Beginning Horizon 8 2512, Horizon supports single sign-on (SSO) into manually provisioned (manual pool) Azure virtual machines that are joined only to Entra ID, when accessed through Omnissa Workspace ONE Access.
Active Directory-sourced end users authenticate through Omnissa Access and can launch their manually provisioned (manual pool) Horizon desktops without re-entering credentials inside the virtual machine. This capability streamlines access for environments built on Entra ID and provides on-prem organizations with a smoother path to delivering Azure-based Horizon resources.
SSO is only supported when users authenticate through Workspace ONE Access.
Setup and Configuration Requirements
SSO to Entra ID-only Azure VMs is supported for the following configurations:
- Horizon 8 Server version 2512 or later
- Azure-hosted agent machines that are Entra ID–joined, deployed in manual desktop pools, with agent version 2512 or later
- End users sourced from Active Directory and synchronized to Entra ID using Microsoft Entra Connect Sync
- End users authenticating through Workspace ONE Access (hosted)
- Workspace ONE Access (hosted) configured to use Microsoft Entra ID as the identity provider, using Password Hash Sync or delegation to AD FS
- Blast Protocol
- Horizon Windows Client version 2512 or later
The following configurations are not supported:
- Direct launch of Windows Client without Workspace ONE Access
- Other types of clients (Only Windows Client is supported.)
- PCoIP Protocol
Workspace ONE Access Hosted
Documentation for configuring Omnissa Identity Service with Entra ID can be found at Enable Omnissa Identity Service.
Omnissa Identity Service Configured with Microsoft Entra ID
The following steps describe how to configure Omnissa Identity Service to use Microsoft Entra ID for user authentication.
- Log in to the Workspace ONE Access Admin Console.
- Navigate to Identity & Access Management > Identity Providers.
- Select Add Identity Provider and select SAML 2.0 (or Microsoft Entra ID for the guided setup).
- Configure the identity provider:
- Set Name and Description.
- Upload or reference the Microsoft Entra ID federation metadata.
- Enter the Single Sign-On URL and Single Logout URL as specified by Microsoft Entra ID.
- Set Name and Description.
- Configure only the required authentication attributes (for example,
userPrincipalNameandemail). - Save the identity provider.
- Assign the identity provider to the appropriate Access Policies.
- Sign in to the Workspace ONE Access user portal with an Entra ID account to verify authentication.
On-premises SCIM attribute mappings
The following steps describe how to configure SCIM provisioning in Microsoft Entra ID to synchronize users, groups, and additional attributes with Omnissa Identity Service.
-
Navigate to your enterprise application in the Microsoft Entra ID.
-
Go to Manage > Provisioning.
-
Go to Manage > Attribute Mapping.
-
Open either:
- Provision Microsoft Entra ID Users or
- Provision Microsoft Entra ID Groups
-
Enable the schema editor by modifying the URL:
- Add the query parameter:
Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true
Ensure the query parameter appears before the URL fragment
#.-
Old URL format:
https://aad.portal.azure.com/#view/Microsoft_AAD_Connect_Provisioning/… -
New URL format:
https://aad.portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true#view/Microsoft_AAD_Connect_Provisioning/…
- Add the query parameter:
-
Navigate to the updated URL.
-
Go to Show advanced options > Supported attributes > Edit attribute list for Microsoft Entra ID.
Under Microsoft Entra ID Group Attributes, add new rows with Name set to:onPremisesDistinguishedNameonPremisesUserPrincipalName
Click Save > Yes.

-
Go to:
Show advanced options > Supported attributes > Edit attribute list for<your registered app name>
Add new rows for:urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:onPremisesUserPrincipalNameurn:ietf:params:scim:schemas:extension:ws1b:2.0:User:distinguishedNameurn:ietf:params:scim:schemas:extension:ws1b:2.0:User:userPrincipalNameurn:ietf:params:scim:schemas:extension:ws1b:2.0:User:onPremisesSecurityIdentifier
Click Save > Yes.

Attribute Mapping
Map the newly added attributes as follows:
| SCIM Attribute | Entra Attribute |
|---|---|
externalId |
objectId (general WS1 requirement) |
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:onPremisesUserPrincipalName |
onPremisesUserPrincipalName |
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:distinguishedName |
onPremisesDistinguishedName |
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:userPrincipalName |
userPrincipalName |
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:onPremisesSecurityIdentifier |
onPremisesSecurityIdentifier |

Horizon 8 Server
Connection server domain requirements:
- Each Horizon Connection Server must be joined to a domain that can search the user domain(s).
- Domain trusts must be in place if users reside in a different domain.
- Verify that user lookup succeeds for all domains authenticating through Workspace ONE Access.
SAML Authenticator Configured in Workspace ONE Mode
The following steps describe how to configure Horizon to delegate authentication to Workspace ONE Access using SAML.
-
Log in to Horizon Console.
-
Navigate to Settings > Authentication > SAML 2.0.
-
Add or edit a SAML authenticator.
-
Set Authenticator Mode to Workspace ONE.
-
Specify the Workspace ONE Access URL.
-
Save the configuration.
-
Navigate to Settings > Servers > Connection Servers.
-
Edit each Connection Server and enable SAML Authentication.
-
Save the changes.
Horizon Windows Agent
- Agent OS :Windows 11 24H2 with Oct 2025 Security Cumulative Update or later
- Windows Server 2025 with Jan 2026 Security Cumulative Update
- Install Agent on Azure VMs in Manual Provisioning mode. See Creating and Managing Manual Desktop Pools (Manual Provisioning Mode).
Horizon Windows Client
No special configuration is needed.
AD FS
See the Microsoft documentation for detailed instructions on setting up AD FS.
Entra ID Connect Sync
See Microsoft documentation for how to set up Entra ID Connect Sync.
Entra ID tenant enablement of Horizon Enterprise resource and client applications
You must add the Horizon Enterprise resource and client applications to your Entra ID tenant and grant admin consent. This step is a prerequisite for configuring Remote Desktop Security through the Azure portal.
This enablement process:
- Creates Service Principals for the Horizon Enterprise and Horizon Enterprise Client applications in your Entra ID tenant.
- Grants admin consent for the Horizon Enterprise application.
- Grants admin consent for the Horizon Enterprise Client application.
Application Identifers
The Horizon Enterprise application identifiers are defined as follows:
- Horizon Enterprise:
7ca77652-da87-4868-b1f2-1e858d1653f1 - Horizon Windows Client:
507b8294-17f2-4e93-b950-32883747b3c5
To grant admin consent for the SSO client and resource apps, run the Horizon-EntraID-Consent.ps1 PowerShell script located in the extras\scripts sub-directory of the Connection Server installation.
The following steps describe how to set Remote Connection Configuration for the Horizon Enterprise application in the Microsoft Entra admin center.
-
Open the Microsoft Entra admin center.
-
Navigate to Devices.
-
Select the Horizon Enterprise application.
-
Activate the toggle Enable Microsoft Entra ID authentication protocol to authenticate users to remote devices.
-
Under the Target device groups to enable SSO option, Select a dynamic device group containing all devices to enable SSO.
-
Under Client app(s) to connect to target server resource option, select the Horizon Enterprise Client application.
Client App Approval
This configuration explicitly approves the Windows Client App to communicate with the Resource App for SSO, ensuring secure and trusted communication
Trusted Device Group Enablement
This configuration suppresses repeated authentication consent prompts for known/trusted devices, improving user experience and reducing friction.

Questa pagina è stata utile?