After setting up your Horizon environment, you must configure your Omnissa Access environment before integrating the Horizon pods and pod federations with the Omnissa Access service.
Using valid certificates signed by a trusted Certificate Authority (CA) for the Horizon Connection Servers is strongly recommended. If you have not obtained CA-signed certificates and are using self-signed certificates temporarily for testing purposes, you must upload the root certificates to the Virtual App service trust store.
Omnissa Access Tenants that do not have Omnissa Identity Service enabled
Prerequisites
- To integrate Horizon pods and pod federations, you must install the Virtual App service component of the Omnissa Access connector.
- To sync users and groups from Active Directory to Omnissa Access, you must install the Directory Sync service component of the Omnissa Access connector.
Procedure
-
If the Horizon Connection Servers have self-signed certificates, upload the root certificates to the Virtual App service truststore.
-
On the Windows server on which the Virtual App service is installed, run the Omnissa Access connector installer again.
-
On the Welcome page, click Next.
-
On the Program Maintenance page, select Add/Remove Services and click Next.
-
Click Next until the Install Trusted Root Certificates page appears.
-
On the Install Trusted Root Certificates page, click Browse and upload the certificate.
-
Save your changes and close the installer.
-
Restart the Virtual App Service.
-
-
Ensure that the distinguishedName attribute is mapped to the Active Directory attribute distinguishedName.
-
Log in to the Omnissa Access console.
-
Navigate to the Integrations > Directories page.
-
Select the directory that contains the users and groups with Horizon entitlements.
-
On the directory page, click Sync Settings, then select the Mapped Attributes tab.
-
Verify that the distinguishedName attribute is mapped to the Active Directory distinguishedName attribute.
-
-
Sync all users and groups with global or local entitlements in Horizon from Active Directory to the Omnissa Access service.
-
Review which users and groups are currently synced to Omnissa Access by going to the Accounts > Users and Accounts > User Groups pages.
-
Select Integrations > Directories.
-
Select the appropriate directory.
-
Click Sync Settings.
-
In the Users and Groups tabs, modify the settings if required, and click Save.
-
On the directory page, click Sync > Sync with Safeguards or Sync > Sync without Safeguards to sync the directory.
Sync safeguards limit the number of changes allowed during sync. For more information, see Directory Integration with Omnissa Access.
Note: Users must have the userPrincipalName and distinguishedName attributes set. If the userPrincipalName or distinguishedName attribute is not set for a user, the user might not be able to run desktops and applications.
-
-
If applicable, establish a connection to multi-domains or trusted multi-forest domains in Active Directory. See Directory Integration with Omnissa Access for information.
Omnissa Access tenants that have Omnissa Identity Service enabled
Omnissa Identity Service is a new cloud service for integrating Omnissa products and services with third-party cloud-based identity providers such as Microsoft Entra ID for user provisioning and identity federation.
For an Omnissa Access tenant that has Omnissa Identity Service enabled, integration with Omnissa Horizon is only supported for Horizon pods that have True SSO enabled. True SSO is configured in the Horizon Console (see Setting up True SSO). In the Omnissa Access console, the True SSO option must be selected for pods that have True SSO configured (see Configure Horizon Pods and Pod Federations in Omnissa Access).
Note: If Okta is configured as the third-party identity provider in Omnissa Identity Service, Omnissa Access integration with Horizon is not supported.
Prerequisites
To integrate Horizon pods and pod federations with Omnissa Access, you must install the Virtual App service component of the Omnissa Access connector.
Procedure
-
If the Horizon Connection Servers have self-signed certificates, upload the root certificates to the Virtual App service truststore.
-
On the Windows server on which the Virtual App service is installed, run the Omnissa Access connector installer again.
-
On the Welcome page, click Next.
-
On the Program Maintenance page, select Add/Remove Services and click Next.
-
Click Next until the Install Trusted Root Certificates page appears.
-
On the Install Trusted Root Certificates page, click Browse and upload the certificate.
-
Save your changes and close the installer.
-
Restart the Virtual App Service.
-
-
In the third-party identity provider that is integrated with Omnissa Identity Service, map the following additional attributes to the Omnissa Identity Service attributes (SCIM attributes).
-
User attributes: onPremisesUserPrincipalName, distinguishedName
-
Group attributes: distinguishedName
These attributes are required to match users provisioned from the cloud-based identity provider with the user entitlements synced from Horizon, to ensure that users can launch the Horizon apps and desktops assigned to them.
See User Attribute Mapping for Omnissa Identity Service for more information.
-
Was this page helpful?