After enabling Omnissa Identity Service in Omnissa Connect, set up the integration with your SCIM 2.0-based identity provider.
-
In the Omnissa Identity Service Getting Started wizard, click Start in step 2, Integrate a SCIM 2.0-Based Identity Provider.

-
Click Set Up on the SCIM 2.0 Identity Provider card.

-
Follow the wizard to set up the integration with your identity provider.
Step 1: Create a Directory
As the first step in setting up user provisioning and identity federation with Omnissa Identity Service, create a directory in the Omnissa Connect console for users and groups provisioned from your identity provider.
Caution: After you create a directory, you cannot change your identity provider selection. Make sure that you select the appropriate identity provider before proceeding.
Procedure
-
In step 1, General Information, of the wizard, enter the name that you want to use for the provisioned directory in Omnissa Identity Service.
The name can have a maximum length of 128 characters. Only the following characters are allowed: letters (a-z or equivalent in other languages), digits (0-9), space, hyphen (-), and underscore (_).
Important: You cannot change the name of the directory after it is created.
-
For Domain Name, enter the primary domain name of your source directory, including the extension such as
.comor.net.Omnissa Identity Service currently supports only one domain. Provisioned users and groups are associated with this domain in Omnissa services.
The domain name can have a maximum length of 100 characters. Only the following characters are allowed: letters (a-z or equivalent in other languages), digits (0-9), space, hyphen (-), underscore (_), and period (.).
For example:

-
Click Save, and confirm your selection.
What to do next
Set up user and group provisioning.
Step 2: Set up User and Group Provisioning
After you create a directory in Omnissa Identity Service, set up user and group provisioning. You start the process in Omnissa Identity Service by generating the admin credentials required for provisioning, then configure provisioning in the identity provider using those credentials.
Note: This information applies to any SCIM 2.0-based identity provider other than Microsoft Entra ID and Okta. To integrate Omnissa Identity Service with Microsoft Entra ID, see Integrating Omnissa Identity Service with Microsoft Entra ID. To integrate Omnissa Identity Service with Okta, see Integrating Omnissa Identity Service with Okta.
Note: This topic provides high-level information about configuring a third-party identity provider. The exact steps and locations for the tasks vary based on your identity provider. Refer to your identity provider's documentation for specific information.
Prerequisites
You have an administrator account in the identity provider with the privileges required to set up user provisioning.
Procedure
-
In the Omnissa Connect console, in step 2, Configure Identity Provider, of the Omnissa Identity Service wizard, select the type of credentials required to set up user provisioning in your identity provider.
Choose between:
- Client ID and secret
- Tenant URL and token Since tokens expire and have to be updated manually, Client ID and secret is preferred. As a security best practice, rotate the client ID and client secret every six months.
When you click Next, Omnissa Identity Service generates the credentials.
-
If you selected Client ID and secret, copy the Client ID and Client Secret values.
Important: Make sure that you copy the secret before clicking Next. After you click Next, the secret will no longer be visible and you will have to generate a new secret. Be aware that whenever you regenerate the secret, the previous secret becomes invalid and provisioning fails. Make sure that you copy and paste the new secret to the identity provider app.
For example:

-
If you selected Tenant URL and token, review and copy the generated values.
-
Tenant URL: Your Omnissa Identity Service tenant's SCIM 2.0 endpoint. Copy the value.
-
Token lifespan: The period for which the secret token is valid
By default, Omnissa Identity Service generates the token with a default lifespan of 6 months. To change the token lifespan, click the down arrow, select another option, and click Regenerate to regenerate the token with the new value.
Important: Whenever you update the token lifespan, the previous token becomes invalid and provisioning of users and groups from the identity provider fails. You must regenerate a new token and copy and paste the new token to the identity provider.
-
Secret token: The token required by the identity provider to provision users to Omnissa Identity Service. Copy the value.
Important: Make sure you copy the token before clicking Next. After you click Next, the token will no longer be visible and you will have to generate a new token. Be aware that whenever you regenerate the token, the previous token becomes invalid and provisioning fails. Make sure that you copy and paste the new token to the identity provider.
For example:

