VMware Horizon login with SAML or OIDC using Integrity WEB as third-party IdP

Adds login methods found in Integrity WEB such as MFA, Swedish BankID, Swedish Freja eID, SITHS etc. to be used when authenticating to the VMware Horizon service

By using Fortified ID Integrity WEB services as a third-party SAML IdP or OpenID Connect (OIDC) OP in combination with Workspace ONE Access (formerly VMware Identity Manager) you can add login method available in Integrity WEB for the users to use when they are using VMware Horizon.

Prerequisites

SAML

  • Workspace ONE Access service installed and connected with Horizon

  • Integrity WEB installed and configured as an SAML IdP service

  • Connectivity between Workspace ONE Access service and the Integrity WEB instance.

  • Obtain the appropriate metadata information to add when you configure the identity provider in the Workspace ONE Access console and in the Integrity WEB configuration.

OpenID Connect (OIDC)

  • Workspace ONE Access service installed and connected with Horizon

  • Integrity WEB installed and configured as an OpenID Connect (OIDC) OP service.

    • The authorization_code grant configured.

    • The redirect_uri is set to the Workspace ONE Access callback endpoint.

  • Connectivity between Workspace ONE Access service and the Integrity WEB instance.

  • The well-known URL of the OpenID Connect (OIDC) OP configuration.

Configuration of Workspace ONE Access service and Integrity WEB

SAML

  • See the following link for the steps to configure SAML in the Workspace ONE Access service.

  • See the following link for Integrity Web SAML use case examples. Any of the login methods available in Integrity WEB can be used to login to Workspace ONE Access service like MFA, Swedish BankID, Swedish Freja eID, SITHS, etc.. .

    • Make sure to configure and provide all needed claims.

OpenID Connect (OIDC)

  • See the following link for the steps to configure OpenID Connect (OIDC) in the Workspace ONE Access service.

  • See the following link for Integrity Web SAML use case examples. Any of the login methods available in Integrity WEB can be used to login to Workspace ONE Access service like MFA, Swedish BankID, Swedish Freja eID, SITHS, etc..

    • Make sure to configure and provide all needed claims.

Comment

For best user experience we recommend to use the True SSO (Single Sign-On) functionality available in the Horizon Connection Server.

Last updated