top of page
Zoeken


The Hybrid Join Cascade: When the PRT Challenge Still Isn’t Done
Over the past few months, I’ve been looking into some of the trickier issues in environments that combine Omnissa Horizon Instant Clones, Hybrid Azure AD Join, App Volumes and even TrueSSO. A true resonance cascade For issues with PRT when federated EntraID to Omnissa Access and when using TrueSSO read my previous post: The Hybrid Join Incident: Recovering the Lost PRT 1. PRT unpredictability and the “Wait for Hybrid Join” setting One of the biggest headaches in Instant Clone
Edwin de Bruin
1 dec 20253 minuten om te lezen


Omnissa Pass: The New Member of the Omnissa MFA Fellowship
A few years back, VMware Verify reached end of life (2022). Since then, we basically had two options left from the Omnissa perspective: a TOTP authenticator app based on RFC 6238 or Intelligent Hub MFA with push notifications. The TOTP option works well, especially for Bring Your Own Devices (BYOD) , but users still end up typing in codes constantly. Intelligent Hub MFA solves that with push, but the downside is that it requires some level of device management or registration
Edwin de Bruin
1 dec 20253 minuten om te lezen


The Hybrid Join Incident: Recovering the Lost PRT
Single Sign-On in modern environments can be a beautiful thing, until it isn’t. You’ve federated Entra ID to Omnissa Access, implemented Hybrid Join, and everything works perfectly when users log in with their username and password. But then you try it externally. TrueSSO is in place to make VDI logins seamless, certificates replace passwords and suddenly the PRT never shows up. Microsoft apps (Teams v2 being the most noticeable) rely increasingly on the PRT for full Single S
Edwin de Bruin
27 nov 20253 minuten om te lezen


Federate EntraID to Omnissa Access with Graph PowerShell SDK
If you’ve integrated Workspace ONE Access with Microsoft 365 before, the steps will look familiar. Omnissa Access is the evolution of VMware Identity Manager, and while the interface and URLs have changed slightly, the principle remains the same: let Microsoft 365 trust Omnissa Access as the identity provider for your domain. This post walks through the new way to federate Entra ID with Omnissa Access using the Microsoft Graph PowerShell SDK. It replaces the legacy MSOnline m
Edwin de Bruin
23 okt 20253 minuten om te lezen


Using the Omnissa Workspace One UEM CA with Microsoft EntraID Certificate Based Access
Although with many implementations of the Workspace One platform Workspace One Access is configured as the IDP (personally preferred when using this platform) I also encounter customers where EntraID is the preferred IDP with mostly valid reasons. There are use cases this is the better choice. With the flexibility Workspace One Access offers this is no issue at all. But when shifting the IDP to EntraID I usually advice to also shift the Conditional Access policies to EntraID.
Edwin de Bruin
10 okt 20242 minuten om te lezen


HELLO Workspace One Access: Using Windows HelloID as FIDO2 security key!
More and more authentication methods are available to Workspace One Access and one of them is FIDO2. I’ve seen multiple use cases with the well-known Yubico Security Keys. But did you know you can also use Windows Hello as Security key? So, to put it in context, you can use Biometrics or PIN as identifier and login to Workspace One Access without sending credentials! Rock On! How does FIDO2 work? FIDO2 is like having a digital key that unlocks your online accounts instead o
Edwin de Bruin
14 mei 20243 minuten om te lezen


VMware vSphere 8.0 U2 and federated Authentications with Microsoft Entra ID
A new feature available since vSphere 8.0 U2 is federated authentication with Microsoft Entra ID (Azure Active Directory) and provision the users with SCIM. This is really nice since it is now possible to create Single Sign On, leverage Conditional Access policies and Multi Factor Authentication (MFA). In this blog I will explain step by step how to configure this and how to mitigate a in my opinion big fat no no required in the original documentation: Expose vCenter to the
Edwin de Bruin
30 dec 20236 minuten om te lezen