When the token is about to expire, a banner notification will appear in Omnissa Identity Service. If you also want to receive email notifications, make sure that you opt in to receive emails. See How to enable email notifications.
-
-
In your identity provider, set up user and group provisioning to Omnissa Identity Service.
-
Log into your identity provider console as an administrator.
-
Set up SCIM 2.0 provisioning.
When prompted, enter the credentials that you generated in the Omnissa Connect console.
-
Activate the provisioning.
-
What to do next
Return to the Omnissa Connect console to continue with the Omnissa Identity Service wizard.
Step 3: Map SCIM User Attributes
Map the user attributes to synchronize from your identity provider to Omnissa services. In your identity provider console, add the required SCIM user attributes and map them to your identity provider attributes. At a minimum, synchronize the attributes that Omnissa Identity Service and the Omnissa services integrated with it require.
Omnissa Identity Service and Omnissa services require the following SCIM user attributes:
- userName
- emails[type eq "work"].value
- name.givenName
- name.familyName
- externalId
- active
For more information about these attributes and their mapping to Omnissa attributes, see User Attribute Mapping for Omnissa Identity Service.
In addition to the required attributes, you can synchronize optional attributes and custom attributes. For the list of supported optional and custom attributes, see User Attribute Mapping for Omnissa Identity Service.
Procedure
-
In the Omnissa Connect console, in step 3, Map SCIM User Attributes, of the Omnissa Identity Service wizard, review the list of attributes that Omnissa Identity Service supports.
-
In your identity provider admin console, navigate to the provisioning configuration for Omnissa Identity Service.
-
Navigate to the attribute mapping page.
-
Map the required SCIM user attributes to your identity provider attributes.
-
Add and map optional and custom SCIM user attributes, as needed.
What to do next
Return to the Omnissa Connect console to continue with the Omnissa Identity Service wizard.
Step 4: Select the Authentication Protocol
Select the protocol to use for federated authentication. Omnissa Identity Service supports the OpenID Connect and SAML protocols.
Caution: Make your choice carefully. After you select the protocol and configure authentication, you cannot change the type of protocol without deleting the directory.
Requirements for certain username and password-based flows in Workspace ONE UEM (Password Grant flows)
If you plan to use Workspace ONE UEM username and password-based flows that rely on the Password Grant protocol, you must select OpenID Connect as the authentication protocol in Omnissa Identity Service.
You must also enable the Password Grant setting on the Workspace ONE UEM Directory Services page to grant permission to use the legacy Password Grant protocol. See Configure Workspace ONE UEM Settings for Omnissa Identity Service.
For the list of flows to which these requirements apply, see Support for Certain Workspace ONE UEM Username and Password-based Flows.
Procedure
-
In step 4, Select Authentication Protocol, of the wizard, select OpenID Connect or SAML.
-
If you plan to create Basic users in Workspace ONE UEM, expand Setup UEM Basic User Authentication and enable the Basic user authentication for UEM option.
See Configuring Authentication for Workspace ONE UEM Basic Users for information.
-
Click Next.
The next step of the wizard appears with the values required to configure the protocol you selected.
What to do next
Configure Omnissa Identity Service and the identity provider for federated authentication.
Step 5: Configure Authentication (Generic SCIM Identity Provider)
To configure federated authentication with your identity provider, you set up an OpenID Connect or SAML app in the identity provider using the service provider metadata from Omnissa Identity Service, and configure Omnissa Identity Service with the values from the app.
Note: This topic provides high-level information about configuring a third-party identity provider. The exact steps for the tasks vary based on your identity provider. Refer to your identity provider's documentation for specific information.
OpenID Connect
If you selected OpenID Connect as the authentication protocol, follow these steps.
-
From step 5, Configure OpenID Connect, of the Omnissa Identity Service wizard, copy the Redirect URI value.
You need this value for the next step, when you create an OpenID Connect app in your identity provider.

