In the Omnissa Access console, you can enable and configure Google Chrome Enterprise Device Signals Adapter as a secondary authentication method to support authentication for managed and bring your own device (BYOD) scenarios. You configure the Google Chrome Enterprise Device Signals adapter in the Omnissa Access console to retrieve device posture information from managed devices and managed profiles on unmanaged devices. Users can sign in to Omnissa Access from managed Chrome browsers, managed Chrome profiles, and managed Chrome OS devices.
For information about Google Chrome Enterprise Device Trust integrations, see this Google Chrome help center article.
The Chrome Enterprise authentication is based on Google Chrome Enterprise device signal attribute settings that you enable when you configure Google Chrome Enterprise Device Signals Adapter in the Access console. To communicate with Google, you integrate Omnissa Access with the Chrome Enterprise Device Trust integration in the Google Admin console. After the integration is set up, you configure access policy rules in the Omnissa Access console.
When users use the Chrome browser to sign in from a macOS, Windows, or ChromeOS device, after their initial credential is authenticated, the second-factor authentication through Google checks the device security status based on the device signal attribute settings you configured. Omnissa Access retrieves the signal status from the Chrome Enterprise integration.
Google Chrome Enterprise Device Signals adapter authentication is available when a user runs the Chrome browser with a managed profile on MacOS, Windows, and ChromeOS devices.
Prerequisites
-
Omnissa Access SaaS Tenant
-
Chrome Enterprise Core or ChromeOS Enterprise/Edu Upgrade
Note: Google Chrome Enterprise Device Trust Connector requirements.
- Chrome Enterprise Device Trust integration is not supported for incognito mode.
- Signals from ChromeOS require the devices to be enrolled in device management in the Google Admin console.
User devices:
- Chrome browser 109 or later
- ChromeOS M108 or later
- Managed Chrome Browser profile on Windows and MacOS devices
Set up Google Chrome Enterprise Device Signals Adapter Authentication in Omnissa Access
Procedure
-
In the Omnissa Access console Integrations > Authentication Methods page, select Google Chrome Enterprise Device Signals.
-
Click CONFIGURE and configure the authentication settings.
Option Description Enable Google Chrome Enterprise Device Signals Adapter Set this option to Yes to enable the adapter. URLs matcher to trigger the Google inline flow Copy and save the URL. You require this value to configure the Device Trust Connector in the Google Admin console.
Important: If multiple URLs are listed, make sure that you copy all of them and configure them in the Device Trust Connector. As part of the upcoming URL migration changes described in KB article 6001062, if your Access tenant FQDN falls in the list of environments under Category 2 - Certificate Branding and URL Change, two URLs appear in the URLs matcher field, one that uses the existing Access FQDN and one that uses the new Access FQDN. The new FQDN has been made available for this use case ahead of the migration for your convenience. Do not use it for any other use cases. The migration timeline will be communicated to all customers through the KB article.IDP Service Account email Copy and save the tenant IDP Service Account email. This setting is configured in the Omnissa connectors page in the Google Admin console. Allow access if not a managed Chrome browser This setting is deactivated by default to prevent access from non-managed Chrome browsers. Activating this setting is not recommended. If you want to support non-managed Chrome browsers, configure the access policy with an alternative authentication method that performs strong validation as the fallback authentication. Verify device's disk encryption status Enable this setting if the device disk must be encrypted. Select the setting that is required to access apps from a device. When you select a setting with multiple options, validation operates with an OR logic, allowing any of the chosen values. - Encrypted. The main disk is encrypted. If you select this option, the check verifies that the main disk must be encrypted. Removable disks are not evaluated for disk encryption.
- Encrypted | Unspecified. The main disk is encrypted or Chrome did not send the signal.
- Encrypted | Unknown. The main disk is encrypted or Chrome could not evaluate the encryption state.
- Encrypted | Unspecified | Unknown. The main disk is encrypted, Chrome did not send the signal, or Chrome could not evaluate the encryption state.
