Skip to main content

April 13, 2026

Add AD FS as an Identity Provider in the Service

To configure the AD FS integration, you must add AD FS as an identity provider instance in Omnissa Access.

Prerequisites

  • Download the federation metadata file for the AD FS server by navigating to the URL: https://ADFSdomain/FederationMetadata/2007-06/FederationMetadata.xml where ADFSdomain is replaced with the fully qualified domain name for your AD FS server.
  • In the Omnissa Access console, configure the access policies that you want to use for the AD FS identity provider instance. For information about configuring access policies, see the Managing Omnissa Access User Authentication Methods guide.

Procedure

  1. Log in to the Omnissa Access console with full administrator privileges.

  2. In the Integrations tab, select Identity Providers.

    Screenshot of the Manage tab showing the Add Identity Providers option list

  3. Click ADD and select SAML IDP.

  4. Modify the configuration settings.

    SettingDescription
    Identity Provider NameEnter a short descriptive name for the AD FS identity provider instance.
    SAML Metadata
    1. To establish trust with AD FS, add the federation metadata here. In the text box, copy and paste the contents of the AD FS federation metadata file that you obtained previously.
    2. Click Process IdP Metadata. The Name ID format mappings are automatically imported from the AD FS metadata. Screenshot of the SAProcess IdP Metadata field showing the imported AD FS Name ID format mappings
    3. (Optional) Configure additional AD FS Name ID formats and map them to user values in the Omnissa Access service.
    Just-in-Time User ProvisioningDo not enable.
    UsersSelect the Omnissa Access directories of the users that can authenticate using AD FS.
    NetworkThe existing network ranges configured in the service are listed. Select the network ranges for the users, based on their IP addresses, that you want to direct to AD FS for authentication.
    Authentication Methods To add an authentication method that you want AD FS to use, click the green plus sign and enter the name of the method. Then select the SAML authentication context class that supports the method. Configure the following authentication methods.
    • Forms-based authentication: For SAML Context, select urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport.
    • Kerberos-based authentication: For SAML Context, select urn:federation:authentication:windows
    Screenshot of the Authentication Methods field showing the configured methods
    Single Sign-Out ConfigurationDo not enable. Single sign-out configuration is not required for the AD FS identity provider instance.
    SAML Signing CertificateTo display the Omnissa Access service provider metadata in a browser window, click Service Provider (SP) Metadata. Copy and save the URL. You need this URL later when you configure the Federation Service Properties in AD FS.
  5. Click Add.

What to do next

Add AD FS Authentication Methods to Access Policy Rules

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…