top of page
Zoeken


Omnissa Pass: The New Member of the Omnissa MFA Fellowship
A few years back, VMware Verify reached end of life (2022). Since then, we basically had two options left from the Omnissa perspective: a TOTP authenticator app based on RFC 6238 or Intelligent Hub MFA with push notifications. The TOTP option works well, especially for Bring Your Own Devices (BYOD) , but users still end up typing in codes constantly. Intelligent Hub MFA solves that with push, but the downside is that it requires some level of device management or registration
Edwin de Bruin
1 dec 20253 minuten om te lezen


Federate EntraID to Omnissa Access with Graph PowerShell SDK
If you’ve integrated Workspace ONE Access with Microsoft 365 before, the steps will look familiar. Omnissa Access is the evolution of VMware Identity Manager, and while the interface and URLs have changed slightly, the principle remains the same: let Microsoft 365 trust Omnissa Access as the identity provider for your domain. This post walks through the new way to federate Entra ID with Omnissa Access using the Microsoft Graph PowerShell SDK. It replaces the legacy MSOnline m
Edwin de Bruin
23 okt 20253 minuten om te lezen


Horizon Instant Clones, Imprivata OneSign and the no SSO bug
Recently got involved in designing and building a new awesome blistering fast Omnissa Horizon environment for a hospital. This new environment is based on the latest Horizon ESB, DEM, AppVolumes, Windows 11 etc. And as many hospitals do, they use Imprivata OneSign. We ran into a bug. When logging in to the desktop (either Imprivata Client or Horizon client directly) we got confronted by the Imprivata GINA screen. Once again entering credentials and the desktop continues. Reco
Edwin de Bruin
1 aug 20243 minuten om te lezen


HELLO Workspace One Access: Using Windows HelloID as FIDO2 security key!
More and more authentication methods are available to Workspace One Access and one of them is FIDO2. I’ve seen multiple use cases with the well-known Yubico Security Keys. But did you know you can also use Windows Hello as Security key? So, to put it in context, you can use Biometrics or PIN as identifier and login to Workspace One Access without sending credentials! Rock On! How does FIDO2 work? FIDO2 is like having a digital key that unlocks your online accounts instead o
Edwin de Bruin
14 mei 20243 minuten om te lezen


Integrating Citrix Virtual App and Desktops with VMware Workspace One Access - Another way Around
A while ago I wrote a cross reference blog with my buddy Henry Heres about integrating Citrix Gateway and VMware Workspace One Access. A respected customer read these blogs and tried integrating this in their environment but ran in to issues and called for some assistance. Unfortunately, the original scenario we blogged about did not work in this specific environment, so I had to find an alternative way. In this blog I will show you another option and how to configure this!
Edwin de Bruin
23 jan 20243 minuten om te lezen


VMware vSphere 8.0 U2 and federated Authentications with Microsoft Entra ID
A new feature available since vSphere 8.0 U2 is federated authentication with Microsoft Entra ID (Azure Active Directory) and provision the users with SCIM. This is really nice since it is now possible to create Single Sign On, leverage Conditional Access policies and Multi Factor Authentication (MFA). In this blog I will explain step by step how to configure this and how to mitigate a in my opinion big fat no no required in the original documentation: Expose vCenter to the
Edwin de Bruin
30 dec 20236 minuten om te lezen


VMware Horizon, Imprivata Onesign and ThinClients
Ran into a little bug yesterday while implementing VMware Horizon and Imprivata. Appliances rolled out, configured the site, policy's etc. etc. On the regular Windows endpoints this worked as expected. Login went fine, tabbed a badge, entering additional credentials if required by policy and the session would beautifully start, locking, roaming, smooth as silk.. Pushed the Imprivata agent to the Thin Clients (Dell Wyse based on Windows 10 IoT, although the brand does not matt
Edwin de Bruin
22 aug 20231 minuten om te lezen


