Skip to main content

September 4, 2026

Configure Horizon Settings on Unified Access Gateway for SAML Integration

You must select the relevant SAML authentication method and choose the IDP (Identity Provider) supported by your organization in the Horizon settings page on the UAG (Unified Access Gateway). The authentication method determines the login flow for the user when using the Horizon Client with UAG.

For information about authentication methods, see Authentication Methods for Unified Access Gateway and Third-Party Identity Provider Integration.

Prerequisites

Procedure

  1. In the Configure Manually section of the UAG Admin UI, click Select.

  2. In the General Settings section, for Edge Service Settings, click Show.

  3. Click the Horizon Settings gearbox icon.

  4. On the Horizon Settings page, click More to configure the following settings:

    Option INI Parameter Description
    Auth MethodsauthMethods


    Example:
    authMethods=SAML

    Select SAML, SAML and Passthrough, SAML and Unauthenticated, or Device X.509 Certificate and SAML.

    Notes:
    • If TrueSSO is enabled on Horizon Connection Server, only SAML authentication method must be used.
    • If you choose SAML and Unauthenticated, ensure that you configure the Login Deceleration Level in the Horizon Connection Server to Low. This configuration is necessary to avoid long delays in login time for an endpoint while accessing the remote desktop or application. For more information about how to configure Login Deceleration Level, see the Horizon Administration guide at Omnissa Product Documentation.
    • To enable Device X.509 Certificate and SAML authentication, configure the X.509 Certificate auth method and External Identity Provider's SAML metadata.
    • The Identity Provider and Binding Protocol settings are visible only when one of the SAML Auth Methods listed is selected.
    Identity ProvideridpEntityIDSelect the Identity Provider that must be integrated with Unified Access Gateway.

    Notes:
    • An identity provider is available for selection only if the identity provider's metadata is uploaded to Unified Access Gateway.
    • SAML authentication request generated by Unified Access Gateway is assigned using the Internet-facing TLS certificate. If multiple certificates are configured, the certificate marked as default is used.
    Binding Protocol idpBindingType=POST
    or
    idpBindingType=ARTIFACT
    Select a binding protocol for SAML to exchange authentication messages between Unified Access Gateway and Identity Provider.

    Notes:
    • The default protocol is set to HTTP-POST.
    • HTTP-Artifact binding provides enhanced security. This option is available only if the selected Identity Provider supports HTTP Artifact Binding.

    To configure the other Horizon settings, see Configure Horizon Settings.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…