Using OpenID Connect with Workspace ONE Access

We mostly talk about SAML with Workspace ONE but i’m asked occasionally if Workspace ONE Access can support OpenID Connect? The answer is yes, of course it can.  Just keep in mind before you start to configure OpenID Connect, Workspace ONE Access only supports the email, profile and user scopes.There is no support for custom … More Using OpenID Connect with Workspace ONE Access

Enabling Risk-Based Identity Assurance: VMware Workspace ONE + RSA SecurID Access

VMware’s Workspace ONE provides a digital workspace platform with a seamless user experience across any application on any device. Users can access a platform native catalog to download and install applications regardless of whether its an IOS, Android, Win10 or MacOS device. They can access both Web and SaaS applications as well as their Virtualized … More Enabling Risk-Based Identity Assurance: VMware Workspace ONE + RSA SecurID Access

Workspace ONE Access with Azure MFA using the NPS Extension.

In an earlier blog I walked through various options on how to use Microsoft Authenticator with Workspace ONE Access (formerly known as VMware Identity Manager). In the final option, we talked about using the Microsoft Azure MFA Server.  However, as of July 1st, 2019, Microsoft is no longer offering the MFA Server for new deployments. … More Workspace ONE Access with Azure MFA using the NPS Extension.

Using Workspace ONE with Microsoft Authenticator

We come across the scenario quite often when customers want to leverage Microsoft Authenticator when using Workspace ONE UEM and/or Horizon. In this blog, I’d like to go through the various options and outline the user experience with each of the options. The  main uses case we see are: Microsoft MFA for Horizon Desktop Microsoft … More Using Workspace ONE with Microsoft Authenticator

Using the Okta RADIUS Agent for VMware Horizon

In this blog we are going to discuss adding Multi-Factor Authentication using Okta Verify with VMware Horizon by leveraging the Okta Radius Agent. For more information on this integration, please see https://www.okta.com/integrations/mfa-for-virtual-desktops/vmware/ We are going to walk through 3 separate deployment options to leverage the Okta Radius Client: Using Workspace ONE Access (formerly known as VMware … More Using the Okta RADIUS Agent for VMware Horizon

Workspace ONE – How to Configure IOS Mobile SSO

In this blog post, we will walk through the steps to configure IOS Mobile SSO. I will be assuming that your Workspace ONE UEM and Workspace ONE Identity Manager environments have not been previously integrated. This blog will assume that you already have an Enterprise Cloud Connector installed and syncing with Workspace ONE UEM. In … More Workspace ONE – How to Configure IOS Mobile SSO

Workspace ONE – Okta Integration Part 2: Unified Digital Workspace

The release of Workspace ONE 19.03 brought in a very seamless integration of Okta Applications. If you have integrated the two solutions previously you will recall the number of steps required to create and entitle new applications in Workspace from Okta. This integrations you to create and entitle applications in Okta and have them seamless … More Workspace ONE – Okta Integration Part 2: Unified Digital Workspace

Workspace ONE – Okta Integration Part 1: Core Setup and Configuration

The release of Workspace ONE 19.03 brought in a very seamless integration of Okta Applications. If you have integrated the two solutions previously you will recall the number of steps required to create and entitle new applications in Workspace from Okta. This integrations you to create and entitle applications in Okta and have them seamless … More Workspace ONE – Okta Integration Part 1: Core Setup and Configuration

How to Configure SAML Single Logout in WS1 for Okta

If you have configured Okta as a 3rd Party IDP in Workspace ONE you might have noticed that the “Logout” function in Workspace ONE doesn’t log you out of your Okta session. The reason for this is that Okta does not include the “SingleLogoutService” by default in the metadata that is used when creating the … More How to Configure SAML Single Logout in WS1 for Okta

Sending Multiple Attributes from WS1 to ADFS

If you have followed the documentation for ADFS Integration with WS1, you configured the WS1 to send “${user.domain}\${user.userName}” as the NameID. However, you will probably need to send additional attributes in case other applications are looking for things like UPN. The following is how you would configure this: Under Attribute Mapping, enter the Name of … More Sending Multiple Attributes from WS1 to ADFS