The Omnissa Access service provides cloud-based authentication methods that you enable and configure from the console. These cloud-based authentication methods do not require a connector.
| Authentication Method | Description |
|---|---|
| Authenticator App (TOTP) | With this authentication method, any TOTP (RFC 6238) compliant app can be registered to provide Time-based One-Time passcodes to be used as a second authentication factor when multi-factor authentication is required. |
| Certificate Cloud Deployment | You can configure certificate-based authentication to allow clients to authenticate with certificates on their desktop and mobile devices or to use a smart card adapter for authentication. Certificate-based authentication is based on what the user has and what the person knows. An X.509 certificate uses the public key infrastructure standard to verify that a public key contained within the certificate belongs to the user. |
| Device Compliance with Workspace ONE UEM | Device Compliance with Workspace ONE UEM checks the compliance status of enrolled devices when users sign in. If a device goes out of compliance based on the rules configured in the Workspace ONE UEM console, users are blocked from signing in to applications or the user portal until the device is compliant again. |
| Duo Security (Cloud only) | Duo Security integrates with the Duo Web SDK to enable Duo as a second authentication factor when multi-factor authentication is required. |
| FIDO2 Authentication (Cloud only) | FIDO2 provides strong, phishing-resistant, passwordless authentication using cross-platform authenticators (such as USB keys) or platform authenticators (such as TouchID) that can be preregistered by an administrator or enrolled by users. |
| Mobile SSO for Android | Mobile SSO for Android is a certificate proxy authentication used for single sign-in authentication for Workspace ONE UEM-managed Android devices. A proxy service is set up between the Omnissa Access service and Workspace ONE UEM to retrieve the certificate from Workspace ONE UEM for authentication. |
| Mobile SSO for Apple (Cloud only) | Mobile SSO for Apple authentication is used for single sign-on on Workspace ONE UEM-managed iOS devices and replaces the KDC-based Mobile SSO for iOS method. It implements the certificate authentication method together with Apple SSO extension settings. |
| Mobile SSO for iOS | Mobile SSO for iOS authentication is used for single sign-on on Workspace ONE UEM-managed iOS devices. Mobile SSO for iOS authentication uses a Key Distribution Center (KDC) that is part of the Omnissa Access service. |
| Pass App (Cloud only) | Omnissa Pass, a multi-factor authentication (MFA) application, can be registered to enable secure login to corporate accounts and applications using TOTP codes or push notifications. |
| Password Local Directory | This authentication method is used for local directories created in the Omnissa Access console. |
| Password with Workspace ONE UEM | The AirWatch Cloud Connector can be integrated with the Omnissa Access service for user password authentication. You configure the Omnissa Access service to sync users from the Workspace ONE UEM directory. |
| Token Auth Adapter (Cloud only) | Token Auth Adapter is used for Day Zero onboarding, generating a one-time use access token or magic link to onboard pre-hires. |
| UEM Token (Cloud only) | UEM Token allows for the use of UEM device registration tokens to authenticate the user and device during device enrollment. |
| Verify (Intelligent Hub) (Cloud only) | Verify (Intelligent Hub) can be used as the second authentication method when multi-factor authentication (MFA) is required. It requires integration with Workspace ONE UEM, Hub Services, and a Workspace ONE UEM-managed device. |
| Risk Score Based Authentication (Cloud only) | Risk score-based authentication leverages the integration with Workspace ONE Intelligence to allow step-up authentication in policies based on User Risk Score or Login Risk Score. |
You configure the cloud-based authentication methods in the Integrations > Authentication Methods page in the Omnissa Access console. After an authentication method is configured, you associate it with an Omnissa Access built-in identity provider in the Integrations > Identity Providers page and create access policy rules in the Resources > Policies page.
Was deze pagina nuttig?