The Flow: Microsoft 365 federated with VMware Access when using the Kerberos Connector
On a recent project a customer is moving it’s on-premises Exchange to Exchange Online. We decided VMware Access is the IDP for Microsoft 365. Well federated the Microsoft tenant with VMware Access and to get single sign on from the Horizon Instant Clones we are going to use the VMware Kerberos connector. So created and installed the necessary components configured the Conditional Access policies... and we have single sign on! Awesome! While explaining the flow to some people
Edwin de Bruin
19 jan 20232 minuten om te lezen


Microsoft November Updates and breaking TrueSSO
First of all happy new year everyone! On 31 december 2022 New Years Eve I got a message from a colleague of mine while eating "oliebollen" with the family at friends of ours. One customer is having issues with external login's to their VMware Horizon environment. They get stuck on the Imprivata login screen. Alltough the user can login by re-entering their credentials it is annoying. The fact Imprivata selected the default domain to be the local machine and the user has to sw
Edwin de Bruin
1 jan 20232 minuten om te lezen


Imprivata OneSign: How to let the patient sleep by turning off the monitor on a lock tab!
A while ago I got asked by a customer how they can auto turn off the monitor when they move away from the workstation. These workstations are located on an Intensive Care unit so when they need to access these machines at night, they want the monitors "on time" limited to a minimum to not wake up the patient too much. First thought: Manually turning off these monitors with the power button? (Smile and wave. No, we can do better!) Second thought: Power settings and the monitor
Edwin de Bruin
19 dec 20222 minuten om te lezen


Using VMware Access and Imprivata ConfirmID for remote Access as MFA solution
Lately a lot has been written about the EOL of VMware Verify. But… what if you are already used to Imprivata and maybe have the Confirm ID for remote access licenses around? Can we use this instead? Yes you can! How? By connecting to Imprivata with RADIUS. Is this new? Nope… they even call this the legacy experience. But sometimes legacy is just what you might need so he ho, let’s go! Of course: As an alternative to this you can use the VMware Authenticator or Intelligent HU
Edwin de Bruin
20 sep 20226 minuten om te lezen


Imprivata and the Kerberos Keytab file
When using VMware Horizon, VMware Workspace One Access, TrueSSO and Imprivata you need to enable Kerberos Authentication within Imprivata. For this to work you also need to create a keytab file. In this blog I will explain how to create one and as a bonus.. can we use a custom account for this instead of the default created by the tool? Imprivata has a built in utility to facilitate this: ISXKerbUtil.exe. Normally you can find this utility in the OneSign Agent install directo
Edwin de Bruin
1 sep 20223 minuten om te lezen


Call me IDP - Workspace ONE Access with Microsoft Office 365
A man browsed down the Login Page He says, "Why am I short of attention? Got a short little span of attention And, whoa, my logins are so long Where's my Credentials and TOTP? What if I die here? Who'll be my role model Now that my role model is gone, gone?" He ducked back down the alley With some roly-poly little login tool All along, along There were Username and passwords There were hints and allegations [Chorus] If you'll be my IDP I can be your long lost SP I can call yo
Edwin de Bruin
27 jun 20222 minuten om te lezen


The VMware Authenticator App is GA!
As I mentioned in my previous blog VMware Verify goes EoS and EoA on on October 31st, 2022. VMware developed (sort of) 2 alternatives: Intelligent HUB verify and the Authenticator App. Yeah Great news!: The Authenticator App is GA (Globally Available) since 10-06-2022 What is the Authenticator App? Authenticator App (any app supporting TOTP RFC 6238 standard)*: By adding support for authenticator apps that use time-based one-time passcodes (TOTP) such as Microsoft Authenticat
Edwin de Bruin
20 jun 20222 minuten om te lezen


VMware Verify (Intelligent HUB) is available within the Default Access Policy on al device platforms
Awesome: VMware Verify (Intelligent HUB) is available within the Default Access Policy on al device platforms! Little back story: As stated in the following article: Workspace ONE Access: VMware Verify End-of-Life Migration Paths (88424) VMware Verify will reach end-of-support (EoS) and end-of-availability date (EoA) on October 31st, 2022. This gave us some headaches.. what are the alternatives? VMware Verify worked very well and gave us the basic features we requested… like
Edwin de Bruin
28 mei 20222 minuten om te lezen
Blog: Blog2
bottom of page