Skip to main content

14 oktober 2025

Configuring Microsoft Edge for Business Device Signals in Omnissa Access

Device Trust Connector in Edge for Business signals make it possible to verify the posture of an unmanaged device or a third-party managed device prior to allowing access to company resources. A managed Edge web browser can collect information about the security posture of a device and share it with Omnissa Access so that a posture-informed access decision can be made in real time.

The verification of unmanaged devices prior to granting access to apps and resources is simplified by the Omnissa integration within the Microsoft Device Trust Connector in Edge for Business and an authentication adapter in Omnissa Access. In Omnissa Access, conditional access rules can be created that require specific device signal criteria to be met.

You can configure Microsoft Edge for Business Device Signals as an authentication factor in Omnissa Access to support authentication for managed profiles on Windows devices. You enable and configure the adapter in the Omnissa Access console to retrieve device-level signals from the Edge browser. Users can sign in to Omnissa Access from an Edge browser with a managed profile on a Windows machine.

The Edge for Business Device Signals authentication is based on the device signal attributes that you enable when you configure the adapter in the Omnissa Access console. You must also integrate Omnissa Access with the Omnissa Device Trust connector in the Microsoft Edge management service console. After completing the setup in both the Omnissa and Microsoft consoles, you configure access policy rules in the Omnissa Access console.

When users use the Edge browser to sign in, after their initial credentials are authenticated, the second-factor authentication through Edge checks the device security status based on the device signal attributes that you configured. Omnissa Access retrieves the signal status from the Edge integration.

Edge for Business Device Signals authentication is available for users running the Edge browser with a managed profile on Windows devices.

Note: This authentication method is not available for managed browsers.

Requirements

  • Omnissa Access SaaS tenant
  • Microsoft Entra tenant ID
  • Managed profiles
  • Users must be assigned to one of the following subscription plans:
    • Education: Microsoft 365 A3, Microsoft 365 A5
    • Business: Microsoft 365 Business Standard, Microsoft 365 Business Premium
    • Enterprise: Office 365 E3, Office 365 E5, Microsoft 365 E3, Microsoft 365 E5

Configure Edge for Business Device Signals Adapter in the Omnissa Access Console

Enable and configure the Edge for Business Device Signals adapter in the Omnissa Access console.

Procedure

  1. In the Omnissa Access console, navigate to the Integrations > Authentication Methods page.

  2. Select Edge for Business Device Signals and click Configure.

  3. Configure the authentication settings.

    OptionDescription
    Enable Microsoft Edge for Business Device Signal AdapterSet this option to Yes to enable the adapter.
    URLs matcher to trigger the Microsoft Edge inline flow Copy and save the URL. You require this value to configure the Device Trust Connector in the Microsoft Edge management service.

    Important: If multiple URLs are listed, make sure that you copy all of them and configure them in the Device Trust Connector. As part of the upcoming URL migration changes described in KB article 6001062, if your Access tenant FQDN falls in the list of environments under Category 2 - Certificate Branding and URL Change, two URLs appear in the URLs matcher field, one that uses the existing Access FQDN and one that uses the new Access FQDN. The new FQDN has been made available for this use case ahead of the migration for your convenience. Do not use it for any other use cases. The migration timeline will be communicated to all customers through the KB article.
    IDP Service Principal Copy and save the IDP Service Principal. You require this value to configure the Device Trust connector in the Microsoft Edge management service.
    Microsoft Tenant IDEnter your Microsoft Entra ID tenant ID.
    Allow access if not a managed Microsoft Edge browser This setting is deactivated by default to prevent access from browsers without a managed profile. Activating this setting is not recommended. If you want to support browsers without a managed profile, configure the access policy with an alternative authentication method that performs strong validation as the fallback authentication.
    Verify device's disk encryption status Enable this setting if the device disk must be encrypted. Select the setting that is required to access apps from a device. When you select a setting with multiple options, validation operates with an OR logic, allowing any of the chosen values.
    • Encrypted. The main disk is encrypted. If you select this option, the check verifies that the main disk must be encrypted. Removable disks are not evaluated for disk encryption.
    • Encrypted | Unspecified. The main disk is encrypted or Edge did not send the signal.
    • Encrypted | Unknown. The main disk is encrypted or Edge could not evaluate the encryption state.
    • Encrypted | Unspecified | Unknown. The main disk is encrypted, Edge did not send the signal, or Edge could not evaluate the encryption state.
    Verify device's firewall statusEnable this setting if a firewall must be enabled on the device. Select the setting that is required to access apps from a device. When you select a setting with multiple options, if any one of the options in the value is valid, the entire validation is considered successful.
    • Enabled. The firewall is enabled.
    • Enabled | Unspecified. The firewall is enabled or Edge did not send the signal.
    • Enabled | Unknown. The firewall is enabled or Edge was unable to determine the status of the operating system's firewall.
    • Enabled | Unspecified | Unknown. The firewall is enabled, Edge did not send the signal, or Edge was unable to determine the status of the operating system's firewall.
    Verify device's screen lock statusEnable this setting to require devices to use a password to unlock the device. When you select a setting with multiple options, if any one of the options in the value is valid, the entire validation is considered successful.
    • Enabled. Screen lock is enabled.
    • Enabled | Unspecified. Screen lock is enabled or Edge did not send the signal.
    • Enabled | Unknown. Screen lock is enabled or Edge was unable to determine the screen lock state.
    • Enabled | Unspecified | Unknown. Screen lock is enabled, Edge did not send the signal, or Edge was unable to determine the screen lock state.

