Omnissa Pass is a multi-factor authentication (MFA) application that enables secure login to corporate accounts and applications. The solution provides a secure, user-friendly, and scalable method for authenticating resources delivered through Omnissa Access. Key features include:
- Time-based one-time passcodes (TOTP) generation for secure authentications.
- Device security policies enforcement including device attestation checks, security lock, and compromise detections.
- Login approvals using push notifications.
- Registration of up to three Omnissa Pass devices per user account in a single Omnissa Access tenant.
- Administrator reporting and monitoring of Omnissa Pass app registrations.
- Protections against phishing and other MFA attacks.
- Support for usage as first-factor, second-factor, and step-up authentication.
- First Factor Authentication: You can use Omnissa Pass as a first factor authenticator with alternative authentication methods, such as certificates. You can also use Omnissa Pass with magic link, which allows end users to authenticate without a password. This approach is commonly used to securely onboard employees who do not yet have credentials. See Enable Magic Link Option for Use with Auth Token Authentication in Omnissa Access for Day Zero Onboarding
- Second Factor Authentication: You can use Omnissa Pass as a second factor authenticator behind the default login method, such as username and password.
- Step-Up Second Factor Authentication: You can also use Omnissa Pass as a second factor authenticator behind a method such as username and password authentication for certification, but with a policy in place for a subset of applications that require Omnissa Pass as an additional authentication step.
Some Omnissa Pass features are available by default to all Omnissa Access customers, while additional capabilities are available as an add-on purchase.
Requirements
-
Omnissa Access Cloud, or Omnissa Access on-premises version 26.07 or later
Note: Only TOTP authentication is supported for on-premises Omnissa Access deployments. Push notifications, and any settings that apply to push notifications, are not available. -
For on-premises Omnissa Access deployments, the Omnissa Access service must be publicly reachable over the Internet so that the user devices registering and using the Pass app can connect to it. Pass app authentication is not available for environments that do not have connectivity to the Internet.
-
For device requirements, see the Omnissa Pass Release Notes:
Configure the Omnissa Pass Auth Adapter and Enable in the Built-In Identity Provider
Procedure
-
On the Omnissa Access console Integrations > Authentication Methods page, click Pass App.
The Pass App page displays the current settings. Before the page is configured the first time, the page lists the default settings. -
Click CONFIGURE and configure the Omnissa Pass app settings.
Option Description Applies to Enable Omnissa Pass Application Authentication Enables the Omnissa Pass application All Omnissa Pass App situations . User identifier format Select the user identifier format that is used to prompt for user identity entry and for displaying the user identity in authentication pages. • When used as first-factor authentication, users must enter their identifier in this format.
• When used as second-factor authentication, this identifier format is displayed to users.
Number of re-tries allowed Enter the number of times a user can enter an incorrect passcode before the sign-in attempt fails and access is denied. The value can be from 1 to 15. The default is 5 times. TOTP only. Retry period The rolling time window in minutes for the number of retries allowed before triggering a user lock-out. The default is 5, minimum is 5, maximum is 15. TOTP only. Lock-out time The length of time in minutes the user must wait after exceeding number of retries within a retry period before the user can login with Pass. The default is 5, minimum is 5, maximum is 60. TOTP only. Friendly Account Name (Optional) The account name that is displayed to users in the Omnissa Pass app. For example, Acme Corp. If left blank, the Omnissa Access tenant name is used as the account name.
Character limit: 32 characters
Note: Only new registrations created after you specify a Friendly Account Name display the name. Existing registrations retain their original account name.Enable Push notification Indicates whether to enable the sending of push notifications as a means of authentication to devices with the Pass application installed. Push notifications apply to second-factor authentication only. Push notification timeout Length of time in seconds that the user has to respond to a push notification. The value can be from 30 to 120 seconds. Push notifications only. When Enable push notification setting is selected, this setting applies. Otherwise, this setting is ignored. Enable push notification limit Indicates whether to enforce a limit of 3 push notifications per minute for each user. When the Enable push notification setting is selected and the Omnissa Pass Advanced add-on is configured, this setting applies. Otherwise, this setting is ignored. Enable push number matching challenge Indicates whether to require the user to complete a number challenge as part of the authentication using push notifications. When the Enable push notification setting is selected and the Omnissa Pass Advanced add-on is configured, this setting applies. Otherwise, this setting is ignored. Enable multiple device registration Allows users to register more than one device for Omnissa Pass. When enabled, users can register up to three independent devices per user account through the standard QR-based registration flow.
Users who already have one registered device will see an Add Omnissa Pass device option on the Support tab in the Workspace ONE Intelligent Hub portal.
Each device is uniquely registered in Omnissa Access and associated with the same user identity. Any registered device can generate valid TOTP codes and receive sign-in push notification requests.