Migrating from Citrix Gateway to VMware Access Workspace One: Part Two!
As mentioned in my previous blog I was discussing a valid migration scenario between an existing Citrix Deployment to VMware Horizon with my buddy Henry Heres. One of the steps is to migrate the external portal from Citrix (Unified) Gateway to VMware WS One Access. This will be a divided in to two blogs describing the 2 steps. This blog is Step 2! In this step we will switch the portal to VMware WS One Access. Same as the previous one, I will show the flow, Henry will show t
Edwin de Bruin
1 mrt 20233 minuten om te lezen


Migrating from Citrix Gateway to VMware Access Workspace One: Part one
A while ago I was discussing a valid migration scenario between an existing Citrix Deployment to VMware Horizon with my buddy Henry Heres. One of the steps is to migrate the external portal from Citrix (Unified) Gateway to VMware WS One Access. As seen before, discussing these kind of scenarios with Henry is like planting a seed and pouring a gallon of Pokon on top of it. So, we decided to do a Cross reference Blog. I will show the flow, the blog(s) made by Henry will show h
Edwin de Bruin
28 feb 20233 minuten om te lezen


The Flow: Microsoft 365 federated with VMware Access when using the Kerberos Connector
On a recent project a customer is moving it’s on-premises Exchange to Exchange Online. We decided VMware Access is the IDP for Microsoft 365. Well federated the Microsoft tenant with VMware Access and to get single sign on from the Horizon Instant Clones we are going to use the VMware Kerberos connector. So created and installed the necessary components configured the Conditional Access policies... and we have single sign on! Awesome! While explaining the flow to some people
Edwin de Bruin
19 jan 20232 minuten om te lezen


Microsoft November Updates and breaking TrueSSO
First of all happy new year everyone! On 31 december 2022 New Years Eve I got a message from a colleague of mine while eating "oliebollen" with the family at friends of ours. One customer is having issues with external login's to their VMware Horizon environment. They get stuck on the Imprivata login screen. Alltough the user can login by re-entering their credentials it is annoying. The fact Imprivata selected the default domain to be the local machine and the user has to sw
Edwin de Bruin
1 jan 20232 minuten om te lezen


Using VMware Access and Imprivata ConfirmID for remote Access as MFA solution
Lately a lot has been written about the EOL of VMware Verify. But… what if you are already used to Imprivata and maybe have the Confirm ID for remote access licenses around? Can we use this instead? Yes you can! How? By connecting to Imprivata with RADIUS. Is this new? Nope… they even call this the legacy experience. But sometimes legacy is just what you might need so he ho, let’s go! Of course: As an alternative to this you can use the VMware Authenticator or Intelligent HU
Edwin de Bruin
20 sep 20226 minuten om te lezen


Imprivata and the Kerberos Keytab file
When using VMware Horizon, VMware Workspace One Access, TrueSSO and Imprivata you need to enable Kerberos Authentication within Imprivata. For this to work you also need to create a keytab file. In this blog I will explain how to create one and as a bonus.. can we use a custom account for this instead of the default created by the tool? Imprivata has a built in utility to facilitate this: ISXKerbUtil.exe. Normally you can find this utility in the OneSign Agent install directo
Edwin de Bruin
1 sep 20223 minuten om te lezen


Call me IDP - Workspace ONE Access with Microsoft Office 365
A man browsed down the Login Page He says, "Why am I short of attention? Got a short little span of attention And, whoa, my logins are so long Where's my Credentials and TOTP? What if I die here? Who'll be my role model Now that my role model is gone, gone?" He ducked back down the alley With some roly-poly little login tool All along, along There were Username and passwords There were hints and allegations [Chorus] If you'll be my IDP I can be your long lost SP I can call yo
Edwin de Bruin
27 jun 20222 minuten om te lezen


The View Agent reports that this desktop source is unable to accept connections.
Last week I was exposing my VMware Horizon environment externally. Of course I wanted the single sign on experience. So enrolled the Workspace One Access tennant, deployed the sync server.. configured directory sync, authentication rules, next Virtual Apps etc . On the connector SAML to required, configured SAML authenticator to Access, connector in Workspace One mode, deployed enrollment server, created TrueSSO template, configured TrueSSO, deployed UAGS etc etc and let the
Edwin de Bruin
17 feb 20222 minuten om te lezen
Blog: Blog2
bottom of page