Configure Workspace ONE Access
This section walks through creating and configuring the Web App inside WSOA.Step 1: Create a new Web App
Log in to the WSOA user interface and navigate to Resources → Web Apps → New.

Step 2: Configure Single Sign-On
On the Single Sign-On page, configure the authentication type and endpoint URLs. The SSO URL and Recipient URL both point to Omni’s Assertion Consumer Service endpoint, and the Application ID points to its SAML metadata URL.
Step 3: Configure advanced signing properties
Still on the Single Sign-On page, scroll to the Advanced Properties section and set the following toggles. The key settings here are enabling assertion signing (required by Omni) while leaving response signing and assertion encryption off.
Step 4: Map custom attributes
At the bottom of the Single Sign-On page, add the following entries in the Custom Attribute Mapping section. These attributes allow Omni to identify users and apply group-based role assignments.
Step 5: Select an access policy
Click Next and select the access policy required by your organization.
Step 6: Assign users and groups
Click Save & Assign and configure who is permitted to log in to Omni.- Select the permitted group from your Active Directory or LDAP server.
- Set Deployment Type to Automatic.


Step 7: Obtain the IdP metadata URL
Navigate to Settings and click Copy URL to copy the IdP metadata URL.
Copy this URL — you will pass it to Omni as the
--auth-saml-url flag in the next step.
Configure Omni to use Workspace ONE Access
Pass the following flags to the Omni container at startup to enable SAML authentication. Alternatively, you can set these values in the Omni configuration file instead of passing them as CLI flags.
For example:
saml.omni.sidero.dev/groups/ rather than a role name directly. For example: