Skip to main content

4 mei 2026

Omnissa Identity Services with Directory Services

Omnissa Identity Service (OIS) is a cloud-based solution designed to integrate Omnissa products and services with third-party Identity Providers such as Microsoft Entra ID and Okta. Omnissa Identity Service supports user provisioning and identity federation, enabling centralized user management across the Omnissa platform. OIS can also be integrated with Workspace ONE UEM to streamline user provisioning, group provisioning, and authentication.

Supported Workspace ONE UEM Deployments

Deployment Type Required Workspace ONE UEM Console Version
Workspace ONE UEM SaaS tenants without any Directory Services configuration (Greenfield) Workspace ONE UEM 2212 and later releases
Workspace ONE UEM SaaS tenants with Directory Services configuration (Brownfield) Workspace ONE UEM 2506 (Limited Availability)
Workspace ONE UEM On-premises Not supported

For more information on the requirements, configuration, and management of Omnissa Identity Services, see the Omnissa Identity Services documentation.

Key Features Supporting Omnissa Identity Service Integration

Workspace ONE UEM offers enhanced and differentiated capabilities for tenants, using integration with the Omnissa Identity Service.

User Management

The integration of a Workspace ONE UEM tenant with the Omnissa Identity Service enables a set of differentiated capabilities for user and group provisioning, which are detailed in the following sections.

Delete or Remove a User from SCIM Provisioning

After integrating the Omnissa Identity Service (OIS) with Workspace ONE UEM, if a user is deleted or removed from SCIM provisioning in the Identity Provider, OIS will remove the user from both the Omnissa Identity Service and Workspace ONE UEM. Omnissa Identity Service will remove the user from itself and attempt to remove the user from UEM, which triggers the following actions:

  • No associated devices - If a user has no associated devices in Workspace ONE UEM, the user record is deleted.

  • Single-user staging enabled- If the user has associated devices and Single-user Staging is enabled:

    • The user is deactivated in Workspace ONE UEM.
    • Username is updated with the suffix Deleted{EnrollmentUserID}. For example, jdoe becomes jdoe_Deleted_1256, where 1256 is the EnrollmentUserID.
  • Enable multi-user staging - If a user is a staging user for one or more enrolled devices:

    • The user is deactivated in UEM.
    • Username is updated with the suffix Deleted{EnrollmentUserID}. For example, jdoe becomes jdoe_Deleted_1256.
  • Staging is disabled for iOS and Android devices:

    • If the user is associated with single-user (dedicated) devices, the devices are deleted, and the user is then deleted from Workspace ONE UEM.
    • If the user is associated with multi-user (shared) devices, the devices are checked in to their staging user, and the end-user account is then deleted from Workspace ONE UEM.
  • Staging is disabled for Windows and macOS devices - Associated devices are deleted and then the user is deleted from Workspace ONE UEM.

When a user is deactivated, administrators can manually delete the user from Workspace ONE UEM after dissociating any associated devices. Deleting the device record from Workspace ONE UEM will cause the device to unenroll if the device attempts to communicate with Workspace ONE UEM later.

Migrating Existing Users in Brownfield Deployments

You can enable Omnissa Identity Service integration with UEM to utilize SCIM provisioning from your cloud-based identity provider, allowing you to migrate users and groups that were previously synced to UEM through LDAP. The migration process through OIS occurs in multiple phases, which may impact user records and authentication.

Omnissa Identity Service Authentication Switch Phase

During the Authentication Switch phase of OIS migration, authentication for Windows Out-of-Box Experience (OOBE) enrollment does not route through the Omnissa Identity Service. OOBE enrollment starts using OIS only after the migration phase is complete.

If Password Grant is enabled during OIS Authentication Switch and the attribute mapped to UEM username is changed, Enrollment QR Code generation located at Devices > Staging > Mobile Staging may not work for Directory users. This feature can be used after OIS migration is completed.

