Create your own application pane, enter a name for the app and click Create.

    6. On the Overview page, click Connect your application.

      ""

    7. Under Admin Credentials, enter the token URL and secret token that you copied from the Configure Microsoft Entra Enterprise Application step of the Omnissa Identity Service wizard.

      For example:

      ""

    8. Click Test Connection.

    9. Make sure the following message appears:

      The supplied credentials are authorized to enable provisioning.
      

      If you get an error:

      • Verify that you copied and pasted the tenant URL correctly from the Omnissa Identity Service wizard.
      • Regenerate the secret token in the Omnissa Identity Service wizard and copy and paste it into the app again.

      Then, click Test Connection again.

    10. Click Save to save the application.

What to do next

Return to the Omnissa Connect console to continue with the Omnissa Identity Service wizard.

Step 3: Map SCIM User Attributes

Map the user attributes to synchronize from Microsoft Entra ID to Omnissa services. In the Microsoft Entra admin center, add the SCIM user attributes and map them to Microsoft Entra ID attributes. At a minimum, synchronize the attributes that Omnissa Identity Service and the Omnissa services integrated with it require.

Note: The information in this section applies when you are configuring Omnissa Identity Service for new organizations. If you are migrating existing directories to Omnissa Identity Service, see the attribute list in the Migration wizard in the user interface. Also see Migrating Directories to Omnissa Identity Service.

Attributes required for Omnissa Access and Workspace ONE UEM

The following user attributes are required:

Microsoft Entra ID AttributeSCIM User Attribute (Required)
userPrincipalNameuserName
mailemails[type eq "work"].value
givenNamename.givenName
surnamename.familyName
objectIdexternalId
Switch([IsSoftDeleted], "False", "True", "True", "False")active

Note: The table shows the typical mapping between the required SCIM attributes and Microsoft Entra ID attributes. You can map the SCIM attributes to different Microsoft Entra ID attributes than those listed here. However, if you are integrating Workspace ONE UEM with Omnissa Identity Service for new organizations, you must map externalId to objectId.

For more information about these attributes and how they map to Workspace ONE attributes, see User Attribute Mapping for Omnissa Identity Service.

In addition to the required attributes, you can synchronize optional attributes and custom attributes. For the list of supported optional and custom attributes, see User Attribute Mapping for Omnissa Identity Service.

Attributes required for Horizon Cloud

See Using Omnissa Identity Service with Horizon Cloud.

Procedure

  1. In the Omnissa Connect console, in step 3, Map SCIM User Attributes, of the wizard, review the list of attributes that Omnissa Identity Service supports.

  2. In the Microsoft Entra admin center, navigate to the provisioning app you created for user provisioning to Omnissa Identity Service.

  3. In the left pane, under Manage, select Attribute Mapping and make the following selections:

    • Set Provision Microsoft Entra ID Groups to Yes.
    • Set Provision Microsoft Entra ID Users to Yes.
  4. Click the Provision Microsoft Entra ID Users link.

  5. On the Attribute Mapping page, specify the required attribute mappings between Microsoft Entra ID attributes and SCIM attributes (Omnissa Identity Service attributes).

    Some attributes are included in the Attribute Mappings table by default. Review and update the mappings if needed.

    Important: If you are integrating Workspace ONE UEM with Microsoft Entra ID through Omnissa Identity Service, you must map externalId to objectId.

    To update the mappings:

    1. Click the attribute in the Attribute Mappings table.

    2. Edit the mapping. For Source attribute, select the Microsoft Entra ID attribute and for Target attribute, select the SCIM attribute (Omnissa Identity Service attribute).

      For example:

      objectId is selected as the source attribute, and externalId is selected as the target attribute.

  6. Map optional user attributes supported by Omnissa Identity Service and Omnissa services, if needed.

    • Some of the optional attributes already appear in the Attributes Mapping table. If the attribute appears in the table, click on it to edit the mapping. Otherwise, click Add New Mapping and specify the mapping. For Source attribute, select the Microsoft Entra ID attribute and for Target attribute, select the SCIM attribute.

      For example:

      The Source attribute is department. The Target attribute is urn:ietf:params:scim:schemas:extension:enterprise.0:User.

    • To add attributes that are part of the Omnissa Identity Service schema extension (attributes that have urn:ietf:params:scim:schemas:extension:ws1b: in their path), click Add New Mapping and specify the mapping for the attribute. For Source attribute, select the Microsoft Entra ID attribute and for Target attribute, select the SCIM attribute.

