Skip to main content

September 22, 2025 Archived

Create an Access Policy in Omnissa Access for Windows 10 Device Enrollment

When you create an application-specific access policy for Office 365 in the Omnissa Access console, to restrict access to Office 365 from only managed Windows 10 devices create a rule using the Windows 10 Enrollment as a device type.

You create or update a second access policy rule that uses Windows 10 as a device type. The rule is configured to authenticates using the Certificate (Cloud Deployment) method with no fallback configured. When users try to access Office 365, if the device is unmanaged, the Office 365 app launch fails, and the Windows 10 Enrollment rule is applied to enroll and manage the device. Uses trying to access Office 365 with a managed device are authenticated based on the second access policy rule.

Prerequisites

  • Office 365 configured with the primary identity provider. The primary identity provider can be Omnissa Access, Okta, or ADFS. Omnissa Access must be configured as the secondary identity provider when Okta or ADFS is the primary identity provider.
  • Device enrollment is managed through the Windows 10 Out-of-Box experience (OOBE) or when joining the Azure Active Directory domain.
  • Authentication methods configured and enabled for the identity provider.
  • Office 365 app added to the Hub catalog.

Procedure

  1. In the Omnissa Access console Resources > Policies page, click Add Policy.

  2. Add a policy name and description in the respective text boxes.

  3. In the Applies To section, select the applications that require restricted access.

  4. Click Next.

  5. Click Add Policy Rule to add a rule.

    OptionDescription
    If a user's network range isSelect a network range.
    and user accessing content fromSelect Windows 10 Enrollment as the device type.
    and user belongs to groupsIf this access rule is going to apply to specific groups, search for the groups in the search box. If no group is selected, the access policy rule applies to all users.
    Then perform this actionSelect Authenticate using....
    then the user may authenticate usingSelect the authentication method to use. Important: Do not use Certificate (Cloud Deployment). Devices do not have the proper certificate before the device is enrolled. To require users to authenticate through two authentication methods, click + and in the drop-down menu select a second authentication method.
    If the preceding methods fails or is not applicable, thenConfigure a fallback authentication method, if necessary.
    Re-authenticate afterSelect the length of the session, after which users must authenticate again.
  6. Click Save.

What to do next

You can now update the access policy configured for Windows 10 device type. The authentication method selected continues to be Certificate (Cloud deployment) but remove any fallback authentication methods that were configured.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…