Refer to this section for some of the common issues that you might encounter during migration.
The directory report does not let you proceed to the migration stage
The directory comparison report displays a Not ready to migrate status and does not let you proceed if it identified critical differences between the new Identity Service directory and your existing Workspace ONE UEM or Omnissa Access directory. You must resolve these differences before you can proceed with migration.
Requirements for migration include:
- The Identity Service directory must include all groups that exist in the Workspace ONE UEM and Omnissa Access directories. You cannot migrate if even one group is missing.
- The number of differences in critical attributes must be below the threshold. Critical attributes are attributes that must match between Identity Service and Workspace ONE UEM or Omnissa Access.
- The number of missing users with devices must be below the threshold. Missing users are users that exist in the Workspace ONE UEM or Omnissa Access directory but are missing in the Identity Service directory.
- The number of missing memberships must be under the threshold. Missing memberships are memberships that exist in the Workspace ONE UEM or Omnissa Access directory but are missing in the Identity Service directory.
Some users do not appear in the directory comparison report
Users that were provisioned after you started running the report do not appear in the report. Run the report again after the users are successfully provisioned.
Workspace ONE UEM Report failure when AirWatch Provisioning app group is not found in Workspace ONE UEM
If a group that is assigned to the AirWatch Provisioning app in Omnissa Access is not found in Workspace ONE UEM (groups are matched using the displayName attribute), the Workspace ONE UEM report fails to generate.
The Omnissa Access group name is listed in the error message. Ensure that groups are consistent between Omnissa Access and Workspace ONE UEM, then try running the report again.
You cannot switch authentication to Identity Service during the Migration phase if multiple AirWatch SAML apps exist in Omnissa Access
When you integrate Omnissa Access with Workspace ONE UEM, an AirWatch SAML app is created in Omnissa Access. Only one instance of this app is allowed. Delete any extra apps from the Resources > Web Apps page in the Omnissa Access console.
Investigating login failures after authentication is switched to Identity Service
If users cannot log in after you switch authentication to Identity Service during the Migration phase, review audit events in the Omnissa Access console.
- In the Omnissa Connect home page, click the Access tile under Launch Services to launch the Omnissa Access console.
- See Generate an Audit Event Report in Omnissa Access for information about viewing audit events.
New users cannot log in after authentication is switched to Identity Service
New users might not be able to log in after you switch authentication to Identity Service during the Migration phase.
New users added during migration are synced directly from Active Directory to Workspace ONE UEM (and Omnissa Access, if applicable) and also provisioned from your cloud identity provider to Omnissa Identity Service. It takes some time for the users to be reconciled between the systems. After a new user is synced successfully to Workspace ONE UEM or Omnissa Access, it can take up to an hour before the user can log in.
Your identity provider updates are not reflected in Identity Service
If the changes you make in your cloud identity provider, such as updates to user and group attributes or assignments, are not reflected in Identity Service, check the provisioning status in the identity provider.
- Review the provisioning logs in the identity provider. In Entra ID, the logs are available on the provisioning app's Provisioning page.
- Test the connection between the identity provider and Identity Service.
Provisioning from your identity provider fails after migration with an "Invalid format of altExternalId" error
After migration, provisioning from your third party identity provider to Identity Service fails with the following error:
Invalid format of altExternalId. Make sure the format is aligned with the Microsoft standard for ObjectGUID.
Remove the urn:ietf:params:scim:schemas:extension:ws1b:2.0:User:altExternalId mapping from the identity provider.
Deleting missing users
Missing users are users that exist in the Workspace ONE UEM or Omnissa Access directory but do not exist in the Identity Service directory. These users remain untouched during the migration process. We recommend that you delete missing users in Workspace ONE UEM and Omnissa Access during or after migration to avoid potential provisioning errors.
Contact Support to request the relevant API documentation for deleting these users.
SAML IDP related errors during Omnissa Access directory migration
Differences in the Name ID Format settings between the third-party SAML IDP configuration in Omnissa Access and Omnissa Identity Service can cause integration issues during directory migration. Other settings in the SAML IDP can also cause errors.
Omnissa Identity Service evaluates the Omnissa Access settings before you start migration. Errors appear as banner messages on the Step 1: Complete Directory Service Prerequisites page in the migration wizard.
Use this information to resolve the errors before you begin migration.
Error: Your identity provider configuration is not supported. Update the IDP IDP_name to send a valid Name ID using a supported format, then try again.
Solution: This error occurs when the SAML IDP in Omnissa Access is configured to use a SAML attribute instead of a Name ID element. Update the configuration to use a Name ID element.
-
In the Omnissa Access console, navigate to the SAML IDP by selecting Integrations > Identity Providers > IDP_name.
-
In the SAML Metadata section, for Identify User Using, select Name ID Element instead of SAML Attribute and select the Name ID Format and Name ID Value.
For example:

