Skip to main content

August 11, 2026

Using a Key Distribution Center for Authentication from iOS Devices When Authenticating with Omnissa Access

For iOS device authentication, you integrate the service with Kerberos. Kerberos authentication provides users, who are successfully signed in to their domain, access to their application portal without additional credential prompts. The iOS device authentication method uses a Key Distribution Center (KDC) without the use of a connector or a third-party system.

Omnissa Access Cloud tenants do not need to manage or configure the KDC.

For on premises deployments, use the Built-in KDC. The built-in KDC requires initializing KDC on the appliance and creating public DNS entries to allow the Kerberos clients to find the KDC. For more information about enabling the built-in KDC, see the Using the Built-in KDC for Omnissa Access article in the latest Omnissa Access on premise installation guide.

To issue the certificates used for Kerberos authentication on iOS devices, you can use one of two certificate authority options:

  • Workspace ONE UEM Certificate Authority: Use the Workspace ONE UEM Certificate Authority, which follows the Simple Certificate Enrollment Protocol (SCEP), to issue certificates to managed iOS 9 or later devices.
  • Active Directory Certificate Authority: Set up a trust relationship between Active Directory and Workspace ONE UEM, and configure the Active Directory Certificate Authority and certificate template for Kerberos certificate distribution.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…