Skip to main content

17 luglio 2026

Connector-Based Federation Setup

Setting up enterprise federation for the connector-based method in Omnissa Connect involves an on-premises instance of Omnissa Access connector that syncs users and groups from your Active Directory to a dedicated instance of an Omnissa Access tenant. View the high-level overview of the steps in the federation setup workflow.

Step 1: Verify domains

In this step, you verify the ownership of the domains that you want to federate. The verification process involves adding DNS TXT records for your domains. Before you begin, verify that you can modify the DNS records for your corporate domains.

The domains you add in this step are the top-level public domains that your enterprise employees use to access Omnissa Connect. These domains are not internal Active Directory domains. You can add users and groups from internal Active Directory domains when you sync users and groups. The internal Active Directory domains that you add for synchronization are not externally visible for access from Omnissa Connect.

Note: The verification does not happen automatically. It might take up to 72 hours after submitting the TXT records for the changes to take effect.

Step 2: Install Omnissa Access Connector

In this step, you download the Omnissa Access connector executable file and install it on a Windows machine with access to your enterprise directory.

Note: As your enterprise does not use a SAML 2.0 based identity provider, the authentication methods supported by the Omnissa Access connector will be used to authenticate users. This is configured when you configure the identity provider.

The Omnissa Access connector is an on-premises component of Omnissa Access that integrates with your on-premises infrastructure such as Active Directory, RADIUS, and RSA SecurID. In the federation setup, the connector is used to continuously sync the users and groups configured by the Enterprise Administrator with a hosted Omnissa Access tenant created for the corporate entity for the purposes of enterprise federation.

Step 3: Sync groups and users

In this step, you bind to your enterprise Active Directory. If necessary, upload security certificates for SSL/TLS communication from the Omnissa Access connector to the Active Directory. You then search your enterprise directory for users and groups to sync them with the Omnissa Access tenant. Syncing additional groups and users can continue after the federation setup is completed.

Step 4: Configure identity provider

Important: You cannot change the identity provider that you configure in this step, after the federation setup is activated. If you must change your identity provider later, file a support ticket.

In this step, you configure the Omnissa Access connector to act as an identity provider and activate direct user authentication against your Active Directory. You activate Kerberos authentication method for secure interactions between users' browsers and the Omnissa Access service.

For detailed information about Kerberos authentication, see Configuring Kerberos Authentication in Omnissa Access.

Step 5: Validate and activate

In this final step of the federation setup, you must perform a list of actions.

Important:After enterprise federation is activated, users with federated domains can only access Omnissa Connect using their corporate accounts. They can no longer use their other accounts to log in to Omnissa Connect.

  1. Validate that the users from your enterprise can log in to Omnissa Connect by using your corporate IdP.
  2. Notify the enterprise users of the domains that you specified that they have to log in to Omnissa Connect by using their corporate credentials.
  3. Acknowledge the changes and activate the federation for your enterprise.

After you complete the federation setup, the self-service workflow is no longer available for changes. Enterprise Administrators can modify the initial setup from the Enterprise Federation dashboard.

In the last step of the workflow, you link your federated account to your Omnissa account. This step is necessary to complete for the following roles:

  • Enterprise Administrator and Owners who participated in the self-service federation setup.
  • Owners and Members who need access to billing information.
  • Owners and Members who want to be able to file support requests.

For details about linking your federated account with your Omnissa account, see Federated Accounts, Omnissa Accounts, and How to Link Them .

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…