Skip to main content

July 28, 2026

Managing Groups in Omnissa Access

In the Omnissa Access service, groups are identified uniquely by both the group name and domain.

When new groups are added to the directory from Active Directory, the group names are synced to the directory. Users that are members of the group can sync to the directory under the following conditions.

  • The group is entitled to an application in Workspace ONE.
  • The group name is added to an access policy.
  • The users in the group are manually synced from the Group > Users profile page.

Note: If some users need to authenticate before a group syncs to the directory, you can add the individual user to the directory's Sync Settings > Users page.

The Omnissa Access service supports having multiple groups with the same name in different Active Directory domains. Group names must be unique within a domain. For example, you can have a group called ALL_USERS in the domain eng.example.com and another group called ALL_USERS in the domain sales.example.com.

During directory sync, groups that have the same name but different domains are synced successfully. If there is a group name conflict within a domain, the first group is synced and an error occurs for subsequent groups with the same name.

In the Omnissa Access console Accounts > User Groups page, Active Directory groups are listed by their group name and domain. In this list, you can distinguish between groups that have the same name. Groups that are created locally in the Omnissa Access service are listed by the group name. The domain is listed as Local Users.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…