When you add and configure new SAML identity provider instances for your Omnissa Access deployment, you can provide high availability, support additional user authentication methods, and add flexibility in the way you manage the user authentication process based on user IP address ranges.
Prerequisites
Complete the following tasks before adding the third-party identity provider instance.
- Verify that the third-party instances are SAML 2.0 compliant and that the Omnissa Access service can reach the third-party instance.
- Coordinate the integration with the third-party identity provider. Depending on the identity provider, you might need to configure both settings in unison.
- Obtain the appropriate third-party metadata information to add when you configure the identity provider in the Omnissa Access console. The metadata information you obtain from the third-party instance is either the URL to the metadata or the actual metadata.
Procedure
-
In the Omnissa Access console Integration > Identity Providers page, click ADD and select SAML IDP.
-
Configure the following settings.
| Form Item | Description |
|---|---|
| Identity Provider Name | Enter a name for this identity provider instance. |
| SAML Metadata |
Add the third-party identity provider XML-based metadata document to establish trust with the identity provider.
|
| Just-in-Time User Provisioning | Just-in-Time provisioning users are created and updated dynamically when they log in, based on SAML assertions sent by the identity provider. SeeHow Just-in-Time User Provisioning Works in Workspace Access. If you enable JIT, enter the directory and domain name for the JIT directory. |
| Users | Select the directories that include the users who can authenticate using this identity provider. |
| Network | The existing network ranges configured in the service are listed. Select the network ranges for the users based on their IP addresses, that you want to direct to this identity provider instance for authentication. |
| Authentication Method |
Enter the authentication method name to associate with this third-party identity provider. You can enter multiple authentication methods to associate with the third-party identity provider. Give each authentication method a friendly name that identifies the auth method. You select the authentication method name in the access policy to configure the rules for the third party IDP authentication method. Map the authentication method name with the SAML authentication context that is sent by the third-party identity provider in the SAML response. In the drop-down menu, select a SAML authentication context class string from the list of commonly used strings, or you can enter a custom string. |
| Single Sign-Out Configuration |
When users sign in to Workspace ONE from a third-party identity provider (IDP), two sessions are opened, one on the third-party identity provider, and the second on the identity manager service provider for Workspace ONE. The lifetime of those sessions is managed independently. When users sign out of Workspace ONE, the Workspace ONE session is closed, but the third-party IDP session might still be open. Based on your security requirements, you can enable single sign-out and configure single sign-out to sign out of both sessions, or you might keep the third-party IDP session intact. Configuration Option 1
|
| SAML Signing Certificate | Click Service Provider (SP) Metadata to see URL to Omnissa Access SAML service provider metadata URL. Copy and save the URL. This URL is configured when you edit the SAML assertion in the third-party identity provider to map Omnissa Access users. |
| IdP Hostname | If the Hostname text box displays, enter the host name where the identity provider is redirected to for authentication. If you are using a non-standard port other than 443, you can set the host name as Hostname:Port. For example, myco.example.com:8443. |
- Click Add.
What to do next
- In the console, go to the Resources > Policies page and edit the default access policy to add a policy rule to select the SAML authentication method name as the authentication method to use. See Managing Access Policies in the Omnissa Access Service.
- Edit the third-party identity provider's configuration to add the SAML Signing Certificate URL that you saved.
Was this page helpful?