Skip to main content

19 agosto 2026

Configuring User Provisioning and Identity Federation with Omnissa Identity Service

Omnissa Identity Service integrates Omnissa products and services with third-party cloud-based identity providers such as Microsoft Entra ID and Okta for user provisioning and identity federation, enabling centralized user management across the Omnissa platform.

Users and groups are provisioned using the SCIM 2.0 protocol from your identity provider to a centralized directory in Omnissa Identity Service. Omnissa Identity Service then provisions them to the Omnissa services you select, such as Workspace ONE UEM and Omnissa Access. You can configure federated authentication using OpenID Connect or SAML 2.0. Once set up, you manage users and groups in the identity provider and Omnissa Identity Service automatically keeps the Omnissa services in sync. Directory settings in individual services become read-only.

Omnissa Identity Service is available both as a cloud service and an on-premises service. For on-premises deployments, it is bundled with Omnissa Access 26.07 and later. For information on how to access Identity Service for your deployment type, see Getting Started with Omnissa Identity Service.

Important: This document provides guidance for configuring Omnissa Identity Service for new deployments — new organizations for cloud and new installations of Omnissa Access 26.07 or later on-premises. To migrate existing directories to the Omnissa Identity Service cloud service, see Migrating Directories to Omnissa Identity Service (Limited Availability).

Key Features

Key features of Omnissa Identity Service include:

  • SCIM 2.0 User Provisioning

    Omnissa Identity Service is based on the System for Cross-domain Identity Management (SCIM) 2.0 protocol, which is a standard for managing user identities in cloud-based applications and services. Omnissa Identity Service supports any SCIM 2.0-based cloud identity provider.

  • Identity federation using OpenID Connect or SAML 2.0

    You can configure federated authentication with your third-party identity provider using either OpenID Connect or SAML 2.0.

  • Centralized user management across Omnissa products and services

    With Omnissa Identity Service, you create a single provisioned directory in the Omnissa Connect console. Users and groups are provisioned from your identity provider to Omnissa Identity Service, and are then provisioned automatically from Omnissa Identity Service to the Omnissa products and services that you select. Omnissa Identity Service currently supports Omnissa Access, Omnissa Workspace ONE® UEM, and Omnissa Horizon Cloud.

    You manage the directory from the Omnissa Connect console. Directory, users, user groups, user attributes, and identity provider settings in Omnissa Access and Workspace ONE UEM are read-only.

  • No connector requirement

    You do not need to deploy the Omnissa Access Connector or the AirWatch Cloud Connector on-premises to integrate Omnissa Identity Service with cloud identity providers.

You set up and manage Omnissa Identity Service from the Omnissa Connect console.

Note: Omnissa Identity Service is not available for Managed Services Provider customers at this time.

Supported Identity Providers

Omnissa Identity Service supports the following cloud-based identity providers:

  • Microsoft Entra ID (formerly known as Azure Active Directory or Azure AD)
  • Okta
  • Google Workspace
    Note: You can only provision users to Omnissa Identity Service. Google Workspace does not support SCIM provisioning of groups.
  • Any generic SCIM 2.0 identity source

Important: Direct integration with Active Directory is not supported.

Supported Products and Services

You can configure Omnissa Identity Service for the following products and services:

  • Omnissa Access Cloud or Omnissa Access on-premises 26.07 or later
  • Workspace ONE UEM 2212 or later
  • Horizon Cloud

Important: Omnissa Identity Service is supported for new Omnissa Connect organizations only.

Key Considerations

  • Omnissa Identity Service is only available for new organizations in Omnissa Connect. For on-premises, it is only available for new installations of Omnissa Access 26.07 or later.

  • Your Workspace ONE subscription automatically includes Omnissa Identity Service if you are onboarding through Omnissa Connect. For on-premises, Omnissa Access 26.07 and later automatically include Omnissa Identity Service.

  • Omnissa Identity Service currently supports Omnissa Access (Cloud service and on-premises version 26.07 or later), Workspace ONE UEM 2212 or later, and Horizon Cloud.

    Note: For Horizon Cloud, Omnissa Identity Service currently supports only Microsoft Entra ID, Okta, and Google Workspace as third-party identity providers.

  • Your Workspace ONE UEM, Omnissa Access, or Horizon Cloud tenants must not have an existing integration with a directory source or identity provider.

  • Omnissa Identity Service centralizes directory management. After you enable Omnissa Identity Service, you can manage your directory only from the Omnissa Identity Service console. Directory services and identity provider settings in the individual services become read-only.

  • You can only integrate a single directory with Omnissa Identity Service.

  • You can only configure one domain.

  • You must set up provisioning and authentication with the same identity provider. Integration with multiple identity providers is not supported.

  • Omnissa Identity Service does not support local users or Just-in-Time users.

    For the cloud service, all users in Omnissa Identity Service are either users provisioned from your third-party identity provider, or Omnissa Connect administrators. For on-premises deployments, end users are provisioned from your third-party identity provider and you can create local administrators in the Omnissa Identity Service console.

    Basic user accounts stored in Workspace ONE UEM are supported. See Configuring Authentication for Workspace ONE UEM Basic Users for more information.

  • Omnissa Identity Service does not support direct integration with Active Directory or other LDAP directories.

  • When Google Workspace is configured as the identity provider, only user provisioning is supported. Google Workspace does not support SCIM provisioning of groups.

  • To set up Omnissa Identity Service, you must have administrator roles in Omnissa Connect for your organization (for Omnissa Identity Service cloud only), the Omnissa Access service, and the services you want to integrate with Omnissa Identity Service. Specific role requirements are listed in this documentation.

Note: In Omnissa Identity Service, after you select an Omnissa service such as Workspace ONE UEM to integrate with Omnissa Identity Service and save your selection, you cannot deselect it. You must contact Support to make any changes.

