Skip to main content

20 de agosto de 2026

Setting up Organization-Level Admin Access and Protection Policies

If you use Entra ID or another SAML-based IdP for single sign-on (SSO), work with your identity team to create the required user groups. Then, provide the group details to Omnissa Support through a Support Request so they can configure the groups for your Multi-Tenancy Admin Console.

Role-based groups (reused across all tenants) - One group for WS1 MTD Full Access Admins (required):

  • WS1 MTD Full Access Admins

Optionally, groups for other admin permission levels:

  • WS1 MTD Restricted Access Admins
  • WS1 MTD Read-Only Admins

Tenant and Multi-Tenancy access groups - One group for access to the Multi-Tenancy Admin Console:

  • WS1 MTD Multi-Tenancy Admins

One group per tenant that controls access to that tenant, for example:

  • WS1 MTD NA Admins
  • WS1 MTD EMEA Admins

Locating Entra ID Tenant IDs and Group Object IDs

  1. Sign in to the Entra ID admin center as an Entra ID Global Administrator.

  2. In the left sidebar, click Entra ID.

  3. To locate your Entra ID Tenant ID:

    a. Under Manage, click Properties.

    b. Scroll to Tenant ID and click the copy icon.

  4. To locate an Entra ID Group Object ID:

    a. Under Manage, click Groups.

    b. Click the name of the group from the list.

    c. Locate the Object Id field and click the copy icon.

About Multi-Tenancy Permissions with SSO

When using IdP groups to control access to your Multi-Tenancy environment, organization administrators must belong to two groups:

  1. A group for Multi-Tenancy administrators that grants access to the Multi-Tenancy Admin Console.
  2. A group that grants Full Access, Restricted Access, or Read-Only permissions.

An administrator for a single tenant belongs to two groups: one that defines their permission level and another that controls access to the specific tenant. Multi-Tenancy (Super) Administrators retain their assigned permission level across all tenants in the organization.

Setting up SSO Groups for Permission Levels

This is a one-time operation; once created, each group can be reused across all your tenants.

  1. In your IdP, create a WS1 MTD Full Access Admins group and note its Group Object ID.
  2. Add users who should have Full Access Admin permissions, regardless of which tenant they use.
  3. If you use Restricted Access or Read-Only permission levels, repeat the steps above for each level and note each Group Object ID.

Setting up SSO for Multi-Tenancy Administrators

  1. In your IdP, create a WS1 MTD Multi-Tenancy Administrators group and note its Group Object ID. This is your "Super Admins" group.

  2. Add users who should have access to the Multi-Tenancy Admin Console to this group.

  3. Add users who should have Full Access Admin permissions to the WS1 MTD Full Access Admins group created above. Note: This group may include the same members as the previous group, or you may restrict Full Access to a subset of those users.

  4. (Optional) Add any Multi-Tenancy Administrators who should have a different access level to the corresponding group.

  5. Raise a Support Request with Omnissa to configure the SSO integration, providing:

    FieldValue
    Entra ID tenant ID (required)Your Entra ID tenant ID
    Access to this organization (required)The Group Object ID for your WS1 MTD Multi-Tenancy Administrators group
    Full access (required)The Group Object ID for your WS1 MTD Full Access Admins group
    Restricted accessThe Group Object ID for your WS1 MTD Restricted Access Admins group
    Read onlyThe Group Object ID for your WS1 MTD Read-Only Admins group

    Important: Users must belong to both the Organization Access group and exactly one Role Permissions group. If they do not belong to both, they cannot sign in.

  6. Once Omnissa Support confirms the integration is created, grant the requested permissions from your IdP as directed.

Creating, Updating, and Deleting Device Policy Groups

Review device policy groups in the Tenants module, under the Device Policy Groups tab. This tab lists all device policy groups created either from the Multi-Tenancy Admin Console or locally on a child tenant and shows how many tenants use each group.

You can create, update, or delete groups, or view a group's protection settings by highlighting it in the list and clicking View Protections.

To create a new group:

  1. Click Create Group in the upper right corner.
  2. Enter a group Name and Description.
  3. Click Create Group.

To modify or delete an existing group, hover over the row and click the edit or delete icon.

Setting up Protection Policies

To set protection policies from the Multi-Tenancy Admin Console:

  1. Click Protections in the left navigation bar. The module opens to the Policies tab.
  2. Click the Manage settings for: dropdown and select the device group you want to configure.
  3. Configure Risk Level and Response settings as required by your organization. Response options include Alert device, Don't alert device, and, for Web & Content threats, Block and alert device or Block but don't alert.
  4. Click Save Changes.

Setting up Phishing and Content Protection

Phishing and Content Protection (PCP) helps organizations protect users, devices, and data from phishing and other content-based threats. It uses Secure DNS through Workspace ONE Tunnel to detect attempts by browsers or apps to access suspicious URLs. In the Workspace ONE Intelligent Hub app, this capability is presented to end users as Safe Browsing.

To set up PCP from the Multi-Tenancy Admin Console:

  1. Click Protections in the left navigation bar.
  2. Click the Manage settings for: dropdown and select the device policy group you want to configure.
  3. Click the Phishing and Content Protection tab.
  4. Activate the Enable Phishing and Content Protection toggle, and confirm Secure DNS is checked.
  5. Optionally, enable Make Phishing and Content Protection mandatory. This prevents end users from disabling Safe Browsing from the Intelligent Hub app.
  6. Add corporate or internal domains to the Secure DNS Corporate Domain Skip List so they bypass the MTD DNS resolver and instead follow the Device Traffic Rules configured in UEM.
  7. Add always-safe domains to Allowlisted content; PCP does not alert on these.
  8. Add always-blocked domains to Denylisted content; PCP always applies your configured response to these.
  9. Click Save Changes.
  10. Click Configure Content Policies (or select the Policies tab) to set Web Content Risk Level and Response settings.

See the Workspace ONE Mobile Threat Defense Console Admin Guide for more details.

Esta página foi útil?

Enviar feedback sobre este tópico

Este tópico foi útil?

Não inclua informações pessoais ou confidenciais.

Gerando o link…