Administration

Table Of Contents
n The shared secret values on the Connection Server instance and the RADIUS server do not
match.
Using SAML Authentication
The Security Assertion Markup Language (SAML) is an XML-based standard that is used to
describe and exchange authentication and authorization information between different security
domains. SAML passes information about users between identity providers and service providers
in XML documents called SAML assertions.
You can use SAML authentication to integrate VMware Horizon with VMware Workspace ONE,
VMware Identity Manager, or a qualified third-party load balancer or gateway. When configuring
SAML for a third-party device, refer to the vendor documentation for information on configuring
VMware Horizon to work with it. When SSO is enabled, users who log in to VMware Identity
Manager or a third-party device can launch remote desktops and applications without having to
go through a second login procedure. You can also use SAML authentication to implement smart
card authentication on VMware United Access Gateway, or on third-party devices.
To delegate responsibility for authentication to Workspace ONE, VMware Identity Manager,
or a third-party device, you must create a SAML authenticator in VMware Horizon. A
SAML authenticator contains the trust and metadata exchange between VMware Horizon and
Workspace ONE, VMware Identity Manager, or the third-party device. You associate a SAML
authenticator with a Connection Server instance.
Using SAML Authentication for VMware Identity Manager Integration
Integration between Horizon 7 and Workspace ONE (formerly called VMware Identity Manager)
uses the SAML 2.0 standard to establish mutual trust, which is essential for single sign-on (SSO)
functionality. When SSO is enabled, users who log in to VMware Identity Manager or Workspace
ONE with Active Directory credentials can launch remote desktops and applications without
having to go through a second login procedure.
When VMware Identity Manager and Horizon 7 are integrated, VMware Identity Manager
generates a unique SAML artifact whenever a user logs in to VMware Identity Manager and
clicks a desktop or application icon. VMware Identity Manager uses this SAML artifact to create
a Universal Resource Identifier (URI). The URI contains information about the Connection Server
instance where the desktop or application pool resides, which desktop or application to launch,
and the SAML artifact.
VMware Identity Manager sends the SAML artifact to the Horizon client, which in turn sends the
artifact to the Connection Server instance. The Connection Server instance uses the SAML artifact
to retrieve the SAML assertion from VMware Identity Manager.
After a Connection Server instance receives a SAML assertion, it validates the assertion, decrypts
the user's password, and uses the decrypted password to launch the desktop or application.
Horizon 7 Administration
VMware, Inc. 75