Skip to main content

April 13, 2026

Configure Omnissa Access as an Identity Provider in Okta

This section describes the process of configuring Omnissa Access as an identity provider in Okta. This configuration is required to configure a unified catalog as well as mobile SSO and device trust.

Get Omnissa Access SAML Metadata Information

Retrieve the SAML metadata information from Omnissa Access that is required to set up an identity provider in Okta.

Procedure

  1. Log in to the Omnissa Access console as the System administrator.

  2. Select Resources > Web Apps.

  3. Click the Settings button.

  4. Click SAML Metadata in the left pane.

  5. From the Download SAML Metadata tab, download the Signing Certificate.

    1. In the Signing Certificate section, click Download.

    2. Make a note of the location of the downloaded signingCertificate.cer file.

  6. Retrieve the SAML metadata.

    1. In the SAML Metadata section, right-click the Identity Provider (IdP) metadata link and open it in a new tab or window.

    2. In the identity provider metadata file, find and make a note of the following values:

      • entityID

        For example: https://tenant.workspaceoneaccess.com/SAAS/API/1.0/GET/metadata/idp.xml

      • SingleSignOnService URL with Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"

        For example: https://tenant.workspaceoneaccess.com/SAAS/auth/federation/sso

      get metadata info

Add Identity Provider in Okta

Create the identity provider record in Okta.

For additional information about how Okta handles external identity providers, see the Okta documentation on Identity Providers.

Procedure

  1. Log in to the Okta Admin console with Administrator privileges or any role entitled to add an Identity Provider.

  2. Navigate to Security > Identity Providers.

  3. Click Add Identity Provider, then select Add SAML 2.0 IdP.

  4. Enter a name for the identity provider. For example, Workspace ONE.

  5. Enter the following information:

    OptionDescription
    IdP Usernameidpuser.subjectNameId
    If you plan to send the username in a custom SAML attribute, define an appropriate expression. For information, see https://developer.okta.com/reference/okta_expression_language.
    FilterUncheck the box.
    Match againstOkta Username
    Adjust the selection as required for your environment and the values that you plan to send.
    If no match is foundRedirect to Okta sign-in page
    IdP Issuer URIEnter the entityID.
    This is the value you obtained from the identity provider metadata file from Workspace ONE. For example: https://tenant.workspaceoneaccess.com/SAAS/API/1.0/GET/metadata/idp.xml
    IdP Single Sign-On URLEnter the SingleSignOnService Location URL.
    This is the value you obtained from the identity provider metadata file from Workspace ONE. For example: https://tenant.workspaceoneaccess.com/SAAS/auth/federation/sso
    IdP Signature CertificateBrowse and select the Signing Certificate file you downloaded from Workspace ONE.
    Tip: You may need to change the file extension or default browser filter to look for *.crt and *.pem files.

    add idp in okta

  6. Click Show Advanced Settings, scroll to the Request Authentication Context option, and select Device Trust.

    This setting specifies the context of the authentication request.

    device trust option in Advanced settings

  7. Click Add Identity Provider.

  8. Verify that the following information appears:

    • SAML Metadata
    • Assertion Consumer Service URL
    • Audience URI For example:

    add idp in okta

  9. Download and save the metadata file.

    1. Click the Download Metadata link.

    2. Save the metadata file locally.

    3. Open the metadata file and copy its contents.

      You will use this metadata when you configure the Okta Application Source in Omnissa Access.

What to do next

Configure the Okta Application Source. Configuring the Okta Application Source is mandatory.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…