To integrate an Access tenant with a Horizon Cloud tenant that has Universal Broker enabled, you must log in to the Access console and configure the mandatory user attributes. Configuring these user attributes is a multi-step process using multiple areas within the Access console's Identity & Access Management area.
Note: This documentation page assumes that you are reading it because you are following the steps described in Horizon Cloud with Universal Broker - Integrate the Tenant with Omnissa Access and Intelligent Hub Services.. This page's contents are not applicable to any other situation or context.
At a high-level, in the Access console, you:
- First use the Setup area of the Identity & Access Management area to add the additional Access attributes that are mandatory for this integration.
- Then you use the Manage area of that Identity & Access Management area to appropriately map those required Access attributes to your Active Directory attributes.
The userPrincipalName, objectGuid, sid, and netBios Access attributes are mandatory and must be mapped to the appropriate Active Directory attributes as described in the following steps.
Additionally, sAMAccountName must be set as the directory search attribute for the Access directory. You specify the directory search attribute at the time when you create the directory in the Access console.
Prerequisites
Before you can configure user attributes in the Access console in support of the integration steps of Universal Broker and Access, you must have installed a compatible version of Access connector and set up directory integration with Active Directory as specifically described in those integration steps.
As of this writing, that page's Step 5 is the relevant point where the connector installation and directory integration are referenced.
Procedure
-
Log in to the console for your Access tenant as administrator.
-
Using the Setup part of the Access console's Identity & Access Management area, navigate to the screen where user attributes are configured for your Access tenant.
Look for the label User Attributes in the Setup area.
-
In that console's screen for configuring the Access user attributes, navigate past the list of default attributes to locate the section for adding other attributes to sync to the directory, and use the console's buttons to add the following attributes.
Important: These attributes are 100% CASE-SENSITIVE!
So that objectGuid must be entered with lowercase uid and NOT capital
uid.netBios must be entered with lowercase ios and NOT capital
ios.The 100% CASE-SENSITIVE NATURE is a technical fact of how it was implemented.
Failure to adhere to the 100% CASE-SENSITIVE NATURE of these attributes in Workspace ONE admin UI will break the sync between Universal Broker to Access and end users logging in will not see desktops and apps that you think they should see.
- objectGuid
- sid
- netBios Please note that even though userPrincipalName is also mandatory for this integration, because it already appears in the list of default attributes, you do not have to specially add it here.
-
Save your changes in that screen.
-
Using the Manage area of the Access console's Identity & Access Management area, map the Access attributes to your Active Directory attributes.
-
Using the Manage part of the Access console's Identity & Access Management area, navigate to the screen where directories are configured and click the directory that contains the users and groups that have Horizon Cloud entitlements.
-
In the screen for that directory, open the Sync Settings screen, then navigate to its Mapped Attributes page.
-
Map the Access user attributes to the Active Directory attributes as indicated.
Important: Pay attention to how the Access attributes are mapped to the Active Directory ones that have similar — but slightly different — names.
Remember from the above steps that the Access attributes are 100% CASE-SENSITIVE!
So that objectGuid in Access has lowercase uid and NOT capital
uid.However, bear in mind that objectGuid in Access with lowercase uid gets mapped to the Active Directory attribute that has the uppercase UID in it.
Access Attribute Active Directory Attribute userPrincipalName userPrincipalName objectGuid objectGUID sid objectSid netBios msDS-PrincipalName
-
-
Save the settings.
-
Verify that you selected all the users and groups that sync to your Horizon Cloud environment.
In the Access console, you can view and edit the lists of users and groups by navigating from the directory's Sync Settings screen into the Users tab and Groups tab.
-
In the Access console, return to that directory's page and click Sync to sync users and groups to Access, now using all of the correct user attributes.
What to do next
Return to the steps in Horizon Cloud with Universal Broker - Integrate the Tenant with Omnissa Access and Intelligent Hub Services and complete the remaining integration steps after the Configure User Access step.
¿Le resultó útil esta página?