This option is enabled by default.Available with Omnissa Pass Advanced add-on only. Enable Registration During Login Indicates whether to provide users with the option of registering for Omnissa Pass authentication during login if they do not have an existing registration. Second-factor authentication only. -
Click SAVE.
Create Omnissa Pass Authentication Policies in Omnissa Access
You create two policy rules for Omnissa Pass, a registration policy rule and an authentication policy rule.
The registration policy rule must be in the default policy. However, the placement of the authentication policy rule depends on how the feature is used. If used for first factor or second factor authentication, the authentication policy must be in the default policy. If used for second factor step-up authentication, the authentication policy must be in a custom app policy.
-
The registration policy rule is required to enforce proper authentication before allowing a user to delete an Omnissa Pass registration. If you enable the option to allow multiple device registrations, the registration policy rule is enforced before the user can delete the last Omnissa Pass registration or add multiple device registrations.
To add this rule, create a rule within the default login policy with the and user is registering Omnissa Pass option selected. Next, create a policy configuration that enforces the same type of authentication that is used to access the resources protected with Omnissa Pass. For example, consider a situation where users can log in with first-factor username and password while Omnissa Pass is used for step-up authentication for a subset of sensitive application resources. In this case, the Omnissa Pass registration policy rule is set to require Omnissa Pass authentication. This prevents an attacker that has obtained a user’s password from also being able to register their device as the Omnissa Pass authenticator to gain access to the sensitive resources.
-
At a minimum, the authentication policy rule specifies when Omnissa Pass is required as the authentication method to access a resource, and if used for first-factor authentication, the authentication policy rule also effectively protects the session of the user and all applications and resources to which the session grants access.
For more information on configuring Access Policies, see Managing Access Policies in the Omnissa Access Service
Assign Applications to Custom Access Policies
If you are using Omnissa Pass to implement step-up authentication, you must assign an application to the access policy with Omnissa Pass as an authentication method you created in the preceding procedure. See Configure Access Policy Rules and Assign Web, Virtual, and Horizon Cloud Service Next-Gen Apps to the Policy for Conditional Access for information about assigning applications to policies in Omnissa Access.
End Users - Install and Register Omnissa Pass
Provide users with the following instructions.
Prerequisites
Meet the following device requirements:
- Minimum OS versions iOS 16+ or Android 11.
- To enable access to the application after installation, the device cannot have unauthorized operating system modifications or elevated privileges.
- To enable access to the application after installation, the device security lock must be enabled.
Procedure
- On your mobile device, go to the Google Play Store for Android devices or the App Store for Apple devices and download and install the Omnissa Pass application.
- Log in to your organization's Workspace ONE Intelligent Hub portal and select the Support tab.
- In the My Devices section, click Add Omnissa Pass account.
A pop-up window appears with a QR code to register Omnissa Pass. - Launch the Omnissa Pass application on your mobile device, select the option to add an account, and click Scan a QR code.
- If prompted, grant the application permission to use the camera on your device, then scan the QR code.
Upon scanning the QR code, an entry is created in the application with your Omnissa username. - Click Show in the Pass application to display the 6-digit one time passcode.
- Enter the passcode in the Enter Passcode Here text box in the pop-up window in your web browser and click Continue.
If the TOTP code is valid, a "Registration successful" message appears. - Click Close and confirm that the Omnissa Pass option is "Activated" in the Support page of the Workspace ONE Intelligent Hub portal.
If the administrator enabled push notifications, in the Omnissa Pass app, you can see the push notifications onboarding screen and a prompt to grant the Omnissa Pass application permissions for sending push notifications. - If push notifications were enabled, in the Omnissa Pass app, accept the permission to start receiving sign-in approval push notifications.
End Users - Register an Additional Device for Omnissa Pass
If your administrator has enabled multiple device registrations, you can register up to three devices for Omnissa Pass authentication.
For example, you can install Omnissa Pass on your work phone, personal phone, and tablet, and register all three devices in the Workspace ONE Intelligent Hub portal. You can then authenticate using the TOTP code from any of your registered devices. For push notifications, you select a default device to receive notifications.
Use this procedure to register a second or third device.
Prerequisites
The additional devices must meet the same requirements as the first device.
Procedure
-
Log in to your organization's Workspace ONE Intelligent Hub portal.
When you log in, the page displays your existing registered Omnissa Pass device, along with an Add Omnissa Pass device option.
Note: Your administrator might require you to log in with another authentication factor in order to add another device or delete the last device.
-
On the new device you want to register, go to the Google Play Store for Android devices or the App Store for Apple devices and download and install the Omnissa Pass app.
-
In the Intelligent Hub portal, click Add Omnissa Pass device.
A QR code is displayed on the screen. -
On the new device you want to register, open the Omnissa Pass app.