Unsupported Features

Omnissa Identity Service does not support the following features.

Workspace ONE UEM

If Omnissa Identity Service is enabled for a tenant, the following features are not supported:

  • Direct integration with on-premises Active Directory
  • Creating and managing administrators and administrator groups through Directory Services
    You can provision administrators through Omnissa Connect.
  • Overriding Directory Services for child organization groups (OG) when Omnissa Identity Service is configured for the parent organization group
  • Just-in-time (JIT) provisioning of users
    Enrollment users are provisioned through SCIM to Workspace ONE UEM.
  • Batch import for Omnissa Identity Service users, for device registration and for updating user properties

The following enrollment methods are not supported:

Platform Unsupported Flows
iOS Hub and Browser-based enrollment with Basic users using Username/Password
Android Hub (Work Profile) and COPE/Work Managed enrollment with Basic users using Username/Password
macOS Hub and Browser based enrollment with Basic users using Username/Password
Windows Hub based enrollment with Basic users using Username/Password

Dropship Online
Linux SAML authentication on Headless devices

Enrollment with Basic users using Username/Password
XR All flows
Peripherals All flows

Omnissa Access

If Omnissa Identity Service is enabled for a tenant, the following features are not supported:

  • Direct integration with on-premises Active Directory
  • Creation of local users or Just-in-time (JIT) users
    All end users are provisioned from your identity provider by Omnissa Identity Service. For cloud deployments, administrators are provisioned through Omnissa Connect. For on-premises deployments, you can create local administrators from the Omnissa Identity Service console.
    Note: Local users and local administrators refer to user accounts that are created directly in Omnissa Access and not synced from a directory source.
  • People Search
  • If you integrate Omnissa Access with Office 365, you cannot use federated authentication to the Microsoft Entra ID identity provider. Only Omnissa Access-specific authentication methods, such as RSA SecurID, Hub MFA, Mobile SSO, and Certificate Auth, will be available. Office 365 Active Flow authentication is currently not supported.

Horizon Cloud

If Omnissa Identity Service is configured as the identity provider for Horizon Cloud, the following features are not supported:

  • Generic SCIM 2.0 identity providers as the third-party identity provider integrated with Omnissa Identity Service
    Only Microsoft Entra ID, Okta, and Google Workspace are supported as third-party identity providers.
  • SAML protocol for authentication
    Only OpenID Connect is supported.
  • Enforce Intelligent Hub setting
    You can enable Intelligent Hub but the Enforce Intelligent Hub setting, which forces users to access their apps through Intelligent Hub, is not currently supported.

Omnissa Workspace ONE® Hub Services

If Omnissa Identity Service is enabled for a tenant, the following features are not supported:

  • People tab configurations
  • New Hire Onboarding configurations, including Onboarding templates
  • Digital Badge and Return to Work experience
  • Integration with Horizon Cloud Service on Microsoft Azure with Universal Broker

Omnissa Workspace ONE® Intelligent Hub

If Omnissa Identity Service is enabled, the following features are not available to users in the Workspace ONE Intelligent Hub app or web browser:

  • People tab
  • Digital Badge and Return to Work experience
  • New Hire Onboarding
  • Change password option for Omnissa Access users (who are not Okta users)
  • Apps and desktops from Horizon Cloud Service on Microsoft Azure with Universal Broker

Support for Certain Workspace ONE UEM Username and Password-based Flows (Password Grant Flows)

Workspace ONE UEM flows that rely on the Password Grant protocol are supported for Omnissa Identity Service-provisioned users only if you:

  • Select OpenID Connect as the authentication protocol in Omnissa Identity Service for the integration with your identity provider.
  • Enable the Password Grant setting on the Workspace ONE UEM Directory Services page to grant permission to use the legacy Password Grant protocol.

Otherwise, these flows are supported for Basic users only. Basic users are users that are created directly in Workspace ONE UEM and not synced from a directory source.

Note: Password Grant flows are not supported when Google Workspace is configured as the identity provider because it does not support OIDC.

Password Grant-based flows include:

Platform Flows
iOS
  • Check out single-user staging or multi-user staging devices to Omnissa Identity Service and Basic users
  • DEP enrollment with Authentication OFF for Omnissa Identity Service and Basic users
  • DEP enrollment with Authentication ON and Custom Enrollment OFF for Omnissa Identity Service and Basic users
  • Hub and Browser enrollments to Basic users with Token authentication
Android Check-out staging-enrolled devices to Omnissa Identity Service and Basic users
macOS
  • Hub and Browser enrollments to Basic users with Token authentication
  • Check out staging-enrolled devices to Omnissa Identity Service and Basic users
  • DEP enrollment with Authentication OFF for Omnissa Identity Service and Basic users
  • DEP enrollment with Authentication ON and Custom Enrollment OFF for Omnissa Identity Service and Basic users
Windows
  • Silent enrollment
  • PPKG enrollment to Basic users
Linux
  • Enrollment using Token authentication
  • Check out staging-enrolled devices to Omnissa Identity Service and Basic users

You select the authentication protocol while integrating your cloud-based identity provider with Omnissa Identity Service. See Integrate Omnissa Identity Service with Microsoft Entra ID, Integrate Omnissa Identity Service with Okta, or Integrate Omnissa Identity Service with a Generic Identity Provider. For information about configuring the Password Grant setting, see Configure Workspace ONE UEM Settings for Omnissa Identity Service.

Important: Although the Password grant protocol is not recommended by the OAuth 2.0 Security Best Practices document, Omnissa Identity Service uses it to support certain legacy authentication flows that rely on password-based authentication only. Its use is strictly limited to those flows.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…