Skip to main content

August 27, 2026

Configure Omnissa Access Policy Rule for Mobile SSO (for Apple)

You create a rule in the Omnissa Access default access policy so that users accessing the Workspace ONE Intelligent Hub app or Hub portal from an iOS device are authenticated using Mobile SSO (for Apple).

The default access policy is configured to allow access to all network ranges from all device types. The session timeout is eight hours. When you enable a new authentication method, you must edit the default policy to add the authentication method to the policy rules. For more information about Omnissa Access default access policy, see Managing the Default Access Policy in Omnissa Access.

When you create this rule, you can chain Device Compliance to the rule to measure the health of the managed device, resulting in pass or fail based on Workspace ONE UEM defined criteria. See Configure Compliance Checking Rules in Omnissa Access.

Prerequisites

Mobile SSO (for Apple) authentication method configured and added to the built-in identity provider.

Network ranges of IP addresses to use created and assigned to the built-in identity provider.

Procedure

  1. In the Omnissa Access console Resources > Policies page, click Edit Default Policy.

  2. Click Next to open the Configuration page.

  3. Add a policy rule, click Add Policy Rule.

    Option Description
    If a user's network range is Select the network range to use.
    and user accessing content from Select the device type iOS.
    and user belongs to groups This policy rule applies to all users. Leave the text box empty. By default, if no group is selected, the access policy rule applies to all users.
    Then perform this action Select Authenticate using...
    then the user may authenticate using Select the authentication method Mobile SSO (for Apple). To require users to authenticate through two authentication methods, click + and in the drop-down menu select a second authentication method. This is where you can add Device Compliance to the rule.
    If the preceding method fails or is not applicable, then Optional
    Re-authenticate after Select the length of the session, after which users must authenticate again. The default is 8 hours.
  4. (Optional) In Advanced Properties, create a custom access denied error message that displays when user authentication fails. You can use up to 4000 characters, which are about 650 words. If you want to send users to another page, in the Custom Error Link URL text box, enter the URL link address. In the Custom Error Link text box, enter the text to describe the custom error link. This text is the link. If you leave this text box blank, the word Continue displays as the link.

  5. Click Next to review the rules and then click Save.

  6. Review the order of the rules in the default access policy and reorder the list if required. Place the Mobile SSO (for Apple) rule before the Web Browser rule.

    Authentication methods are applied in the order they are listed in the rule.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…