You can move users who currently use Omnissa Access Mobile SSO (for iOS) for authentication to Workspace ONE Intelligent Hub to use Omnissa Access Mobile SSO (for Apple) for authentication.
The process to migrate to Mobile SSO (for Apple) is as follows.
-
Configure the Mobile SSO (for Apple) authentication method in the Omnissa Access console.
-
Update the Omnissa Access default access policy rule for iOS devices to make Mobile SSO (for Apple) the fallback authentication method.
-
Update the Workspace ONE UEM MDM profile to replace the Single Sign-on profile with the Apple SSO Extension profile.
-
Make sure that users have the latest Hub app with the updated MDM profile installed. Users can begin to migrate at this point. The individual migration downtime is typically a few seconds.
-
After all devices are migrated, deactivate the Mobile SSO (for iOS) authentication method from the Omnissa Access console and update the access policy to remove Mobile SSO (for iOS) from the rule.
Update the MDM profile to replace the Single Sign-on profile with the Apple SSO Extension profile
You enable the Apple single sign-on extension setting in the Workspace ONE UEM Apple iOS device profile to provide users with single sign-on to apps and websites without having to re-enter their credentials. The Apple SSO Extension handles authentication for users. When users enroll their Apple IOS devices in Workspace ONE UEM MDM, the extension profile is added to the app installer and the certificate is copied to the local certificate store on the Apple device. Clients can then authenticate with the certificate for single sign-on.
-
In the Workspace ONE UEM console, select the desired organization group and navigate to DEVICES > Profile & Resources > Profiles.
-
Select the iOS Mobile SSO device profile to edit.
-
You do not need to change the certificate setting if the device profile is configured with a certificate that can be used with Mobile SSO (for Apple) authentication. The certificate must include the SSL Client Authentication key usage value (EKU). This is the enhanced key usage (EKU) extension that contains the OIDs: PKI Peer Auth and PKI Server Auth.
If you change the certificate in the device profile, you can configure either a SCEP or a Credentials certificate in the profile. See Configure Workspace ONE UEM to use Omnissa Access Mobile SSO (for Apple) Authentication for Managed iOS Devices (Cloud only).
-
Delete the Single Sign-on section that is configured with the Mobile SSO (for iOS) configuration
-
Configure SSO Extension to enable single sign-on to Workspace ONE Intelligent Hub app without requiring authentication into each app.
Click +ADD.
Extension Type Select WS1 Access. Extension Identifier This value is populated with the Omnissa Access identifier. Type This value is populated with Credential. Additional Settings - Allowed Bundle IDs If the SSO extension is to be limited to specific app bundle IDs, click ADD and enter the app bundle IDs. -
Click Save and Publish.
Configure Mobile SSO (for Apple) Authentication Method
To set up Mobile SSO (for Apple) authentication in Omnissa Access, you configure the Mobile SSO (for Apple) certificate-based authentication settings in the Omnissa Access console and upload the certificate file that was configured in the Workspace ONE UEM device profile for Apple iOS. You then configure the built-in identity provider with the users, network ranges, and the Mobile SSO (for Apple) authentication method for single sign-on.
See Configuring Mobile SSO (for Apple) Authentication in Omnissa Access (Cloud only).
Update the Omnissa Access Default Access Policy
You edit the existing Mobile SSO (for iOS) default access policy rule to add Mobile SSO (for Apple) as the fallback authentication method.
To understand how access policies work in Omnissa Access, see Managing Access Policies in the Omnissa Access Service and Configure Omnissa Access Policy Rule for Mobile SSO (for Apple) (Cloud only).
Procedure
-
In the Omnissa Access console Resources > Policies page, click Edit Default Policy.
-
Click Next to open the Configuration page.
-
Edit the policy that has Mobile SSO (iOS) authentication configured as the then the user may authenticate using value. In the If the preceding method fails or is not applicable, then section, select the fallback method to be Mobile SSO (for Apple).
If the access policy rule for Mobile SSO (for iOS) was configured to chain with another authentication method, chain the same authentication method in the Mobile SSO (for Apple) fallback setting. For example, if the Mobile SSO (for iOS) rule also included Device Compliance as the chained authentication method, you add Device Compliance in the Mobile SSO (for Apple) setting.
-
Click SAVE.
Was this page helpful?