Horizon Cloud の場合は、次の手順を実行して、統合された Entra ID または統合された Okta を使用して Omnissa Identity Service を ID プロバイダとして構成します。
前提条件
-
Horizon Cloud へのアクセス権があることを確認します。ログインを作成するには、「Horizon Cloud 管理者のオンボーディング」を参照してください。
-
Omnissa Identity Service アカウントが構成されていることを確認します。「Omnissa Identity Service の使用開始」を参照してください。
関連情報については、「Horizon Cloud で Omnissa Identity Service を使用する」を参照してください。
Omnissa Identity Service の構成と使用に関する情報については、「Omnissa Identity Service を使用したユーザー プロビジョニングと ID フェデレーションの構成」のトピックを参照してください。
Omnissa Identity Service と Microsoft Entra ID の統合
Omnissa Identity Service と Microsoft Entra ID を Horizon Cloud の ID プロバイダとして統合するには、Omnissa Identity Management製品ドキュメントの「Omnissa Identity Service と Microsoft Entra ID の統合」に記載されている手順に従います。
Omnissa Identity Service と Okta の統合
Omnissa Identity Service と Okta を Horizon Cloud の ID プロバイダとして統合するには、Omnissa Identity Management製品ドキュメントの「Omnissa Identity Service と Okta の統合」および「Horizon Cloud での Omnissa Identity Service の使用」に記載されている手順に従います。
構成された ID プロバイダとして Omnissa Identity Services が統合された Okta を使用する場合は、次の属性を構成する必要があります。
-
onPremisesSamAccountName(active_directory.samAccountNameとして) -
onPremisesSecurityIdentifier(active_directory.objectSidとして) -
onPremisesUserPrincipalName(active_directory.userNameとして)
Omnissa Identity Service と Google Identity(Google Workspace および Cloud Identity)の統合
Omnissa Identity Service と Google Identity(Google Workspace および Cloud Identity)を Horizon Cloud の ID プロバイダとして統合するには、Omnissa Identity Management 製品ドキュメントの「Omnissa Identity Service を使用したユーザー プロビジョニングと ID フェデレーションの構成」に記載されている手順に従います。
構成された ID プロバイダとして Omnissa Identity Service が統合された Google Identity を使用する場合は、次の属性を構成する必要があります。
-
userName(Basic Information > Usernameとして) -
name.givenName(Basic Information > First nameとして) -
name.familyName(Basic Information > Last nameとして) -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.userPrincipalName(onPremisesUserPrincipalNameにマッピングされた属性として) -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.onPremisesSamAccountName(onPremisesSamAccountNameにマッピングされた属性として) -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.onPremisesUserPrincipalName(onPremisesUserPrincipalNameにマッピングされた属性として) -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.onPremisesSecurityIdentifier(onPremisesSecurityIdentifierにマッピングされた属性として) -
urn:ietf:params:scim:schemas:extension:ws1b:2.0:User.securityIdentifier(onPremisesSecurityIdentifierにマッピングされた属性として)注:
- 上記の属性の最後の 4 つ(
userPrincipalName、onPremisesSamAccountName、onPremisesUserPrincipalName、およびonPremisesSecurityIdentifier)については、マッピングする前に Google Workspace でカスタム スキーマを作成する必要があります。デフォルトでは、これらのカスタム属性は Google OIS SAML アプリケーションでは使用できません。 onPremisesSecurityIdentifierとsecurityIdentifierは両方ともonPremisesSecurityIdentifierという同じカスタム属性にマッピングされます。 。- GCDS は、Base64 URL のパディングなしのエンコードを使用してバイナリ属性を自動的にエンコードします。
- 上記の属性の最後の 4 つ(
これらの属性は、次の要素にとって重要です。
- デスクトップ割り当て:ユーザーを Active Directory ID と照合するために使用されます。
- SSO:正しい ID トークンを Horizon Agent に渡すために使用されます。
- ドメイン参加の検証:ユーザーのオンプレミス セキュリティ コンテキストを検証するために使用されます。
このページは役に立ちましたか?