""

  1. Click Save.

What to do next

Copy and save the URLs matcher and the IDP Service Principal values if you did not do so already. Then, configure the Omnissa Device Trust Connector in the Microsoft Edge management console using these values.

Configure Omnissa Device Trust Connector in the Microsoft Edge Management Console

In the Microsoft Edge management console, configure the Omnissa Device Trust Connector.

Note: This procedure reflects the Microsoft user interface at the time the Omnissa Device Trust Connector was first released. For updated information, see the Microsoft documentation, Set up an Omnissa Device Trust Connector.

Procedure

  1. In the Microsoft admin center, go to the Microsoft Edge connectors page: https://admin.microsoft.com/Adminportal/Home#/Edge/Connectors

  2. Under Discover, find the Omnissa Device Trust Connector and click Set up.

    ""

  3. For Choose Policy, select a policy.

  4. In the URL patterns to allow, one per line text box, enter the URL matchers value from the Omnissa Access console.

  5. In the Application (Client ID) text box, enter the IDP Service Principal value from the Omnissa Access console and click Consent to grant Omnissa access to retrieve device signals.

  6. Click Save configuration to apply your changes.

Add Microsoft Edge for Business Device Signals as a Secondary Authentication Method in Omnissa Access Policies

After you configure the Edge for Business Device Signals adapter in Omnissa Access and the Omnissa Device Trust Connector in the Microsoft Edge management service console, you create access policy rules in Omnissa Access to use Edge for Business Device Signals for second factor authentication. Update the default access policy or other policies as needed.

Prerequisite

Associate the Microsoft Edge for Business Device Signals authentication method with an identity provider in the Omnissa Access console. Navigate to the Integrations > Identity Providers page, select the identity provider, scroll to the Authentication Methods section, and enable Microsoft Edge for Business Device Signals. Then click Save.

Procedure

  1. In the Omnissa Access console Resources > Policies page, add a policy or edit an existing policy.

  2. Click Next to go to the Configuration page.

  3. Select the rule to edit or click Add Policy Rule to create a new rule.

    Option Description
    If a user's network range is Select the network range.
    and the user accessing content from Select Windows 10+ as the device type that this rule manages.
    and user belongs to groups Select the group that this rule applies to. If you do not add a group to the rule, the rule applies to all users.
    Then perform this action Select Authenticate using....
    then the user may authenticate using Select the user authentication method to apply first.
    To require users to select Microsoft Edge for Business Device Signals as the second authentication method, click ADD AUTHENTICATION, select Microsoft Edge for Business Device Signals from the drop-down menu, and click ADD.
  4. To save your changes, click Next and click Save.

When users sign in, they are prompted to authenticate using their primary authentication method. If that is successful, the secondary authentication process through Microsoft Edge checks the device security status and shares the information with Omnissa Access. If the device is in compliance, the secondary authentication succeeds and the user is signed in. If the device is not in compliance, the authentication fails.

The Omnissa Access Audit Events report logs the success or failure of the authentication, including which signal failed. In the Omnissa Access console, select Monitor > Reports, select the Audit Events report type, select your parameters, and click Show Results.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…