You can configure multiple types of authentication methods in the Omnissa Access service. You can configure single authentication methods and you can set up chained, two-factor authentication.
To use the information in this guide, familiarize yourself with the following concepts:
- Single sign-on (SSO) common protocols and terminology. For the SAML protocol, understand terminology such as XML, attributes, and nameIDFormat. For the OpenID Connect protocol, know terminology such as token, claims, JWT, and OAuth 2.
- Multi-factor authentication implementations for Kerberos, RSA SecurID, and certificate-based authentication.
You can install and manage the following types of authentication methods:
- Omnissa Access connector-based authentication methods
- User Auth service methods: When the User Auth service is installed on the connector, Password (cloud deployment), RSA SecurID (cloud deployment), and RADIUS (cloud deployment) authentication methods can be configured and associated with a Built-in identity provider.
- Kerberos Auth service methods: When the Kerberos Auth service is installed on the connector, the Kerberos authentication method can be configured and associated with a Workspace identity provider to provide connector-based Kerberos authentication for internal users.
- User Auth service methods: When the User Auth service is installed on the connector, Password (cloud deployment), RSA SecurID (cloud deployment), and RADIUS (cloud deployment) authentication methods can be configured and associated with a Built-in identity provider.
- Cloud-based authentication methods managed from the Omnissa Access service and associated with a Built-in identity provider
- Authentication managed by third-party identity providers
The identity provider instance that you use with Omnissa Access creates an in-network federation authority that communicates with the service using either SAML 2.0 or OpenID Connect 1.0 protocols.
Omnissa Identity Service Integration
Omnissa Identity Service is a new service for integrating Workspace ONE services, including Omnissa Access, with a third-party identity provider to provide centralized user management. Omnissa Identity Service is based on the System for Cross-domain Identity Management (SCIM) 2.0 protocol.
Omnissa Identity Service is available for new Workspace ONE tenants that do not have any existing directory or identity provider integrations.
Some features are not available in tenants that have Omnissa Identity Service enabled. See the Unsupported Workspace ONE Features topic in the Configuring User Provisioning and Identity Federation with Omnissa Identity Service guide.
For more information about Omnissa Identity Service, see the following links.
Questa pagina è stata utile?