Skip to main content

December 4, 2024 Archived

Integrating Active Directory with Omnissa Access

You can integrate Omnissa Access with your Active Directory deployment to sync users and groups from Active Directory to the Omnissa Access service. The type of Active Directory environment that you have determines the type of directory you create in the Omnissa Access service.

Active Directory Environments

You can integrate the Omnissa Access service with an Active Directory environment that consists of a single Active Directory domain, multiple domains in a single Active Directory forest, or multiple domains across multiple Active Directory forests.

Single Active Directory Domain Environment

With a single Active Directory domain deployment, you can sync users and groups from a single Active Directory domain.

For this environment, you can create a directory either of type Active Directory over LDAP or type Active Directory over Integrated Windows Authentication in the Omnissa Access service.

For more information, see:

Multi-Domain, Single Forest Active Directory Environment

In a multi-domain, single forest Active Directory deployment, you can sync users and groups from multiple Active Directory domains within a single forest.

For this environment, in the Omnissa Access service you can create either a single Active Directory over Integrated Windows Authentication directory, or an Active Directory over LDAP directory configured with the Global Catalog option.

  • The recommended option is to create a single Active Directory over Integrated Windows Authentication directory.

    When you add a directory for this environment, select the Active Directory over Integrated Windows Authentication option. Make sure that a direct (non-transitive) two-way trust is set up between domains in the directory and the domain that the Directory Bind user is a member of.

    For more information, see:

  • If Integrated Windows Authentication does not work in your Active Directory environment, create an Active Directory over LDAP directory and select the Global Catalog option.

    Some of the limitations with selecting the Global Catalog option include:

    • The Active Directory object attributes that are replicated to the global catalog are identified in the Active Directory schema as the partial attribute set (PAS). Only these attributes are available for attribute mapping by the service. If necessary, edit the schema to add or remove attributes that are stored in the global catalog.
    • The global catalog stores the group membership (the member attribute) of only universal groups. Only universal groups are synced to the service. If necessary, change the scope of a group from a local domain or global to universal.
    • The bind DN account that you define when configuring a directory in the service must have permissions to read the Token-Groups-Global-And-Universal (TGGAU) attribute.
    • Users can sync to the Omnissa Access Global Catalog directory from multiple Active Directory domains, either directly or through group memberships. You must make sure that no other directory in the Omnissa Access tenant syncs users from the same domains, otherwise the conflict can cause sync failures.
    • When Omnissa Workspace ONE® UEM is integrated with Omnissa Access and multiple Workspace ONE UEM organization groups are configured, the Active Directory Global Catalog option cannot be used. Active Directory uses ports 389 and 636 for standard LDAP queries. For global catalog queries, ports 3268 and 3269 are used.

Multi-Forest Active Directory Environment with Trust Relationships

In a multi-forest Active Directory deployment with trust relationships, you can sync users and groups from multiple Active Directory domains across forests where two-way trust exists between the domains. In the Omnissa Access service, for this Active Directory environment create a single Active Directory over Integrated Windows Authentication directory.

When you add a directory for this environment, select the Active Directory over Integrated Windows Authentication option. Make sure that a direct (non-transitive) two-way trust is set up between domains in the directory and the domain that the Directory Bind user is a member of.

For more information, see:

Multi-Forest Active Directory Environment Without Trust Relationships

In a multi-forest Active Directory deployment without trust relationships, you can sync users and groups from multiple Active Directory domains across forests without a trust relationship between the domains. In this environment, you create multiple directories in the Omnissa Access service, one directory for each forest.

For more information, see:

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…