Skip to main content

August 17, 2026

Configuring High Availability for Omnissa Access Connector Services

You can configure high availability for the Directory Sync, User Auth, Kerberos Auth, and Virtual App services by installing multiple instances of the services and configuring high availability for the corresponding features in the Omnissa Access console. For the Kerberos Auth service, a load balancer is also required.

High availability for connector services works through automatic failover. You install multiple instances of a service on separate connector servers, then associate those instances with a directory, authentication method, or virtual apps collection in the Omnissa Access console. The Omnissa Access service uses the primary instance and fails over to the next available instance if the primary becomes unavailable.

Each service type has its own failover configuration, so you can manage high availability for directory sync, authentication, and virtual apps independently. Because Kerberos authentication requires an inbound connection, a load balancer must front the Kerberos Auth service instances. The other services are outbound-only and do not require a load balancer.

In This Section

  • Configuring High Availability for Directory Sync in Omnissa Access

    Associate a directory with multiple Directory Sync service instances and arrange them in failover order in the Omnissa Access console. Each directory maintains its own list of service instances. As a best practice, avoid having the same instance sync multiple directories simultaneously by using separate instances per directory, staggering sync schedules, or varying the failover order across directories.

  • Configuring High Availability for Omnissa Access Connector-Based Authentication Methods

    Enable high availability for connector-based authentication methods — Password (cloud deployment), RSA SecurID (cloud deployment), and RADIUS (cloud deployment) — by installing the User Auth service on multiple connectors and linking them to the same authentication method in the Omnissa Access console.

  • Configuring a Load Balancer for Kerberos Auth Service High Availability

    Install a load balancer in your internal network, inside the firewall, and add your Kerberos Auth service hosts to it. You must also establish SSL trust between the load balancer and the Kerberos Auth service hosts, and update the IdP Hostname value in the Workspace IDP for Kerberos authentication in the Omnissa Access console.

  • Configuring High Availability for the Virtual App Service

    Associate a virtual apps collection with multiple Virtual App service instances and arrange them in failover order. Each collection maintains its own list of service instances, which allows you to optimize failover behavior independently for different app integrations such as Horizon, Citrix, or ThinApp.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…