Skip to main content

March 5, 2025 Archived

Enabling Break-Glass URL Endpoint /SAAS/Login/0 in Omnissa Access (On Premises only)

When Omnissa Access system domain admin users cannot log in to the console from the Omnissa Access login page, use the break-glass URL endpoint /SAAS/login/0 hosted by the Omnissa Access appliance to log in and resolve the issue.

When the default access policy configuration locks out administrators, system domain admin users can use the break-glass URL endpoint, /SAAS/login/0, to access the Omnissa Access console. The /SAAS/login/0 URL authenticates system directory admins with a user name and password.

This login URL is deactivated in Omnissa Access service by default. You see an error message instead of the login page when you try to use https://{yourFQDN}/SAAS/login/0. All attempts to reach /SAAS/login/0 are logged to /opt/.../horizon/workspace/logs with the following message.

"Break-glass" login end-point called, access is disabled.

Enable /SAAS/login/0

Enable /SAAS/login/0 so that system domain admin users can log in to the Omnissa Access console.

Procedure

  1. SSH into the Omnissa Access appliance as the root user.

  2. Enter hznAdminTool configureBreakGlassLogin -enable -loginZero.

  3. Restart the service on the appliance. Enter service horizon-workspace restart.

    Repeat this process for all appliances in your environment.

Now Omnissa Access system domain admin users can log in using the following login URL.

https://{yourFQDN}/SAAS/login/0

Deactivate /SAAS/login/0

After you resolve the default access policy configuration issues, deactivate /SAAS/login/0 as a login option.

Procedure

  1. SSH into the Omnissa Access appliance as the root user.

  2. Enter hznAdminTool configureBreakGlassLogin -disable -loginZero.

  3. Restart the service on the appliance. Enter service horizon-workspace restart.

    Repeat this process for all appliances in your environment.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…