-
Select the option to add an account, and click Scan a QR code.
-
Use the device's camera to scan the QR code displayed in the browser and follow the prompts to complete the registration.
The Omnissa Pass app on the new device registers with your account. The new device appears on the Support tab along with your existing registered device. -
To change the default name for the new device in the Support tab, click the menu icon on the tile, select Rename, enter the new name, and click Save.
For example, you can change the default name Pass 1 to iPhone 17 so that you can identify it easily. -
Select the device on which to receive push notifications.
Push notifications can only be sent to one device, and they are sent to the first registered device by default. To select another device, click the menu icon on the tile, select Set as default device, and click Save. If none of the devices are set as the default, the login screen prompts you to select the device on which to receive a push notification.
End Users - Authenticate with Omnissa Pass
After users configure their devices with Omnissa Pass as an authentication method for an application, Omnissa Access requires users to respond with one of the two following main methods, depending on the method administrators configured:
- Time-Based One-Time Password (TOTP) - Users provide a one-time passcode sent to their device.
- Push Notifications - Users approve the sign-in notification request sent to their device. Push-notification security can be enhanced with a number-matching prompt to which users must respond.
Procedure to Authenticate Using the TOTP Code Method
- Sign in to the application using the required first-factor authentication method.
- When prompted for multi-factor authentication, open your Omnissa Pass app on your mobile device.
- Unlock the app using your device’s security method (fingerprint, PIN, or face ID).
- Click Show to display the 6-digit time-based one-time password (TOTP) associated.
- Enter the code into the multi-factor authentication prompt on the sign-in screen to complete authentication.
Procedure to Authenticate Using the Push Notifications Method
This option is available to users after an Omnissa Access administrator enables the push notification setting in the Omnissa Pass adapter and the notification permission has been granted to the Omnissa Pass application.
- Launch an application that has been configured to require the use of Omnissa Pass as a second factor authentication method.
- A push notification will be sent to your mobile device where Omnissa Pass is installed and registered.
If you have registered multiple devices for the Omnissa Pass authentication method, the push notification is sent to the device that is set as the default device. You can manage the default device setting from the Intelligent Hub portal Support tab. - Tap the notification to launch the Omnissa Pass app. Unlock the app using your device’s security method (e.g., fingerprint, PIN, or face ID).
- In the app, tap Approve to confirm the sign-in request.
Procedure to Authenticate Using the Push Notifications with Number Matching Method
This option is only available if the push notification and number matching settings have both been enabled in the Omnissa Pass adapter in Access and the notification permission has been granted to the Omnissa Pass app.
- Launch an application that has been configured to require the use of Omnissa Pass as a second factor authentication method.
A two-digit number appear on the sign-in screen. - A push notification is sent to your mobile device where Omnissa Pass is installed and registered.
If you have registered multiple devices for the Omnissa Pass authentication method, the push notification is sent to the device that is set as the default device. You can manage the default device setting from the Intelligent Hub portal Support tab. - Tap the notification to launch the Omnissa Pass app. Unlock the app using your device’s security method (e.g., fingerprint, PIN, or face ID).
- In the Omnissa Pass app, you will see three numbers. Select the number that matches the one shown on the sign-in screen to confirm the sign-in request
View Omnissa Pass-Related Reports
Several reports are available in the Omnissa Access console to help you manage your deployment of the Omnissa Pass authentication method. The reports provide insights such as which users have registered and activated the Omnissa Pass app, whether any users are blocked, whether any user devices are compromised, and when users last logged in successfully using the app. You can also view detailed audit logs containing registration and login events for Omnissa Pass.
To view the reports:
-
In the Omnissa Access console, navigate to the Monitor > Reports page.
-
Select the report.
The following reports contain data relevant to Omnissa Pass:
- Pass Registration Report
- Pass Device Status Report (requires Omnissa Pass Advanced and Omnissa Pass app version 26.03 or later)
- Audit Events Report
-
To export the report to a CSV file, click Export on the report page.
Pass Registration Report
Use this report to monitor user registration status.
The report displays the following information for all users:
- Name: The user's last name, first name, and username
- Email address: The user's email address
- Domain: The user's domain
- Status: The status of the user's registration
- Not Registered: The user has not yet registered the Omnissa Pass app
- Not Activated: The user has not yet activated the Omnissa Pass app
- Activated: The user has registered and activated the Omnissa Pass app
- Blocked: While attempting to log in to the Omnissa Pass app, the user exceeded the Number of retries allowed in the Retry period. The status remains Blocked until the user attempts to log in again after the Lock-out time expires.
- Notification Status: Whether the user has enabled push notifications; values: Enabled or Disabled
You can filter the report by status.
