Skip to main content

September 3, 2026

Configuring your Browser for Kerberos Authentication in Omnissa Access

When Kerberos is enabled in Omnissa Access, you need to configure Web browsers to send your Kerberos credentials to the Omnissa Access service when users sign in. Without this browser-side configuration, Kerberos authentication is enabled on the server side, but browsers will not automatically negotiate and pass the Kerberos ticket, and users will fall back to a standard sign-in prompt instead of getting single sign-on.

The following Web browsers can be configured to send your Kerberos credentials to the Omnissa Access service on Windows machines: Firefox, Microsoft Edge, and Chrome. All the browsers require additional configuration, and the configuration steps differ by browser.

Note: Kerberos authentication works in conjunction with Omnissa Access on Windows operating systems. Do not implement these Kerberos-related steps on other operating systems.

Configure Microsoft Edge to Access the Web Interface from Omnissa Access with Kerberos

You configure the Microsoft Edge browser to support Kerberos authentication when Kerberos is configured for your Omnissa Access deployment and if you want to grant users access to the Web interface using the Microsoft Edge browser.

Procedure

  1. Open the Windows Control Panel and go to Network and Internet > Internet Options.

  2. On the Advanced tab, scroll to the Security section and select Enable Integrated Windows Authentication.

    Microsoft Edge browser configuration for Kerberos step1

  3. On the Security tab, configure the following.

    1. Select Local Intranet and click Custom Level.

      Microsoft Edge browser configuration for Kerberos step2

    2. Scroll to the User Authentication section and select Automatic login only in Intranet zone and click OK.

      Microsoft Edge browser configuration for Kerberos step3

      This option takes effect only after you restart Microsoft Edge.

    3. On the Security page, click Local Internet > Sites and select all check boxes.

      Microsoft Edge browser configuration for Kerberos step4

    4. Select Advanced and add the website to the zone.

    5. Click Add > Close > OK.

  4. Log in to the Microsoft Edge browser to check access.

Results

The Kerberos protocol secures all interactions between this Microsoft Edge browser instance and Omnissa Access. Now, users can use single sign-on to access their Hub portal.

Configure Firefox to Access the Web Interface from Omnissa Access with Kerberos

You must configure the Firefox browser if Kerberos is configured for your Omnissa Access deployment and you want to grant users access to the web interface using Firefox.

Prerequisites

Configure the Firefox browser, for each user, or provide users with the instructions, after you configure Kerberos.

Procedure

  1. In the URL text box of the Firefox browser, enter about:config to access the advanced settings.

  2. Click Accept the Risk and Continue.

  3. Double-click network.negotiate-auth.trusted-uris in the Preference Name column.

  4. Enter your Omnissa Access connector URL in the text box.

    https://myconnectorhost.domain.com

    If you are using multiple connectors for Kerberos authentication, add a comma separated list of connectors.

  5. Click OK.

  6. Test Kerberos functionality by using the Firefox browser to log in to connector login URL. For example, https://myconnectorhost.domain.com.

    If the Kerberos authentication is successful, the test URL goes to the Web interface.

Results

The Kerberos protocol secures all interactions between this Firefox browser instance and Omnissa Access. Now, users can use single sign-on to access their Workspace ONE portal.

Configure the Chrome Browser to Access the Web Interface from Omnissa Access with Kerberos

You must configure the Chrome browser if Kerberos is configured for your Omnissa Access deployment and if you want to grant users access to the Web interface using the Chrome browser.

Prerequisites

  • Configure Kerberos.
  • Since Chrome uses the Microsoft Edge configuration to enable Kerberos authentication, you must configure Internet Explorer to allow Chrome to use the Microsoft Edge configuration. See Google documentation for information about how to configure Chrome for Kerberos authentication.

Procedure

  1. Test Kerberos functionality by using the Chrome browser.

  2. Log in to Omnissa Access connector at https://myconnectorhost.domain.com/authenticate/.

    If Kerberos authentication is successful, the test URL connects with the Web interface.

Results

If all related Kerberos configurations are correct, the protocol (Kerberos) secures all interactions between this Chrome browser instance and Omnissa Access. Users can use single sign-on to access their Workspace ONE portal.

Related information

Configure and Enable Kerberos Authentication in Omnissa Access

Kerberos Initialization Error in Omnissa Access

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…