Administration

Table Of Contents
2 On the Connection Servers tab, select a server instance to associate with the SAML
authenticator and click Edit.
3 On the Authentication tab, from the Delegation of authentication to VMware Horizon (SAML
2.0 Authenticator) drop-down menu, select Allowed or Required.
You can configure each Connection Server instance in your deployment to have different
SAML authentication settings, depending on your requirements.
4 Click Manage SAML Authenticators and click Add.
5 Configure the SAML authenticator in the Add SAML 2.0 Authenticator dialog box.
Option Description
Label You can use the FQDN of the VMware Identity Manager server instance.
Description (Optional) You can use the FQDN of the VMware Identity Manager server
instance.
Metadata URL URL for retrieving all of the information required to exchange SAML
information between the SAML identity provider and the Horizon Connection
Server instance. In the URL https://<YOUR HORIZON SERVER NAME>/
SAAS/API/1.0/GET/metadata/idp.xml, click <YOUR HORIZON SERVER
NAME> and replace it with the FQDN of the VMware Identity Manager server
instance.
Administration URL URL for accessing the administration console of the SAML identity provider
(VMware Identity Manager instance). This URL has the format https://
<Identity-Manager-FQDN>:8443.
6 Click OK to save the SAML authenticator configuration.
If you provided valid information, you must either accept the self-signed certificate (not
recommended) or use a trusted certificate for Horizon 7 and VMware Identity Manager.
The SAML 2.0 Authenticator drop-down menu displays the newly created authenticator,
which is now set as the selected authenticator.
7 In the System Health section on the Horizon Administrator dashboard, select Other
components > SAML 2.0 Authenticators, select the SAML authenticator that you added, and
verify the details.
If the configuration is successful, the authenticator's health is green. An authenticator's health
can display red if the certificate is untrusted, if the VMware Identity Manager service is
unavailable, or if the metadata URL is invalid. If the certificate is untrusted, you might be able
to click Verify to validate and accept the certificate.
8 Log in to the VMware Identity Manager administration console, navigate to the desktop pool
from the Catalog > Virtual Apps page, and select the True SSO Enabled check box.
Horizon 7 Administration
VMware, Inc. 108