Skip to main content

17 luglio 2026

Configure the Identity Provider Okta

Configuring the identity provider (IdP) in the Enterprise Federation workflow in Omnissa Connect includes working in both the provider and Omnissa Connect consoles, and this procedure outlines using Okta in the SAML (Security Assertion Markup Language) protocol with JIT (Just-in-Time) provisioning.

The Omnissa Access tenant is provisioned automatically to help with this step. Omnissa Access acts a service provider and self-service federation provides a presentation layer to help simplify connecting your identity provider with your service provider.

General workflow

In general, whether you are configuring Microsoft Entra ID, Okta, or another identity provider, take the listed steps.

  1. Establish trust between your identity provider and the service provider.
  2. Configure how admins and groups are identified for authentication.
  3. Configure single sign-on (SSO).

Okta documentation

  • This topic outlines using Okta as the identity provider, but if you want the latest Okta documentation, see the Okta documentation site.
  • See the topic Okta Expression Language overview for information on expressions used in Okta attribute mappings.

Requirements

You must complete the Verify Domains step before you can access the Configure identity provider area of the Set up Enterprise Federation widget in Omnissa Connect.

Configuring SAML SSO with Okta

Work in both the Omnissa Connect console and in Okta. It is best to use two browser instances to facilitate copying and pasting values between the consoles.

  1. Open a browser instance and go to your Omnissa Connect console.
    1. Go to Set up Enterprise Federation > Configure identity provider and select Start.
    2. In Omnissa Connect, On the Select your identity provider tab, select these settings and then select Next.
      • Identity Provider: Okta
      • Provisioning Type: JIT-based
      • Authentication Protocol Type: SAML
        Begin the process of configuring your IdP by selecting the provider, the provisioning type, and SAML protocol.
  2. In another browser instance, log in to your Okta admin console with admin permissions and select the right Okta organization.
    1. In Okta, go to the Applications menu and select Create App Integration.
      An image of the Applications section in the Okta console and where to select to create the app integration.
    2. In the Create a new app integration widget, select SAML 2.0 and select Next.
      A screenshot of the Okta app integration widget with SAML 2.0 selected for the sign-in method.
    3. In the General Settings area of the Create SAML Integration widget, enter an App name and other details as needed and select Next.
      An image of entering an app name in the General Settings area.
  3. In Omnissa Connect, in the Set up SAML within your identity provider step, copy and note the listed settings.
    • Copy the Single sign-on URL and the Audience URI (SP Entity ID) values.
    • Note the entries for the Name ID format and the Application username. When you set the Attributes Statements in Okta, the values for Name ID format and Application username must match the values in Connect.
      A screenshot of Omnissa Connect where you get the URLs.
  4. Go to your Okta instance and paste the copied Omnissa Connect values in to the SAML Settings > General area, leaving other fields in Okta as they are.
    An image of Okta where you paste the copied URLs.
  5. In Okta, in the Attribute Statements section, add the required user attributes that match those in Omnissa Connect.
    • Ensure that the Name format are unspecified (except for the userName entry) to match the attribute values in Connect.
    • Update userName to the Name format > Okta Username to match the attribute value in Connect.
    • Select to Add Group attribute Statements if you plan to provision group memberships.
    • (Optional) Preview the XML that is used in SAML assertions to ensure everything looks right, then select Next to continue.
      An image of the Preview the SAML Assertion menu in Okta.
  6. Go to your Omnissa Connect instance, in the Configure your identity provider step, and enter a name for the provider to display in Omnissa Connect.
    1. Select URL as the method of sharing for the Metadata menu option.
      An image of the Okta IdP in Omnissa Connect.
  7. In Okta, go to the Assignments tab of your Omnissa app and assign users and groups to the application so that they can SSO in to Omnissa Connect.
    An image of Okta Assignments tab where you can assign users and groups.
  8. In Okta, go to your application's Sign On tab and copy the Metadata URL.
  9. Go back to Omnissa Connect, still on the Configure your identity provider step, and paste the copied Okta metadata URL in to the Metadata URL text field.
    A screenshot of where you paste the metadata URL in Omnissa Connect.
    • Select the Name ID Format. The Name ID Format is the value in the SAML response to identify the authenticated user.
    • Select the Name ID Value.
  10. In Omnissa Connect, in the Set user identification preference step, select how users of your enterprise are going to identify themselves when accessing Omnissa Connect from the Omnissa Connect discovery page.
    • User identification is different from how the user authenticates against your enterprise identity provider.
    • Follow the examples shown on the screen to choose the correct one.
    • Consider that for all the options, the chosen value must end with @<DomainName.com> where domainName is the one you registered during the verification step.
  11. In Omnissa Connect, select Configure to complete the self-service federation process.

What to do next

In this step you configured Okta as the IdP, selected the SAML user and group claims, and selected the value to be used for user identification. Move on to validating and activating your setup.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…