Note: The Pass Registration report displays only one status for each user. If a user has registered multiple devices, use the Pass Device Status report to see information about all the devices. Additionally, you can see the list of devices and their status, including the push notification status, in the user's account page. Navigate to Accounts > Users, select the user, select the Multifactor Authentication tab, and view the information in the Omnissa Pass section.
Pass Device Status Report
The following requirements apply to the Pass Device Status report:
- Omnissa Pass Advanced must be enabled for your tenant.
- Omnissa Pass app version 26.03 (or later) for iOS or Android must be installed on user devices for data to appear in the report.
Use this report to monitor the status of devices that have the Omnissa Pass app, such as the device location, OS version, and compromise status, as well as the time the device was last seen and last used to log in successfully.
The report displays the following information for all Omnissa Pass device registrations:
- Name: The user’s last name, first name, and username
- ID: Unique device identifier
- OS Platform: iOS or Android
- OS Version: OS version, for example: iOS 26.3
- Model: Device model, for example: Pixel 7 Pro
- Pass Version: Omnissa Pass app version, for example: 26.03
- Security Patch (Android only): Device Security Patch Level, for example: 2025-04-05
- Region: The approximate location of the device when it was last seen, based on IP address (not GPS)
- Last Login: The last time there was a successful TOTP authentication or any response to a push notification from the device. The timestamp reflects the administrator’s time zone.
- Lock Status: Whether the device security lock (passcode or biometric) is enabled; values: Enabled or Not Enabled
- Compromise Status: Whether the device has been compromised (jailbroken or rooted); values: Yes or No
- Last Seen: The last time the device was online and the Omnissa Pass app reported data. The timestamp reflects the administrator’s time zone.
If a user has multiple device registrations, the report displays multiple rows for the user, one for each device.
You can filter the report by user, OS platform, Omnissa Pass app version, and device compromise status.
Audit Events Report
Use this report to view audit events related to Omnissa Pass. You can select PassAuthenticator for Type to filter the events.
Examples of Omnissa Pass-related audit events include:
- PassAuthenticator CREATE and PassAuthenticator UPDATE events: Created when a user registers and activates the Omnissa Pass app, or updates it subsequently
Note: When a user has multiple devices registered, you can look for theauthenticatorIdvalue in the audit event details to see which device the event is associated with. - LOGIN (Omnissa Pass) events: Created when a user logs in successfully or attempts to log in using the Omnissa Pass app authentication method
- Blocked events: Created when a user is blocked because they exceeded the number of retries allowed while attempting to log in to the Omnissa Pass app
Reset Omnissa Pass User Registrations
As an administrator, you can reset users' Omnissa Pass registrations, for example, when a user's device is damaged or lost.
- In the Omnissa Access console, navigate to Accounts > Users.
- Click the name of a user, or search for a user.
- Select the Multifactor Authentication tab.
The Omnissa Pass section lists all the devices that the user has registered. You can see when each device was registered, whether it is activated, and whether push notifications are enabled on the device. The Default label indicates the device that is used to receive push notifications. - Select the device you want to reset, then click Reset in the Omnissa Pass section.
The user can navigate to the Support tab in the Workspace ONE Intelligent Hub portal and register a new device.
Troubleshoot Common Omnissa Pass Issues
Omnissa Pass Issues, Causes, and Resolutions
| Issue | Possible Cause | Resolution |
|---|---|---|
| Omnissa Pass access is blocked on app launch. | Device might not meet required security requirements. For example, the device security lock is not enabled or the device is compromised. | Ensure device security is set and verify that the device is not compromised. |
| Registration fails with an error when the QR code is scanned. | Device registration might fail due to: • Device is offline. • Device attestation fails or attestation cannot complete due to network issues. • A duplicate registration exists. • Attempting to register a third-party application without an existing Omnissa Access registration. | Address each of the possible causes mentioned. |
| Authentication fails. | Authentication with Omnissa Pass might fail due to: • The TOTP code is not valid. • The server time is more than 30 seconds off from the time on the mobile device with Omnissa Pass. • The account is locked out. | Address each of the possible causes mentioned. |
| Push Notification is hidden or not visible. | Device might be on Do-Not-Disturb or Focus Mode. | Open the notification tray to view the Omnissa Pass notification. In your device’s settings, you can allow Omnissa Pass to deliver notifications even when the device is in Focus Mode. |
| Unable to see the push sign-in prompt when the Omnissa Pass app is launched during sign-in attempt. | This occurs when the app is launched directly without tapping the notification. | When a push notification is sent to your device, tap the notification to view the sign-in prompt and do not launch the app directly. |
| Users are unable to add additional devices or delete the last Pass device registration in the Intelligent Hub portal. | The registration and deletion policy rule may not be configured. | Administrators need to enable the registration and deletion policy rule in the default access policy which requires a multi-factor authentication in order to add another device or delete the last device. |
Was this page helpful?