<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure MFA SSO + Horizon client login in Horizon Desktops and Apps</title>
    <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2953532#M98609</link>
    <description>&lt;P&gt;Did you manage to autoclose the webpage ?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 15:03:07 GMT</pubDate>
    <dc:creator>WouterKeus</dc:creator>
    <dc:date>2023-02-09T15:03:07Z</dc:date>
    <item>
      <title>Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2931907#M97854</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have setup Azure MFA for Unified Access Gateway authentication and all working fine. The only issue we have is that once authenticated through Azure i.e. after the user is redirected to the Azure logon to enter their UPN/password and MFA details, the Horizon Client then loads but also requires network credentials again from the user. Ideally we wanted to remove this given the user has already authenticated once. We've looked at TRUESSO and set it up in a test environment but that doesn't seem remove the requirement to sign into the Horizon client. Also tried the 'login as current user' setting in the client, that also doesn't work and the user is still required to login to the Horizon client.&lt;/P&gt;&lt;P&gt;Any suggestions how we remove the requirement to login into the Horizon client after successfully authenticating through Azure MFA?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 14:03:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2931907#M97854</guid>
      <dc:creator>TBC-Gareth</dc:creator>
      <dc:date>2022-10-04T14:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932008#M97859</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5581608"&gt;@TBC-Gareth&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check my blog posts on&amp;nbsp;&lt;A href="https://itpro.peene.be/vmware-horizon-authentication-using-azuread-with-multifactor/" target="_self"&gt;VMware Horizon authentication using AzureAD (with multifactor) – MickeyByte IT Pro Blog&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I think the SAML part (&lt;A href="https://itpro.peene.be/vmware-horizon-authentication-using-azuread-with-multifactor-part-4-saml-setup/" target="_self"&gt;VMware Horizon authentication using AzureAD (with multifactor) – Part 4: SAML Setup – MickeyByte IT Pro Blog&lt;/A&gt;) will be the one you need to double-check to see if everything is setup correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 06:18:13 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932008#M97859</guid>
      <dc:creator>Mickeybyte</dc:creator>
      <dc:date>2022-10-05T06:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932080#M97862</link>
      <description>&lt;P&gt;Thanks for that&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5451386"&gt;@Mickeybyte&lt;/a&gt;&amp;nbsp;,guides really useful. Checked the SAML setup and I had the auth method in the UAG Horizon settings set to SAML and Passthrough rather than just SAML. Now only requires the Azure credentials.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 13:44:04 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932080#M97862</guid>
      <dc:creator>TBC-Gareth</dc:creator>
      <dc:date>2022-10-05T13:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932092#M97864</link>
      <description>&lt;P&gt;Good to hear its fixed, Thanks for sharing.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 14:51:02 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932092#M97864</guid>
      <dc:creator>smut5203</dc:creator>
      <dc:date>2022-10-05T14:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932368#M97876</link>
      <description>&lt;P&gt;Great writeup&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5451386"&gt;@Mickeybyte&lt;/a&gt;&amp;nbsp;- thanks for sharing! We have identical setup, Horizon 8.6, UAG 2207 with Azure SAML and TrueSSO like this, works perfectly with the HTML client. We do though have some challenges getting a native client initiated session to come back to the native client after authentication, it stays at the /portal/webclient page.&lt;/P&gt;&lt;P&gt;I can't find anywhere that someone actually has shown that working or what needs to be changed in the config, besides in this video:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=asLT1aHrBvM" target="_blank"&gt;https://www.youtube.com/watch?v=asLT1aHrBvM&lt;/A&gt;&amp;nbsp;(which is with Okta, though SAML, hence same-same ...)&lt;/P&gt;&lt;P&gt;In your setup, does it redirect back to a native client session after authentication and MFA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 08:04:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932368#M97876</guid>
      <dc:creator>5teelman</dc:creator>
      <dc:date>2022-10-07T08:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932687#M97887</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/3621739"&gt;@5teelman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, after logon to Azure, the native client pops up again showing the available pools for that user. However, the webpage used for the sign-on doesn't closes itself, so it stays in the back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 06:28:39 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932687#M97887</guid>
      <dc:creator>Mickeybyte</dc:creator>
