Skip to main content

2025년 4월 17일 아카이브됨

Requirements to Use SAML Assertions for Just-in-Time Provisioning in Omnissa Access

When Just-in-Time user provisioning is enabled for a SAML third-party identity provider, users are created or updated in the Omnissa Access service during login based on SAML assertions. SAML assertions sent by the identity provider must contain certain attributes.

  • The SAML assertion must include the userName attribute.

  • The SAML assertion must include all the attributes that are marked as required in the User Attributes page in the Omnissa Access service.

    You can view the user attributes in the admin console Settings > User Attributes page.

    Important: Ensure that the keys in the SAML assertion match the attribute names exactly, including the case.

  • If you are configuring multiple domains for the Just-in-Time directory, the SAML assertion must include the domain attribute. The value of the attribute must match one of the domains configured for the directory. If the value does not match or a domain is not specified, login fails.

  • If you are configuring a single domain for the Just-in-Time directory, specifying the domain attribute in the SAML assertion is optional.

    If you specify the domain attribute, ensure that its value matches the domain configured for the directory. If the SAML assertion does not contain a domain attribute, the user is associated with the domain that is configured for the directory.

  • If you want user name changes to be updated, include the ExternalId attribute in the SAML assertion. The user is identified by the ExternalId. If on a subsequent login, the SAML assertion contains a different user name, the user is still identified correctly, login succeeds, and the user name is updated in the Omnissa Access service.

Attributes from the SAML assertion are used to create or update users as follows.

  • Attributes that are listed as required or optional in the User Attribute page in the Omnissa Access service are used.

  • SAML attributes that do not match any attributes in the User Attributes page are ignored.

  • SAML attributes without a value are ignored.

이 페이지가 도움이 되었나요?

이 항목에 대한 피드백 보내기

이 항목이 도움이 되었나요?

개인정보나 기밀정보는 입력하지 마세요.

링크를 생성하는 중…