In the Omnissa Access console, you can configure Microsoft Entra ID MFA as the secondary authentication method for any supported primary authentication methods in the Omnissa Access service.
You configure Microsoft Entra ID as an identity provider (IDP) in the Omnissa Access console and then you configure an Omnissa Access authentication access policy rule that makes Microsoft Entra ID MFA the secondary authentication method in the rule.
You then configure an Entra conditional access policy in the Microsoft Entra admin center to apply the access controls to manage how the secondary authentication is implemented after Omnissa Access primary authentication is completed.
Users use their existing authentication method to log in to Omnissa Access and are then prompted for the Microsoft Entra ID MFA without an additional Entra ID login prompt.
Configure Microsoft Entra ID as a Third-Party Identity Provider Instance in Omnissa Access
Prerequisites
-
Access to the Entra ID admin center to create the enterprise application for the SAML integration
Create the application before you start.
-
Entra Premium P1 license for MFA and setting up conditional access policies
Procedure
-
Log in to the Omnissa Access console as the system administrator.
-
Select Integrations > Identity Providers.
-
Click Add and select SAML IDP.
-
In the Add SAML IDP page, configure the following settings.
Option Description General Information Identity Provider Name - Enter a name for the new identity provider, such as Entra SAML IdP.
Identity Provider Type - Select Microsoft Entra IDBinding Protocol Select HTTP Redirect .
Note: This field appears after you enter the metadata URL in the SAML Metadata section and click Process IdP Metadata.SAML Metadata - In the Identity Provider Metadata text box, enter the metadata from the Microsoft Entra integration app.
- Click Process IdP Metadata.
- Select the Send Subject in SAML Request (when available) check box.
Authentication Method - In the Authentication Method text box, enter the Microsoft Entra MFA authentication method name to associate as the third-party identity provider.
- In the SAML Context text box, map to
"urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified" - In the Description text box, compose a statement to help users identify Microsoft Entra MFA as the authentication method. The text in the **Description** text box is displayed in the Select Authentication login prompt page when the entraMFA authentication method is an authentication choice option in an access policy rule.
-
Click SAVE.
Add Microsoft Entra ID as the Secondary Authentication Method to Access Policies in Omnissa Access
After you set up Microsoft Entra ID as a SAML identity provider in Omnissa Access, create access policy rules in Omnissa Access to use Microsoft Entra ID for second factor authentication. Update the default access policy, and other policies as needed.
Procedure
-
In the Omnissa Access console Resources > Policies page, add a policy or edit an existing policy.
-
Click Next to open the Configuration page.
-
Select the rule to edit or click Add Policy Rule to create a new rule.
Option Description If a user's network range is Select the network range. and the user accessing content from Select the device type that this rule manages. and user belongs to groups Select the group that this rule applies to. Then perform this action Select Authenticate using.... then the user may authenticate using Select the authentication method to apply first.
To require users to select Entra ID MFA as the second authentication method, click ADD AUTHENTICATION and in the drop-down menu select entraMFA and click ADD. -
Save your changes.
Configure Passwordless Sign-in and Conditional Access Policy in Microsoft Entra Admin Center
After configuring Entra ID MFA as the secondary authentication method in Omnissa Access, enable passwordless sign-in and configure a conditional access policy in the Microsoft Entra admin center. The Entra conditional access policy will be enforced after Omnissa Access primary authentication is completed.
In the Microsoft Entra admin center:
-
Enable passwordless sign-in with Microsoft Authenticator. See Enable passwordless sign-in with Microsoft Authenticator.
-
Set the conditional access policy for the SAML integration app.
a. Create a Conditional Access policy with the "Require authentication strength" control.
b. Select "Passwordless MFA strength".
For more information, see Conditional Access authentication strength.
Was this page helpful?