      <dc:date>2022-10-10T06:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932930#M97895</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5451386"&gt;@Mickeybyte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in our case the native client tells me this in it's log when I try to connect (authentication in Azure with MFA done successfully):&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2022-10-10T13:04:58.726+02:00 EROR (01) [libsdk] : Cdk::ErrorCallback:866: The task 'CdkGetConfigurationTask' failed with error: Your client was not launched with valid SAML2 credentials. Please contact your Administrator. (domain=55, code=3).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2022-10-10T13:04:58.752+02:00 EROR (01) [libsdk] : ServerErrorHandler::OnError:71: Handling error 'Your client was not launched with valid SAML2 credentials. Please contact your Administrator.' (domain=55(CDK_BROKER_ERROR), code=3) from task CdkGetConfigurationTask.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2022-10-10T13:04:58.752+02:00 INFO (01) [libsdk] : Server::HandoffToWorkspaceOne:1628: (26474C6C0D0) &lt;STRONG&gt;The server is in Workspace ONE mode: uag.corp.com/portal/nativeclient&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2022-10-10T13:04:58.752+02:00 INFO (01) [ServerService] Handoff:1131 Handing off to &lt;A href="https://uag.corp.com/portal/nativeclient" target="_blank"&gt;https://uag.corp.com/portal/nativeclient&lt;/A&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2022-10-10T13:04:59.146+02:00 INFO (01) [ServerService] Shutdown:213 The client is forcibly shutting down, clear all pending actions...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2022-10-10T13:04:59.147+02:00 INFO (01) [ServerService] Shutdown:228 The server &lt;A href="https://uag.corp.com/" target="_blank"&gt;https://uag.corp.com/&lt;/A&gt; has no session. Will quit after logged out.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2022-10-10T13:04:59.147+02:00 INFO (01) [client] Disconnect:1205 The server &lt;A href="https://uag.corp.com/" target="_blank"&gt;https://uag.corp.com/&lt;/A&gt; is disconnecting...&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;But the CS isn't:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5teelman_1-1665473617743.png" style="width: 400px;"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/97736i413B56473D1876BF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="5teelman_1-1665473617743.png" alt="5teelman_1-1665473617743.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5teelman_0-1665473527315.png" style="width: 400px;"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/97735iFE49662B95AC73D7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="5teelman_0-1665473527315.png" alt="5teelman_0-1665473527315.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I continue with the HTML portal, the VDI opens without further authentication, hence SAML and TrueSSO works.&lt;/P&gt;&lt;P&gt;As we're on the latest versions of all components (client, uag, Horizon CS), and all configs are done "by the book", I guess this will end as a ticket with support. I really cannot see anything that should lead the client and/or CS to see this as &lt;EM&gt;Workspace ONE mode&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 07:41:21 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932930#M97895</guid>
      <dc:creator>5teelman</dc:creator>
      <dc:date>2022-10-11T07:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932937#M97896</link>
      <description>&lt;P&gt;Sorry for doblepost due to erroneously "spam posting" message from the website &lt;img class="lia-deferred-image lia-image-emoji" src="https://communities.vmware.com/html/@E73D2BD5EE4D86E7826FC46445719090/emoticons/1f602.png" alt=":face_with_tears_of_joy:" title=":face_with_tears_of_joy:" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:15:37 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2932937#M97896</guid>
      <dc:creator>5teelman</dc:creator>
      <dc:date>2022-10-12T14:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2933243#M97915</link>
      <description>&lt;P&gt;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/3621739"&gt;@5teelman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is definitely very strange. The best thing indeed is to open a support case for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:03:03 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2933243#M97915</guid>
      <dc:creator>Mickeybyte</dc:creator>
      <dc:date>2022-10-12T14:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2933987#M97934</link>
      <description>&lt;P&gt;OK, so we figured out what was the issue - the BigIP in front of the UAG.&lt;/P&gt;&lt;P&gt;We did an upgrade from 15.1.5.1 to 15.1.7 and recreated the profiles there from the iApp&amp;nbsp;&lt;SPAN&gt;f5.vmware_view.v1.5.9&amp;nbsp;package, and ta-daa - it worked. No other changes on UAG or CS, hence something in the old (working with Horizon7) config fooled us here ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The only "nag" now is the browser window that's not closing, but it should be possible to autoclose with some scripting if needed.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 11:52:28 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2933987#M97934</guid>
      <dc:creator>5teelman</dc:creator>
      <dc:date>2022-10-17T11:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2953532#M98609</link>
      <description>&lt;P&gt;Did you manage to autoclose the webpage ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 15:03:07 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2953532#M98609</guid>
      <dc:creator>WouterKeus</dc:creator>
      <dc:date>2023-02-09T15:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Azure MFA SSO + Horizon client login</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2953535#M98610</link>
      <description>&lt;P&gt;We haven't done anything about it yet, hence the users just close it themselves - or reuses the browser for something else anyway. It should though be some "autoclose timer feature" in the webservice made available as an option by VMware in the config&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://communities.vmware.com/html/@677206E94727C39F3BB2721E5A55F2C1/emoticons/1f609.png" alt=":winking_face:" title=":winking_face:" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 15:10:27 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Azure-MFA-SSO-Horizon-client-login/m-p/2953535#M98610</guid>
      <dc:creator>5teelman</dc:creator>
      <dc:date>2023-02-09T15:10:27Z</dc:date>
    </item>
  </channel>
</rss>

