Configuring a generic Identity Provider (IdP) in the Enterprise Federation workflow allows you to establish single sign-on (SSO) and automated user management using the SAML protocol and Generic SCIM 2.0-compliant provisioning.
What is the role of Omnissa Identity Service?
Enterprise federation uses Omnissa Identity Service for SCIM based user provisioning and management. Omnissa Identity Service integrates Omnissa products and services with third-party, cloud-based identity providers for user provisioning and identity federation. Omnissa Identity Service offers centralized user management across the Omnissa platform.
Important: Configure a separate instance of the The Omnissa Identity Service app for enterprise federation using the Generic SCIM 2.0 Identity Provider process. You cannot use a previously configured Omnissa Identity Service app.
Requirements
- You must complete the Verify Domains step before you can access the Configure identity provider area of the Set up Enterprise Federation widget in Omnissa Connect.
- You must have admin permissions to integrate apps in the IdP.
- Your IdP must support SAML 2.0 for authentication and SCIM 2.0 for provisioning.
Procedure
To configure Okta in the SAML protocol for generic SCIM provisioning, work in both the Omnissa Connect console and in the Okta admin console. It is best to use two browser instances to facilitate copying and pasting values between the consoles.
- Initiate Configuration in Omnissa Connect.
- Open a browser instance and go to your Omnissa Connect console.
- Go to Set up Enterprise Federation > Configure identity provider and select Start.
- On the Select your identity provider tab, select these settings and then select Next.
- Identity Provider: Other
- Provisioning Type: SCIM-based
- Authentication Protocol Type: SAML

- Configure Provisioning in the IdP.
- Consider using the Client ID and secret because tokens expire and have to be updated manually.
- As a security best practice, rotate the client ID and client secret every six months.
- In Omnissa Connect, navigate to the Set up identity provider for SCIM provisioning tab.
- Select the Credential Type, click Generate, and depending on the credentials, copy the generated urls and secrets.
- Tenant URL and token
- Review and copy the generated values.
- Tenant URL: Your Omnissa Connect tenant’s SCIM 2.0 endpoint. Copy the value.
- Token Lifespan: The period for which the secret token is valid. By default, Omnissa Connect generates the token with a default lifespan of 6 months. To change the token lifespan, slect the drop-down, select another option, and select Regenerate to regenerate the token with the new value.
- You must regenerate a new toke: Whenever you update the token lifespan, the previous token becomes invalid and provisioning of users and groups from the IdP fails. You must regenerate a new token and copy and paste the new token to the IdP.
- Secret Token: The token required by the IdP to provision users to Omnissa Connect. Copy the value.
- Token no longer visible: Make sure you copy the token before clicking Next. After you click Next, the token is no longer visible and you have to generate a new token.
- Be aware that whenever you regenerate the token, the previous token becomes invalid and provisioning fails.
- Make sure that you copy and paste the new token to the identity provider.
- Client ID and secret
- Copy the Client ID and Client Secret values.
- Secret no longer visible: Make sure that you copy the secret before clicking Next. After you click Next, the secret is no longer visible and you have to generate a new secret.
- Be aware that whenever you regenerate the secret, the previous secret becomes invalid and provisioning fails.
- Make sure that you copy and paste the new secret to the IdP.
- Tenant URL and token
- In your IdP console, create a new Generic SCIM 2.0 application (sometimes referred to as a "Custom SCIM" or "Non-Gallery" application).
- Provide the Tenant URL and Secret Token or the Token URL and Client Secret in the IdP's API integration settings.
- Activate the following provisioning actions within the IdP.
- Create Users
- Update User Attributes
- Deactivate Users
- Perform a connection test to ensure the IdP can reach the Omnissa SCIM endpoint.
- Start the metadata URL exchange.
- In Omnissa Connect, on the Set up SAML within your identity provider tab, copy the Metadata URL.

- Paste it into your IdP.
- In Omnissa Connect, on the Set up SAML within your identity provider tab, copy the Metadata URL.
- Set up user attributes.
- On the User attributes tab in Omnissa Connect, review the required mappings.
- If using the Omnissa Identity Service application template in your IdP, these attributes are typically pre-configured.
- Select Next.

- On the User attributes tab in Omnissa Connect, review the required mappings.
- Complete SAML setup.
- Locate the Metadata URL in your IdP application settings and copy it.
- In Omnissa Connect, go to the Configure your identity provider tab.
- Enter an IdP Display Name (for example, Corporate IdP).
- Select the URL radio button for the Metadata option and paste the URL from your IdP.

- Set user identification preference.
- On the Set user identification preference tab in Omnissa Connect, choose the attribute users will provide to identify themselves.
- Ensure the chosen value matches the format of your verified domain (for example, user@example.com).
- Select Configure to complete the process.
- On the Set user identification preference tab in Omnissa Connect, choose the attribute users will provide to identify themselves.
Next steps
After the technical configuration is complete, use the Validate and Activate workflow in Omnissa Connect to test the authentication loop. After successful validation, assign users or groups to the Omnissa Identity Service application in your IdP to trigger the initial synchronization.
Questa pagina è stata utile?