    See the list of optional SCIM attributes supported by Omnissa Identity Service and how they map to Workspace ONE attributes in User Attribute Mapping for Omnissa Identity Service.

  7. Map custom user attributes supported by Omnissa Identity Service and Omnissa services, if needed.

    1. On the Attribute Mapping page, click Add New Mapping.

    2. Specify the mapping. For Source attribute, select the Microsoft Entra ID attribute and for Target attribute, select a Omnissa Identity Service custom attribute. Omnissa Identity Service custom attributes are named urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:customAttribute#. Omnissa Identity Service supports up to five custom attributes.

      For example:

      The Source attribute is employeeHireDate, and the Target attribute is the Omnissa Identity Service customAttribute1.

    See the list of custom SCIM attributes supported by Omnissa Identity Service and how they map to Workspace ONE attributes in User Attribute Mapping for Omnissa Identity Service.

What to do next

Return to the Omnissa Connect console to continue with the Omnissa Identity Service wizard.

Step 4: Select the Authentication Protocol

In the Omnissa Connect console, select the protocol to use for federated authentication. Omnissa Identity Service supports the OpenID Connect and SAML protocols.

Caution: Make your choice carefully. After you select the protocol and configure authentication, you cannot change the type of protocol without deleting the directory.

Requirements for certain username and password-based flows in Workspace ONE UEM

If you plan to use certain Workspace ONE UEM username and password-based flows, you must select OpenID Connect as the authentication protocol in Omnissa Identity Service.

You must also enable the Password Grant setting on the Workspace ONE UEM Directory Services page to grant permission to use the legacy Password grant protocol. See Configure Workspace ONE UEM Settings for Omnissa Identity Service.

For the list of flows to which these requirements apply, see Support for Certain Workspace ONE UEM Username and Password-based Flows.

Requirements for Horizon Cloud

If you plan to use Omnissa Identity Service with Horizon Cloud, you must select OpenID Connect as the authentication protocol.

Procedure

  1. In step 4, Select Authentication Protocol, of the Omnissa Identity Service wizard, select OpenID Connect or SAML.

  2. If you plan to create Basic users in Workspace ONE UEM, expand Setup UEM Basic User Authentication and enable the Basic user authentication for UEM option.

    See Configuring Authentication for Workspace ONE UEM Basic Users for information.

  3. Click Next.

    The next step of the wizard appears with the values required to configure the protocol you selected.

What to do next

Configure Omnissa Identity Service and the identity provider for federated authentication.

Step 5: Configure Authentication

To configure federated authentication with Microsoft Entra ID, you set up an OpenID Connect or SAML app in Microsoft Entra ID using the service provider metadata from Omnissa Identity Service, and configure Omnissa Identity Service with the values from the app.

OpenID Connect

If you selected OpenID Connect as the authentication protocol, follow these steps.

  1. From step 5, Configure OpenID Connect, of the Omnissa Identity Service wizard, copy the Redirect URI value.

    You need this value for the next step, when you create an OpenID Connect application in the Microsoft Entra admin center.

    The Redirect URI value has a copy icon next to it.

  2. In the Microsoft Entra admin center, navigate to Enterprise applications > App registrations.

    ""

  3. Click New Registration.

  4. In the Register an application page, enter a name for the app.

  5. For Redirect URI, select Web, and copy and paste the Redirect URI value that you copied from the Configure OpenID Connect section of the Omnissa Identity Service wizard.

    For example:

    ""

  6. Click Register.

    A Successfully created application name message appears.

  7. Create a client secret for the application.

    1. Click the Client Credentials: Add a certificate or secret link.

    2. Click + New client secret.

    3. In the Add a client secret pane, enter a description and the expiration period for the secret.

    4. Click Add.

      The secret is generated and appears on the Client secrets tab.

    5. Copy the secret value by clicking the copy icon next to it.

      If you leave the page without copying the secret, you will have to generate a new secret.

      You will enter the secret in the Omnissa Identity Service wizard in a later step.

      The Certificates & secrets page displays the secret in the Client secrets tab.

  8. Grant permissions for the application to call the Omnissa Identity Service APIs.

    1. Under Manage, select API permissions.
    2. Click Grant admin consent for organization, and click Yes in the confirmation box.
  9. Copy the client ID.

    1. From the left pane on the application page, select Overview.

    2. Copy the Application (client) ID value.

      You will enter the client ID in the Omnissa Identity Service wizard in a later step.

      The Application (client) ID value is in the Essentials section and has a copy icon next to it.

