Skip to main content

August 11, 2026

Create a Conditional Access Policy Rule for iOS Mobile SSO Authentication

You must edit the Omnissa Access default access policy to add the iOS Mobile SSO authentication method that you configured to the rules.

When users attempt to sign in from their iOS devices, Omnissa Access service evaluates the default access policy rules to select the rule that applies to iOS Mobile SSO authentication. The authentication policy you create determines which authentication method Omnissa Access implements, based on the network range, device type, and user group.

Procedure

  1. In the Omnissa Access console Resources > Policies page, clickEdit Default Policy and then click Next.

  2. Add a new policy rule, click Add Policy Rule.

    OptionDescription
    If a user's network range isSelect the network range for this policy rule.
    and user accessing content fromSelect iOS.
    and user belongs to groupsIf this access rule is going to apply to specific groups, search for the groups in the search box. If you do not select a group, the access policy applies to all users.
    Then perform this actionSelect Authenticate using....
    then the user may authenticate usingSelect Mobile SSO (for iOS).
    If the preceding methods fails or is not applicable, thenConfigure additional fallback authentication methods. You can add Device Compliance to check the Workspace ONE UEM server for device compliance status when users sign in from their devices. See Configure Compliance Checking Rules in Omnissa Access.
    Re-authenticate afterSelect the length of the session, after which users must authenticate again.
  3. (Optional) In Advanced Properties, create a custom access denied error message that displays when user authentication fails. You can use up to 4000 characters, which are about 650 words. If you want to send users to another page, in the Custom Error Link URL text box, enter the URL link address. In the Custom Error Link text text box, enter the text to describe the custom error link. This text is the link. If you leave this text box blank, the word Continue displays as the link.

  4. Click Save.

  5. Drag and drop this rule before the Web Browser rule in the list of default access policy rules.

  6. Click Next to review the rules and then click Save.

What to do next

Go to the Workspace ONE UEM console and configure the iOS device profile and add the KDC server issuer certificate from Omnissa Access. See Configure Apple iOS Profile in Workspace ONE UEM Using Workspace ONE UEM Certificate Authority.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…