Verify device's firewall status Enable this setting if a firewall must be enabled on the device. Select the setting that is required to access apps from a device. When you select a setting with multiple options, if any one of the options in the value is valid, the entire validation is considered successful. - Enabled. The firewall is enabled.
- Enabled | Unspecified. The firewall is enabled or Chrome did not send the signal.
- Enabled | Unknown. The firewall is enabled or Chrome was unable to determine the status of the operating system's firewall.
- Enabled | Unspecified | Unknown. The firewall is enabled, Chrome did not send the signal, or Chrome was unable to determine the status of the operating system's firewall.
Verify device's screen lock status Enable this setting to require devices to use a password to unlock the device. When you select a setting with multiple options, if any one of the options in the value is valid, the entire validation is considered successful. - Enabled. Screen lock is enabled.
- Enabled | Unspecified. Screen lock is enabled or Chrome did not send the signal.
- Enabled | Unknown. Screen lock is enabled or Chrome was unable to determine the screen lock state.
- Enabled | Unspecified | Unknown. Screen lock is enabled, Chrome did not send the signal, or Chrome was unable to determine the screen lock state.

-
Click SAVE.
Copy and save the URL matcher and the IDP Service Account email settings. Then, to integrate with the Chrome Enterprise Device Trust connector, add these settings to the Omnissa connectors page in the Google Admin console.
-
Associate the Google Chrome Enterprise Device Signals authentication method to an Omnissa Access identity provider. Go to the Integrations > Identity Providers page in the Omnissa Access console, select the identity provider and in the Authentication Methods section, enable Google Chrome Enterprise Device Signals. Click SAVE.
Integrate with the Chrome Device Trust Connector
The Device Trust connector is a Google Chrome service that verifies the security posture of devices that are using the Chrome browser to access apps through Omnissa Access.
-
Sign in to your Google Admin console as an administrator.
-
Go to Devices > Chrome > Connectors and click New provider configuration.
-
Select Omnissa in the device trust connector provider list and click Set up.
-
In configuration name enter a unique name for your configuration.
-
In the Provider configuration section, enter the URL pattern and the Service account information you saved when you set up the Google Device Signals Adapter Authentication in Omnissa Access.
-
Click Add configuration.
-
Apply this provider configuration to the Google organization unit that includes the users who use the Google Chrome Enterprise Device Signal Adapter for authentication.
- Select the organizational unit listed on the tree UI widget.
- Scroll down to Device trust connector and select the radio button to apply the appropriate configuration.
-
Click Save.
Next, add a rule to the access policy in the Omnissa Access console.
Add Google Chrome Enterprise Device Signals as a Secondary Authentication Method to Omnissa Access Policies
After you set up Omnissa Access as a Chrome Trust Connector in the Google Admin console, you create access policy rules in Omnissa Access to use Google Chrome Enterprise Device Signals for second factor authentication. Update the default access policy and other policies as needed.
Procedure
-
In the Omnissa Access console Resources > Policies page, add a policy or edit an existing policy.
-
Click Next to open the Configuration page.
-
Select the rule to edit or click Add Policy Rule to create a new rule.
Option Description If a user's network range is Select the network range. and the user accessing content from Select the device type that this rule manages, either Windows 10+. macOS, or Chrome OS. and user belongs to groups Select the group that this rule applies to. If you do not add a group to the rule, the rule applies to all users. Then perform this action Select Authenticate using.... then the user may authenticate using Select the user authentication method to apply first.
To require users to select Google Chrome Enterprise Device Signals as the second authentication method, click ADD AUTHENTICATION and in the drop-down menu select Google Chrome Enterprise Device Signals and click ADD. -
To save your changes, click Next and click Save.
When users sign in, they first authenticate using their primary method. Once approved, the secondary authentication process through Google checks the device security status and shares the status with Omnissa Access. If the device is not in compliance, the authentication fails. The Omnissa Access Audit Events report logs the success or failure of the authentication, including which signal failed.
Was deze pagina nuttig?