-
In the identity provider admin console, create an OpenID Connect app.
-
Find the Redirect URI section in the app, and copy and paste the Redirect URI value that you copied from the Omnissa Identity Service wizard.
-
Create a client secret for the app, and copy it.
You will enter the secret in the Omnissa Identity Service wizard in the next step.
-
Return to the Omnissa Identity Service wizard in the Omnissa Connect console, and complete the configuration in the Configure OpenID Connect section.
Client ID Copy and paste the client ID value from the identity provider app. Client Secret Copy and paste the client secret from the identity provider app. Configuration URL Copy and paste the OpenID Connect well-known configuration URL of the identity provider app. For example: https://example.com/.well-known/openid-configuration OIDC User Identifier Attribute Specify the OpenID Connect attribute to map to the Workspace ONE attribute for user lookups. Workspace ONE User Identifier Attribute Specify the Workspace ONE attribute to map to the OpenID Connect attribute for user lookups. -
In the Omnissa Identity Service wizard, click Finish to complete setting up the integration between Omnissa Identity Service and your identity provider.
SAML
If you selected SAML as the authentication protocol, follow these steps.
-
Get the service provider metadata from the Omnissa Connect console.
From step 5, Configure SAML Single Sign-On, of the Omnissa Identity Service wizard, either copy or download the SAML service provider metadata.

-
In the identity provider admin console, navigate to the single sign-on configuration page.
-
Configure single sign-on using values from the Omnissa Identity Service wizard.
Typical configuration steps include one of the following, based on what the identity provider supports:
-
Find the Service Provider metadata option, and upload or copy and paste the SAML service provider metadata from the Omnissa Identity Service wizard.
-
If the identity provider does not have an option for uploading the metadata file, or if you prefer to configure settings individually, copy and paste the following values from step 5 of the Omnissa Identity Service wizard to the corresponding fields in the identity provider console:
Entity ID value: For example, https
://yourIdentityServiceFQDN/SAAS/API/1.0/GET/metadata/sp.xml. Single sign-on URL value: For example, https
://yourIdentityServiceFQDN/SAAS/auth/saml/response. Signing Certificate
Encryption certificate (under Advanced options): Required if you plan to enable SAML encryption in the identity provider.
-
-
Find and copy the Identity Provider SAML metadata from the identity provider console.
-
In the Omnissa Connect console, in step 5, Configure SAML Single Sign-On, of the Omnissa Identity Service wizard, paste the Identity Provider metadata into the Identity provider metadata text box.

-
Configure the rest of the options in the Configure SAML Single Sign-On section, as required.
-
Binding protocol: Select the SAML binding protocol, HTTP POST or HTTP Redirect.
-
Name ID format: Use the Name ID format and Name ID value settings to map users between your identity provider and Omnissa Identity Service. For Name ID format, specify the Name ID format used in the SAML response.
-
Name ID value: Select the Omnissa Identity Service user attribute to which to map the Name ID value received in the SAML response.
-
SAML Context: Select the SAML authentication context. You can select one of the values shown in the drop-down menu, or type a custom value. The default value is urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified.
The authentication context indicates how users are authenticated at the identity provider. The identity provider includes the authentication context in an assertion at the request of a service provider or based on the configuration at the identity provider.
-
Send Subject in SAML request (when available): Select this option if you want to send the subject to the identity provider as a login hint to improve the user login experience, when available.
-
Use SAML single logout: Select this option if you want to log users out of their identity provider session after they log out of Omnissa services.
-
Identity provider single logout URL: If your identity provider does not support SAML single logout, you can use this option to specify the URL to which to redirect users after they log out of Omnissa services. If you use this option, also select the Use SAML single logout check box.
If you leave this option blank, users are redirected to the identity provider using SAML single logout.
-
-
Click Finish in the wizard to complete setting up the integration between Omnissa Identity Service and your identity provider.
Results
The integration between Omnissa Identity Service and your identity provider is complete.
The directory is created in Omnissa Identity Service and will be populated when you push users and groups from the provisioning app in the identity provider. Provisioned users and groups will automatically appear in the Omnissa services you choose to integrate with the identity provider, such as Omnissa Access and Workspace ONE UEM.
You cannot edit the directory in the Omnissa Access, Workspace ONE UEM, or Horizon Cloud consoles. Directory, users, user groups, user attributes, and identity provider pages are read-only.
What to do next
Next, select the Omnissa services to which you want to provision users and groups.
If Workspace ONE UEM is one of the services you select, configure additional settings in the Workspace ONE UEM console.
Then, push users and groups from your identity provider. See Provisioning Users to Workspace ONE.
Questa pagina è stata utile?