Omnissa Identity Service Migration Phase

When user provisioning for Workspace ONE UEM is enabled through the Omnissa Identity Service (OIS) for a tenant that already has LDAP-based Directory Services integration, the following processes apply during the OIS migration phase:

LDAP-synced User statusSCIM-provisioned User statusMigration Result
Active with or without associated devicesNo match foundUser record remains in UEM but is not managed through OIS. Associated devices are not modified
Active with or without associated devicesMatching user foundUser record in UEM is updated with OIS-provisioned attributes. Associated devices are not modified
Inactive with or without associated devicesMatching user foundUser record in UEM is updated with OIS-provisioned attributes. Associated devices are not modified
Inactive with associated devicesNo match foundUser record remains in UEM but is not managed through OIS. Associated devices are not modified
Inactive without associated devicesNo match foundUser record is deleted from UEM once OIS migration phase is completed.

If you have Azure AD (Entra ID) enabled for Identity Services and users created in Workspace ONE UEM through Just-in-Time (JIT) provisioning during Windows OOBE enrollment, such users may lack the required attribute values for user matching with Omnissa Identity Services (OIS). As a result, such users will not be migrated to OIS provisioning and will remain unmanaged by OIS after the migration phase is complete.

Directory Services Configuration

When a Workspace ONE UEM tenant is integrated with Omnissa Identity Services, the Directory Services and SAML configurations under All Settings > System > Enterprise Integration > Directory Services are managed by OIS and can no longer be modified through the Workspace ONE UEM console. However, configuration of Azure AD integration settings, such as those for Windows OOBE and Conditional Access, remains unrestricted.

Advanced Settings

To configure the Advanced Settings, navigate to All Settings > System > Enterprise Integration > Directory Services > Advanced. The Advanced settings are available for tenants with the Directory type set to Omnissa Identity Service. The Advanced settings can be configured only at the OG where the OIS is integrated and allow the following configurations:

Password Grant

Password Grant protocol supports specific authentication flows listed in the following table. When this setting is enabled, the authentication flows are supported for OIS-provisioned users in addition to Basic users. If this setting is disabled, the authentication flows are applied to Basic users only.

PlatformFlows
iOS
  • Check out single-user staging or multi-user staging devices to Omnissa Identity Service and Basic users

  • DEP enrollment with Authentication OFF for Omnissa Identity Service and Basic users

  • DEP enrollment with Authentication ON and Custom Enrollment OFF for Omnissa Identity Service and Basic users

  • Hub and Browser enrollments to Basic users with Token authentication
Android
  • Check-out staging-enrolled devices to Omnissa Identity Service and Basic Users
macOS
  • Hub and Browser enrollments to Basic users with Token authentication

  • Check out staging-enrolled devices to Omnissa Identity Service and Basic users

  • DEP enrollment with Authentication OFF for Omnissa Identity Service and Basic users

  • DEP enrollment with Authentication ON and Custom Enrollment OFF for Omnissa Identity Service and Basic users

Windows
  • Silent enrollment

  • PPKG enrollment to Basic user
Linux
  • Enrollment using Token authentication

  • Check out staging-enrolled devices to Omnissa Identity Service and Basic users

Note: The Password Grant protocol is not recommended by the OAuth 2.0 Security Best Current Practices. Omnissa Identity Service supports it to maintain compatibility with certain legacy authentication flows that rely on password-based login. The use of Password Grant is strictly limited to these specific scenarios.

Username and password-based authentication for Basic users is supported in environments that have completed a Brownfield migration. This requires additional configuration in the Omnissa Identity Service. For more information, refer to the Migrating Directories to Omnissa Identity Service.

User Notification Settings

You can now configure whether end users receive an email notification when their accounts are provisioned in Workspace ONE UEM through Omnissa Identity Service (OIS). By default, a User Activation email is sent upon provisioning. The following notification options are available:

  • Message Type: None

    • No email notification is sent to users when their account is provisioned in Workspace ONE UEM.
  • Message Type: Email (Default)

    • User Activation notifications are sent through email when the user is provisioned in UEM.
    • You can also view or change the Message Template used for the User Activation notification.

Admin Account Provisioning using Omnissa Connect

Omnissa Identity Service does not manage administrator accounts or groups within Workspace ONE UEM. Administrator provisioning and role-based access control (RBAC) must instead be configured in Omnissa Connect by integrating your Identity Provider. For more information on integrating your Identity Provider for administrator access and provisioning, see the Omnissa Connect documentation.

Basic Administrator functionality is unaffected by OIS enablement or Omnissa Connect migration. Omnissa recommends using OAuth Clients for authenticating any integrations developed with the Workspace ONE UEM REST APIs.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…