Skip to main content

27 agosto 2026

Integrate your Identity Provider

After you complete the directory prerequisites, the next step in the migration process is to integrate your third-party cloud identity provider with Omnissa Identity Service. Omnissa Identity Service supports integrations with Microsoft Entra ID, Okta, and any generic SCIM 2.0–compliant identity provider.

In this step, you perform the following actions:

  • Set up the connection between your cloud identity provider and Omnissa Identity Service for user provisioning and authentication. This involves configuration tasks in both Omnissa Identity Service and the identity provider console.
  • Assign users and groups to the provisioning app in your cloud identity provider.
  • Verify the provisioned users and groups in Omnissa Identity Service.

There is no disruption to your existing Workspace ONE UEM or Omnissa Access users during this process.

Set up the connection between your Identity Provider and Omnissa Identity Service

Prerequisites

Procedure

  1. In the Omnissa Connect console, select Identity Management > End User Management from the left pane.

  2. Click Launch End User Management.

    Omnissa Identity Service opens in a new tab in the browser.

  3. In the Omnissa Identity Service tab, in the Configuration Steps pane on the right, click Start in the Integrate Identity Provider step.

    ""

  4. Click Integrate on your identity provider tile.

  5. Follow the wizard to configure the integration, using the following documentation:

Support for multiple domains

In a migration scenario, when you create the directory in Omnissa Identity Service, you can specify multiple domains. This allows you to provision users from multiple domains to your Omnissa Identity Service directory.

Important: If you specify multiple domains, you must add the mapping for the domain attribute for both users and groups in the SCIM provisioning app in your cloud identity provider.

"Multiple Domains"

Important considerations for user and group attribute mapping

  • In the provisioning app in your cloud identity provider, map the required user and group attributes listed in Required Attributes for Migration to Omnissa Identity Service to SCIM attributes (Omnissa Identity Service attributes). Try to map the attributes as closely as possible to the mappings you currently have in your Workspace ONE UEM environment.

  • If you are migrating multiple domains, you must add the mapping for the domain attribute for both users and groups in the provisioning app.

  • ObjectId type setting in the Omnissa Identity Service integration wizard

    When you integrate your identity provider with Omnissa Identity Service, Step 3: Map SCIM Attributes of the wizard includes an ObjectId type setting with the options Binary and String. Select the data format of the attribute mapped to externalId in your identity provider. If the attribute is objectGUID and your Workspace ONE UEM LDAP setting for Object Identifier Data Type is configured as Binary, ensure this field is also set to Binary to maintain consistency and enable accurate identity resolution.

    Important: The ObjectId type setting is only used during migration. After migration, you can no longer access the setting in the console. We also recommend that you remove the urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:altExternalId mapping in the identity provider after migration.

    "ObjectId type setting"

Important considerations for SAML and OpenID Connect configuration in Omnissa Identity Service

  • To set up SAML or OpenID Connect when sAMAccountName is mapped to username in Workspace ONE UEM and Omnissa Access, in the Identity Service integration wizard select userPrincipalName or Email in Name ID Value (for SAML) and in OIDC User Identifier Attribute (for OpenID Connect). For example:

    ""

  • If you plan to use Password Grant Flows, use OpenID Connect as the authentication protocol and select email or UPN as the Login Hint User Attribute (to match the identity provider Login Identifier) in Step 5: Configure OpenID Connect of the Identity Service wizard.

Selecting the Workspace ONE UEM Basic user authentication option

If your Workspace ONE UEM deployment includes Basic user accounts, you must enable the Basic user authentication for UEM option in Step 4: Select Authentication Protocol of the integration wizard so that Basic users can continue to log in after the migration to Omnissa Identity Service.

See Configuring Authentication for Workspace ONE UEM Basic Users for more information.

Important: As the Basic user authentication for UEM setting affects the login experience for all users (federated and Basic), make sure that you communicate the change to your end users and provide guidance on which option to select.

"Basic User Authentication"

Assign Workspace ONE UEM Users and Groups to the provisioning app

Assign Workspace ONE UEM users and groups to the provisioning app in your cloud identity provider. If you are also migrating an Omnissa Access directory, make sure that you assign the Omnissa Access users and groups to the app too.

See Provisioning Users to Omnissa Identity Service.

Important: Make sure that you have prepared nested groups for migration before you perform this step. See the nested groups prerequisite.

Verify Provisioned Users and Groups in Omnissa Identity Service

After provisioning users and groups and waiting for some time for the provisioning process to complete, verify that all users and groups appear in Omnissa Identity Service.

Perform this verification step after provisioning from the identity provider is 100% complete. For example (Entra ID):

""

  1. In Omnissa Connect, select Identity Management > End User Management from the left pane, then click Launch End User Management.

  2. In the End User Management page, check the number of users and groups listed on the directory tile. When provisioning completes, the numbers should match the number of users and groups assigned to the provisioning app in the cloud identity provider.

  3. Click View to verify that the users and groups appear in the Omnissa Identity Service directory.

  4. After verifying that all the users and groups are provisioned, click Confirm in the Configuration Steps pane to proceed with the migration.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…