Administration

Table Of Contents
Option Description
Metadata URL (For dynamic authenticators) URL for retrieving all of the information required
to exchange SAML information between the SAML identity provider and the
Connection Server instance. In the URL https://<YOUR HORIZON SERVER
NAME>/SAAS/API/1.0/GET/metadata/idp.xml, click <YOUR HORIZON
SERVER NAME> and replace it with the FQDN or IP address of the VMware
Identity Manager server or external-facing load balancer (third-party device).
Administration URL (For dynamic authenticators) URL for accessing the administration console of
the SAML identity provider. For VMware Identity Manager, this URL should
point to the VMware Identity Manager Connector Web interface. This value is
optional.
SAML metadata (For static authenticators) Metadata text that you generated and copied from
the Unified Access Gateway or a third-party device.
Enabled for Connection Server Select this check box to enable the authenticator. You can enable multiple
authenticators. Only enabled authenticators are displayed in the list.
6 Click OK to save the SAML authenticator configuration.
If you provided valid information, you must either accept the self-signed certificate (not
recommended) or use a trusted certificate for Horizon 7 and VMware Identity Manager or
the third-party device.
The Manage SAML Authenticators dialog box displays the newly created authenticator.
7 In the System Health section on the Horizon Administrator dashboard, select Other
components > SAML 2.0 Authenticators, select the SAML authenticator that you added, and
verify the details.
If the configuration is successful, the authenticator's health is green. An authenticator's health
can display red if the certificate is untrusted, if VMware Identity Manager is unavailable, or if
the metadata URL is invalid. If the certificate is untrusted, you might be able to click Verify to
validate and accept the certificate.
What to do next
Extend the expiration period of the Connection Server metadata so that remote sessions are not
terminated after only 24 hours. See Change the Expiration Period for Service Provider Metadata
on Connection Server.
Configure Proxy Support for VMware Identity Manager
Horizon 7 provides proxy support for the VMware Identity Manager (vIDM) server. The proxy
details such as hostname and port number can be configured in the ADAM database and the HTTP
requests are routed through the proxy.
This feature supports hybrid deployment where the on-premise Horizon 7 deployment can
communicate with a vIDM server that is hosted in the cloud.
Prerequisites
Horizon 7 Administration
VMware, Inc. 78