-
Save your changes.
-
Update the configuration in your cloud identity provider to match the changes.
Error: We could not determine the Name ID Format and Name ID Value from your identity provider configuration for IDP_name. Please update these fields, then try again.
Solution: Omnissa Access supports multiple Name ID format mappings while Omnissa Identity Service supports only one. If the SAML IDP in Omnissa Access has multiple mappings, Omnissa Identity Service attempts to determine the correct one to use. This error occurs when it cannot do so.
Update the SAML IDP in Omnissa Access to use only one Name ID format mapping.
-
In the Omnissa Access console, navigate to the SAML IDP by selecting Integrations > Identity Providers > IDP_name.
-
In the SAML Metadata section, for Name ID format mapping from SAML Response, delete all mappings except one and verify that it is mapped correctly.
For example:

-
Save your changes.
-
Update the configuration in your cloud identity provider to match the changes.
Error: Your identity provider IDP_name is configured to use the “Send Subject with Mapping” feature, which is not supported by Omnissa Identity Service. Update your IDP configuration to disable this feature, then try again.
Solution: This error occurs if the Send Subject in SAML Request (when available) > Use Name ID format mapping for Subject option is selected in the SAML IDP in Omnissa Access. Omnissa Identity Service does not support the Use Name ID format mapping for Subject option.
Update the SAML IDP in Omnissa Access to deselect the option.
-
In the Omnissa Access console, navigate to the SAML IDP by selecting Integrations > Identity Providers > IDP_name.
-
In the SAML Metadata section, under Name ID Policy in SAML Request, deselect the Use Name ID format mapping for Subject option.

-
Verify that the Name ID Policy in SAML Request value is correct.
-
Save your changes.
-
Update the configuration in your cloud identity provider to match the changes.
Error: Your identity provider IDP_name is sending an unsupported SAML authentication context. Update your IDP to use the unspecified AuthNContext class, then try again.
Solution: This error occurs when the authentication method SAML Context set in the SAML IDP in Omnissa Access is not supported by Omnissa Identity Service. Omnissa Identity Service only supports the following SAML context: urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified.
Update the SAML context for all the authentication methods configured in the SAML IDP in Omnissa Access.
-
In the Omnissa Access console, navigate to the SAML IDP by selecting Integrations > Identity Providers > IDP_name.
-
In the Authentication Methods section, select the following SAML context for all authentication methods: urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified.
For example:

-
Save your changes.
-
Update the configuration in your cloud identity provider to match the changes.
Error: The Name ID Format sent by your identity provider IDP_name is not supported. Update your IDP to use a Name ID Format supported by Omnissa Identity Service.
Solution: This error occurs if the Name ID Format set in the SAML IDP in Omnissa Access is not supported by Omnissa Identity Service. Omnissa Identity Service supports the following formats:

Update the Name ID Format in Omnissa Access to a value supported by Omnissa Identity Service.
-
In the Omnissa Access console, navigate to the SAML IDP by selecting Integrations > Identity Providers > IDP_name.
-
In the SAML Metadata section, for Name ID format mapping from SAML Response, select a value that is supported by Omnissa Identity Service:
For example:

-
Select the Name ID Value.
-
Save your changes.
-
Update the configuration in your cloud identity provider to match the changes.
Error: The Name ID Value sent by your identity provider IDP_name is not supported. Update your IDP to use a Name ID Value supported by Omnissa Identity Service.
Solution: This error occurs if the Name ID Value set in the SAML IDP in Omnissa Access is not supported by Omnissa Identity Service. Omnissa Identity Service supports the following values: userName, userPrincipalName, and emails.
Update the Name ID Value in the SAML IDP in Omnissa Access to a value supported by Omnissa Identity Service.
-
In the Omnissa Access console, navigate to the SAML IDP by selecting Integrations > Identity Providers > IDP_name.
-
In the SAML Metadata section, for Name ID format mapping from SAML Response, select a Name ID Value that is supported by Omnissa Identity Service.
For example:

-
Save your changes.
-
Update the configuration in your cloud identity provider to match the changes.
Questa pagina è stata utile?