Skip to main content

August 11, 2026

Configure Omnissa Access for Single Sign-On Authentication from Workspace ONE UEM Devices

When Workspace ONE UEM and Omnissa Access services are integrated, users from Workspace ONE UEM enrolled devices can log in to their Workspace ONE Intelligent Hub app to access their enabled apps without entering multiple passwords.

What to Expect from this Section

The topics that follow in this section guide you through configuring single sign-on (SSO) authentication for users accessing applications from Workspace ONE UEM-enrolled devices. When properly configured, users can access their Workspace ONE Intelligent Hub app and enterprise resources with minimal authentication prompts, creating a seamless and secure user experience.

The workflows in this section establish the foundational authentication and access control framework that connects Workspace ONE UEM with Omnissa Access. You configure how users are synchronized between systems, set up authentication methods, and define access policies that determine when and how users can access their applications.

This section covers the following major configuration areas:

  • User Synchronization: Establishing identity data flows between Workspace ONE UEM and Omnissa Access directories, ensuring users can authenticate against the appropriate identity sources.

  • Authentication Methods: - Configuring password-based authentication through AirWatch Cloud Connector and setting up built-in identity providers to validate user credentials.

  • Device Compliance Integration (Optional): - Enabling verification that managed devices meet your security compliance policies before granting access to applications.

  • Access Policy Configuration: - Creating policy rules that control how users authenticate and access applications based on network location, device type, and compliance status.

Why These Steps Matter

  • Seamless User Experience: Single sign-on reduces authentication friction. After initial sign-in, users access their applications without repeatedly entering credentials, improving productivity while maintaining security.

  • Unified Identity Management: By synchronizing users from Workspace ONE UEM to Omnissa Access, you create a single source of truth for user identities, simplifying administration and ensuring consistent access across your environment.

  • Security Through Compliance: Optional compliance checking ensures that only devices meeting your security standards can access corporate resources. If a device becomes compromised or falls out of compliance, access is automatically blocked until the device is remediated.

  • Flexible Access Control: Access policies give you granular control over authentication requirements based on contextual factors like network location, device platform, and compliance status. This enables you to balance security with user experience based on risk.

  • Foundation for Advanced Scenarios: The configurations in this section establish the groundwork needed for advanced authentication scenarios, such as mobile SSO for iOS devices covered in later sections.

Configuration Workflow Summary

The procedures in this section follow a logical sequence, with some steps being required and others conditional based on your specific deployment needs:

Phase 1: User Synchronization (Required)

Choose Your User Sync Approach

Before users can authenticate, you must synchronize user accounts from Workspace ONE UEM to Omnissa Access. Your approach depends on how user accounts are managed in Workspace ONE UEM:

  • Syncing Directory-Based Accounts: Use this workflow when your Workspace ONE UEM deployment integrates with Active Directory or OpenLDAP. This is the most common enterprise scenario and includes:

    • Mapping user attributes between UEM and Access directories.
    • Configuring directory synchronization.
    • Managing group memberships.
  • Syncing Workspace ONE UEM Local Basic User Accounts to Omnissa Access: Use this workflow when users are created locally in Workspace ONE UEM without directory integration. This approach:

    • Syncs standalone user accounts to Omnissa Access.
    • Supports environments without directory infrastructure.
    • Enables basic authentication scenarios.

Important: Choose only one sync approach based on your UEM user account type. Do not sync the same users through both methods, as this can cause conflicts and authentication failures.

Phase 2: Authentication Configuration (Required)

  • Implementing Authentication with AirWatch Cloud Connector: Configure the AirWatch Cloud Connector to enable password authentication. This component:

    • Bridges authentication requests between Omnissa Access and your identity sources.
    • Supports Active Directory credential validation.
    • Enables just-in-time user provisioning for first-time sign-ins.
  • Configure Built-in Identity Providers in Omnissa Access: Associate authentication methods with built-in identity providers to establish how Omnissa Access validates user credentials. This includes:

    • Linking password authentication methods to identity providers
    • Configuring authentication method priority
    • Setting session timeout parameters

Phase 3: Device Compliance Integration (Optional - Security Enhancement)

  • When to Enable Compliance Checking: If your security requirements mandate that only compliant devices can access corporate resources, complete these optional procedures:

    Note: Compliance checking requires that compliance policies are already configured in Workspace ONE UEM. If you skip these procedures, users can authenticate from any enrolled device regardless of compliance status.

Phase 4: Access Policy Configuration (Required)

Important Notes and Considerations

  • User Sync Conflicts: Ensure users and groups synced from Workspace ONE UEM to Omnissa Access are unique. Do not sync the same users through both UEM sync and a separate Omnissa Access directory connection to the same source (Active Directory or LDAP), as duplicate users with shared external IDs can cause synchronization failures.

  • Third-Party Identity Providers: While this section focuses on using Workspace ONE UEM as the identity source, you can alternatively use third-party identity providers like Okta or Ping Federation for SSO. See Providing Access to Third-Party Managed Applications in Omnissa Access for details on those scenarios.

  • AirWatch Cloud Connector Prerequisites: The AirWatch Cloud Connector must be installed and configured in Workspace ONE UEM before implementing authentication. Refer to the AirWatch Cloud Connector Installation Process for installation instructions.

  • Compliance Checking Availability: The Device Compliance authentication method requires connectivity to Workspace ONE UEM. It will not function during planned maintenance windows or unplanned outages of the UEM service.

  • Configuration Change Impact: When Workspace ONE UEM service details change (such as URLs, API keys, or certificates), you must update the corresponding configuration in Omnissa Access to prevent authentication failures.

What to do Next

After completing the procedures in this section, you will have established SSO authentication for users on Workspace ONE UEM-managed devices. Users can sign in to Workspace ONE Intelligent Hub and access their entitled applications with a streamlined authentication experience.

  • For iOS Mobile SSO: If you need to implement certificate-based Kerberos authentication for iOS devices, proceed to the Implementing Mobile Single Sign-On Authentication for Workspace ONE UEM-Managed iOS Devices section after completing the configurations described here.

  • For Ongoing Management: Periodically review your access policies and compliance rules to ensure that they align with evolving security requirements and user needs. Monitor authentication logs to identify and address any access issues users may experience.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…