Skip to main content
This guide walks through creating a Web App in Workspace ONE Access (WSOA) and configuring Omni to authenticate against it via SAML.

Configure Workspace ONE Access

This section walks through creating and configuring the Web App inside WSOA.

Step 1: Create a new Web App

Log in to the WSOA user interface and navigate to Resources → Web Apps → New. Workspace ONE Access Web Apps page Enter the following values to identify the application, then click Next. Web App definition settings

Step 2: Configure Single Sign-On

On the Single Sign-On page, configure the authentication type and endpoint URLs. The SSO URL and Recipient URL both point to Omni’s Assertion Consumer Service endpoint, and the Application ID points to its SAML metadata URL. Single Sign-On authentication type settings

Step 3: Configure advanced signing properties

Still on the Single Sign-On page, scroll to the Advanced Properties section and set the following toggles. The key settings here are enabling assertion signing (required by Omni) while leaving response signing and assertion encryption off. Advanced signing properties

Step 4: Map custom attributes

At the bottom of the Single Sign-On page, add the following entries in the Custom Attribute Mapping section. These attributes allow Omni to identify users and apply group-based role assignments. Custom attribute mapping configuration

Step 5: Select an access policy

Click Next and select the access policy required by your organization. Access policy selection

Step 6: Assign users and groups

Click Save & Assign and configure who is permitted to log in to Omni.
  • Select the permitted group from your Active Directory or LDAP server.
  • Set Deployment Type to Automatic.
Save and assign screen Application assignment configuration

Step 7: Obtain the IdP metadata URL

Navigate to Settings and click Copy URL to copy the IdP metadata URL. Settings page showing Copy URL link
Copy this URL — you will pass it to Omni as the --auth-saml-url flag in the next step.
SAML metadata download settings

Configure Omni to use Workspace ONE Access

Pass the following flags to the Omni container at startup to enable SAML authentication. Alternatively, you can set these values in the Omni configuration file instead of passing them as CLI flags. For example:
Once Omni is running with these flags, refer to the Auto-assign roles to SAML users guide to automatically assign roles based on SAML group attributes. When using groups, the label prefix is saml.omni.sidero.dev/groups/ rather than a role name directly. For example: