VMware Workspace ONE Community
ShaunBinkley
Enthusiast
Enthusiast

SSO to UEM from IDM

Hi Folks, I've been having a play on some of the VMware test drive instances and noticed that I am able to load the UEM console from the WS1 user portal. They've created an app icon and it SSOs me into the UEM console. Does anyone know how to set this up? Struggling to find documentation online. You can imagine the minefield using terms such as 'Workspace One', 'SSO', 'UEM'.
Labels (1)
0 Kudos
5 Replies
MHaagSoehner
Enthusiast
Enthusiast

Hey Shaun,


yeah, do the following:


1. Log in to your Identity Manager tenant and navigate to Catalog >> Settings.
2. Click on SAML Metadata and open the link ' Identity Provider (IdP) metadata' . Download that XML file and keep it ready for the next step.
3. Log in to your Workspace ONE environment and navigate to Settings >> System >> Enterprise Integration >> Directory Services.
4. Scroll down and switch ' Use SAML for Authentication'  to Enabled and remove the checkboxes for Enrollment + SSP.
5. Upload the XML file you just downloaded in the ' Import Identity Provider Settings'  dialogue. Make sure to save the page after you uploaded it to populate all fields.
6 Change the ' Service Provider (AirWatch) ID'  to something unique, for example ' AirWatchCompanyName' . It's just to identify your environment.
7. Go back to the Identity Manager and add a new web app.
8. Use the ' Search the catalog'  link to search for the app ' AirWatch Admin'  (The app just called ' AirWatch'  is for the Self service portal).
9. Under configuration:
- Scroll down to application parameters and enter your AirWatch server URI (in format f.ex. cnXXX.awmdm.com), your highes Group ID and the Service Provider ID that you entered in the WSONE console.
10. You also might have to change the format of the username. If you use Active Directory users for administrators you have to change the username value to ' domain or ${user.UserName}'  and set the ' Username format'  to ' User Principal Name' .


And that should be it.


Hope this helps, have a great weekend!

0 Kudos
ShaunBinkley
Enthusiast
Enthusiast

Thanks Maximillian, have you done this in an on-prem environment? Is it possible the URLs have been updated? I'm struggling to get back in, leaning towards DB restore so I can log into UEM again.
0 Kudos
Stansfield
Enthusiast
Enthusiast

You should have a local root administrator account for the system, you should be able to login with that even if ad login is broken
0 Kudos
MHaagSoehner
Enthusiast
Enthusiast

Hey Shaun,

no, I'm a SaaS customer.
0 Kudos
ShaunBinkley
Enthusiast
Enthusiast

Cheers guys, will revisit this soon and post an update
0 Kudos