Skip to main content

17 luglio 2026

Enterprise Federation

As an enterprise using Omnissa Connect, you can federate multiple corporate domains. By federating your corporate domains, you can activate single sign-on to Omnissa services for users in your enterprise, you can control identity across all your Omnissa services using your identity provider, and you can enforce security and access policies at an enterprise level across all your Omnissa services.

Benefits of federation

By adopting a federated identity access for Omnissa Connect administrators and organizations in your enterprise, you activate the following features.

  • All users in your enterprise access Omnissa Connect using their corporate account.
  • Owners can control authentication to organizations and services by assigning Organization and Service roles to the groups synced from your corporate directory.
  • Your security team can set up and enforce enterprise-level security and access policies for Omnissa Connect, including multi-factor authentication (MFA).

Supported federation setup methods

As an Owner of an non-federated domain, you initiate your entire enterprise domain setup. After completing the setup, enterprise federation becomes available to all users from your corporate domain and applies to all services across all organizations.

Attention: Your enterprise must own the domains you want to federate for access with Omnissa Connect and you must verify the ownership during the first step of set-up. You cannot federate domains that belong to a service provider.

Federation setupAuthentication methodAdmin and group provisioning
Dynamic (connectorless) authentication setup- SAML 2.0 Identity Provider

- OIDC Identity Provider
- JIT dynamic provisioning

- SCIM dynamic provisioning
Connector-based authentication setupSAML 2.0 Identity Provider or Omnissa Access connector authentication methodsPre-provisioning - syncing admins and groups from your Active Directory

Dynamic (connectorless) authentication setup

When enterprise federation for your enterprise domain is set up to use your third-party identity provider, admins accessing Omnissa Connect from the federated domain are redirected to the log in screen of the identity provider for your enterprise.

Admins authenticate directly with their identity provider through SAML or OIDC (SCIM provisioning only). You can provision admins and groups with JIT or SCIM.

Connector-based authentication setup

In this federation setup, an on-premises instance of Omnissa Access connector syncs admins and groups from your Active Directory to a dedicated instance of an Omnissa Access tenant. Only synced groups and admins can log in to Omnissa Connect with their corporate credentials. Authentication can be set up to use either a SAML 2.0 based IdP or the Omnissa Access connector authentication methods.

After setup completes successfully, enterprise federation becomes available to all admins from your corporate domain and applies to all services across all organizations.

What is the difference between federated and non-federated authentication?

  • Non-federated: If your corporate domain is not federated, your access to Omnissa Connect is authenticated through your Omnissa ID account.
    • See the topics in Managing Identity for details on how to setup identity with authentication policies and OAuth 2.0.
  • Federated: If your corporate domain is federated, your access to Omnissa Connect is authenticated through your corporate account.
    • A hosted Omnissa Access tenant is used as an identity broker to set up federation with your identity provider. The hosted tenant is configured for validation with your corporate identity provider and active directory.
    • You manage admin and group access to Omnissa Connect by configuring the Omnissa Access connector to sync admins and groups from your corporate active directory.
    • Only a subset of required user profile attributes, such as username, firstname, lastname, and email address, is configured to be synced. You can add more attributes later.
    • Note: User passwords are never synced, nor cached.

How do you revoke the federation of corporate domains?

If you decide to undo the federation setup or undo federation for any of the federated corporate domains you initially configured, you must file a support ticket.

What's involved in setting up enterprise federation

Setting up enterprise federation for your corporate domain is a self-service process that involves multiple steps, users, and roles. Here's who and what's involved in federating your corporate domain with Omnissa Connect.

Owner

Owners of non-federated domains can kick off the federation setup from Omnissa Connect. Any Owner can initiate the self-service federation process and assign one or more Enterprise Administrators to complete the setup.

Owners who hold system administrator roles with their enterprise and have sufficient knowledge of the enterprise directory service and identity provider configuration, can act as Enterprise Administrators for the federation setup.

Enterprise Administrator

The Enterprise Administrator is a system administrator who belongs to the central security team for your enterprise and manages the directory services and identity providers.

As the designated person to set up enterprise federation for your corporate domain, the Enterprise Administrator completes the configuration and validation steps of the self-service setup process. Setting up enterprise federation might involve representatives of different security teams. The designated Enterprise Administrator can invite other administrators to help with the setup.

The Enterprise Federation dashboard

When an Owner initiates the self-service federation workflow for their corporate domain by inviting one or more Enterprise Administrators, a special Management Organization is created. This organization provides access to the Enterprise Federation dashboard.

The purpose of the dashboard is to set up enterprise federation for the corporate domain and to modify the initial setup. Everyone involved in the self-service federation process receives an email notification with a link to access the Enterprise Federation dashboard in the Management Organization.

Linking corporate accounts to Omnissa accounts

Many Omnissa services like creating support requests or viewing and managing subscriptions require Omnissa ID-based accounts. However, federated accounts do not provide access to these services, so you must link your federated account to the Omnissa account.

Linking the federated account to the Omnissa account for existing admins of Omnissa Connect happens automatically if the federated email was used to create the Omnissa account. If the Omnissa account uses a different email account from the federated email account, the admins must link their corporate accounts to their Omnissa accounts in order to access the services in their organization.

New admins with federated accounts must create an Omnissa account only if they need to file support tickets.

Switching from non-federated accounts to enterprise federation

You can switch from using non-federated accounts to enterprise federation by following the procedure outlined in How do I move from using non-federated accounts to federated accounts?

Omnissa Access tenant

Setting up federated identity management requires you to configure and manage an Omnissa Access tenant. The tenant is created as part of the self-service federation process. The Omnissa Access tenant acts as an identity broker (service provider) to your identity provider and is not involved in the actual user authentication.

The self-service federation setup workflow

The self-service federation setup involves multiple steps that can be performed at various times by different Enterprise Administrators. The workflow resumes from the place it was left last. Enterprise Administrators involved in the setup must have Omnissa Connect accounts linked to their corporate accounts. All steps in the federation setup are completed through the set up Enterprise Federation workflow accessed in the special Management Organization. The system automatically creates the Management Organization when an Enterprise Federation process is started.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…