Skip to main content

April 13, 2026

Configure Okta as an Identity Provider for Workspace ONE

This section describes the process of configuring Okta as the identity provider to Workspace ONE. This configuration can be used to provide streamlined access to virtualized applications, provide Okta's extensible Multi Factor Authentication to applications in Workspace ONE, and provide a consistent and familiar login experience for users and administrators.

This configuration is done in Omnissa Access, the identity component of Workspace ONE.

Add Workspace ONE SAML App in Okta

Add and configure the Workspace ONE SAML app in the Okta Admin console.

Prerequisites

If you are using the Okta developer dashboard, switch to the Classic UI first. If you see a <> Developer prompt in the top left, click it and select Classic UI to switch to the Classic UI. Use the Classic UI for all the tasks in this document.

Procedure

  1. Log in to your Okta org and navigate to the Admin user interface.

  2. Navigate to Applications > Applications.

  3. Click Browse App Catalog.

  4. Search for Workspace ONE.

    The Workspace ONE app information page displays.

  5. Click Add.

    The Workspace ONE app page has overview information about the app and includes an Add button.

  6. In the Add Workspace ONE page, under General Settings, enter your Omnissa Access tenant URL in the Base URL text box.

    For example: https://example.workspaceoneaccess.com

    The page has example values.

  7. Click Done.

  8. Select the Sign On tab.

  9. In the Settings section, under SAML 2.0, right-click the Identity Provider metadata link and copy the link.

    ""

    You need this information for the next task, creating an identity provider in Omnissa Access.

  10. Select the Assignments tab and assign the app to the users or groups who need to access Omnissa Access.

    You can assign the app to a few users at first to test the integration.

    ""

Create a New SAML Identity Provider in Omnissa Access

Create a new SAML identity provider in the Omnissa Access console for the Okta integration.

Procedure

  1. Log in to the Omnissa Access console as the System administrator.

  2. Select Integrations > Identity Providers.

  3. Click Add Identity Provider and select Create SAML IDP.

    Create SAML IDP in Omnissa Access.

  4. In the New Identity Provider page, enter the following information.

    OptionDescription
    Identity Provider NameEnter a name for the new identity provider, such as Okta SAML IdP.
    Binding ProtocolSelect HTTP Post.
    Note: This field appears after you enter the metadata URL in the SAML Metadata section and click Process IdP Metadata.
    SAML Metadata
    1. In the Identity Provider Metadata text box, enter the metadata URL copied from Okta. For example: https://yourOktaTenant/app/appId/sso/saml/metadata
    2. Click Process IdP Metadata.
    3. In the Identify User Using section, select NameID Element.
    4. In the Name ID format mapping from SAML Response section, click the + icon, then select the following values:
      Name ID Format: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
      Name ID Value: userPrincipalName
      Note: Select the User Attribute that the application username value defined in Okta will match.
    5. In the Name ID Policy in SAML Request section, select the same value that you selected for Name ID Format in the previous step: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
    6. Leave the Send Subject in SAML Request (when available) check box unselected.
    UsersSelect the directories you want to authenticate using this identity provider.
    NetworkSelect the networks that can access this identity provider.
    Authentication MethodsEnter the following:
    Authentication Methods: Enter a name for the Okta authentication method, such as Okta Auth Method.
    SAML Context: urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport

    For example:

    The image displays the New Identity Provider form filled out with the values mentioned above.

  5. Click Add.

Add Okta Authentication Method to Access Policies in Omnissa Access

After you set up Okta as a SAML identity provider in Omnissa Access, add the newly-created Okta authentication method to access policies in Omnissa Access. Update the default access policy, and other policies as needed.

You need to add the Okta authentication method to the default access policy so that Okta is used as the sign in provider for the Workspace ONE catalog. The default access policy governs login to the catalog, and any apps configured in Omnissa Access that do not have another policy definition already.

Procedure

  1. In the Omnissa Access console, select Resources > Policies.

  2. Click Edit Default Policy.

  3. In the Edit Policy wizard, click Configuration.

  4. Click the policy rule for Web browsers.

    1. Set Okta authentication as the authentication method.

      If a user's network range is: ALL RANGES
      and the user is accessing content from: Web Browser
      Then perform this action: Authenticate using
      then the user may authenticate using: Okta Auth Method

      Note: For Okta Auth Method, select the authentication method you created for the IDP in Create a New SAML Identity Provider in Omnissa Access.

    2. Click Save.

  5. Edit other policies as needed to add the Okta authentication method.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…