  10. Copy the OpenID Connect metadata document value.

    1. On the application Overview page, click Endpoints.

    2. From the Endpoints pane, copy the OpenID Connect metadata document value.

      ""

    You will enter the OpenID Connect metadata document value in the Omnissa Identity Service wizard in the next step.

  11. Return to the Omnissa Identity Service wizard in the Omnissa Connect console, and complete the configuration in the Configure OpenID Connect section.

    Application (client) IDPaste the application (client) ID value that you copied from the Microsoft Entra ID OpenID Connect app.
    Client SecretPaste the client secret that you copied from the Microsoft Entra ID OpenID Connect app.
    Configuration URLPaste the OpenID Connect metadata document value that you copied from the Microsoft Entra ID OpenID Connect app.
    OIDC User Identifier AttributeThe email attribute is mapped to the Workspace ONE attribute for user lookups.
    Workspace ONE User Identifier AttributeSpecify the Workspace ONE attribute to map to the OpenID Connect attribute for user lookups.
  12. Click Finish to complete setting up the integration between Omnissa Identity Service and Microsoft Entra ID.

SAML

If you selected SAML as the authentication protocol, follow these steps.

  1. Get the service provider metadata from the Omnissa Connect console.

    From step 5, Configure SAML Single Sign-On, of the Omnissa Identity Service wizard, either copy or download the SAML service provider metadata.

    ""

    Note: When you use the metadata file, you do not need to copy and paste the Entity ID, Single sign-on URL, and Signing Certificate values individually.

  2. Configure the app in Microsoft Entra ID.

    1. In the Microsoft Entra admin center, select Enterprise applications in the left pane.

    2. Search for and select the provisioning app that you created in Step 2: Set up User and Group Provisioning

    3. From the Manage menu, select Single sign-on.

    4. Select SAML as the single sign-on method.

      ""

    5. Click Upload metadata file, select the metadata file that you copied from the Omnissa Connect console, and click Add.

      The Upload metadata file option is at the top of the Set up Single Sign-On with SAML page.

    6. In the Basic SAML Configuration pane, verify the following values:

      • The Identifier (Entity ID) value should match the Entity ID value displayed in step 5 of the Omnissa Identity Service wizard.

        For example: https://yourIdentityServiceFQDN/SAAS/API/1.0/GET/metadata/sp.xml

      • The Reply URL (Assertion Consumer Service URL) value should match the Single sign-on URL value displayed in step 5 of the Omnissa Identity Service wizard.

        For example: https://yourIdentityServiceFQDN/SAAS/auth/saml/response

  3. Get the federation metadata from Microsoft Entra ID.

    1. In the SAML app in Microsoft Entra ID, scroll to the SAML Certificates section.

    2. Click the Federation Metadata XML Download link to download the metadata.

      ""

  4. In the Omnissa Connect console, copy and paste the federation metadata from the file you downloaded from Microsoft Entra ID to the Identity provider metadata text box in step 5 of the Omnissa Identity Service wizard.

    In step 5 of the wizard, the Identity provider metadata text box displays the federation metadata XML.

  5. Configure the rest of the options in the Configure SAML Single Sign-On section.

    • Binding protocol: Select the SAML binding protocol, HTTP POST or HTTP Redirect.
    • Name ID format: Use the Name ID format and Name ID value settings to map users between Microsoft Entra ID and Omnissa Identity Service. For Name ID format, specify the Name ID format used in the SAML response.
    • Name ID value: Select the Omnissa Identity Service user attribute to which to map the Name ID value received in the SAML response.
    • Advanced options > Use SAML single logout: Select this option if you want to log users out of their identity provider session after they log out of Omnissa services.
  6. Click Finish to complete setting up the integration between Omnissa Identity Service and Microsoft Entra ID.

Results

The integration between Omnissa Identity Service and Microsoft Entra ID is complete.

The directory is created in Omnissa Identity Service and will be populated when you push users and groups from the provisioning app in Microsoft Entra ID. Provisioned users and groups will automatically appear in the Omnissa services you choose to integrate with Microsoft Entra ID, such as Omnissa Access and Workspace ONE UEM.

You cannot edit the directory in the Omnissa Access, Workspace ONE UEM, or Horizon Cloud consoles. Directory, users, user groups, user attributes, and identity provider pages are read-only.

What to do next

Next, select the Omnissa services to which you want to provision users and groups.

If Workspace ONE UEM is one of the services you select, configure additional settings in the Workspace ONE UEM console.

Then, push users and groups from the Microsoft Entra ID provisioning app. See Provisioning Users to Omnissa Identity Service.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…