Administration

Table Of Contents
What to do next
Congure the SAML authenticator used for delegating authentication to VMware Identity Manager. See
“Congure SAML Authentication to Work with True SSO,” on page 85.
Configure SAML Authentication to Work with True SSO
With the True SSO feature introduced in Horizon 7, users can log in to VMware Identity Manager 2.6 and
later releases using smart card, RADIUS, or RSA SecurID authentication, and they will no longer be
prompted for Active Directory credentials, even when they launch a remote desktop or application for the
rst time.
With earlier releases, SSO (single sign-on) worked by prompting users for their Active Directory credentials
the rst time they launched a remote desktop or published application if they had not previously
authenticated with their Active Directory credentials. The credentials were then cached so that subsequent
launches would not require users to re-enter their credentials. With True SSO, short-term certicates are
created and used instead of AD credentials.
Although the process for conguring SAML authentication for VMware Identity Manager has not changed,
one additional step has been added for True SSO. You must congure VMware Identity Manager so that
password pop-ups are suppressed.
N If your deployment includes more than one View Connection Server instance, you must associate the
SAML authenticator with each instance.
Prerequisites
n
Verify that single sign-on is enabled as a global seing. In View Administrator, select  >
Global , and verify that Single sign-on (SSO) is set to Enabled.
n
Verify that VMware Identity Manager is installed and congured. See the VMware Identity Manager
documentation, available at hps://www.vmware.com/support/pubs/vidm_pubs.html
n
Verify that the root certicate for the signing CA for the SAML server certicate is installed on the
connection server host. VMware does not recommend that you congure SAML authenticators to use
self-signed certicates. See the topic "Import a Root Certicate and Intermediate Certicates into a
Windows Certicate Store," in the chapter "Conguring SSL Certicates for View Servers," in the View
Installation document.
n
Make a note of the FQDN of the VMware Identity Manager server instance.
Procedure
1 In Horizon Administrator, select  > Servers.
2 On the Connection Servers tab, select a server instance to associate with the SAML authenticator and
click Edit.
3 On the Authentication tab, from the Delegation of authentication to VMware Horizon (SAML 2.0
Authenticator) drop-down menu, select Allowed or Required.
You can congure each View Connection Server instance in your deployment to have dierent SAML
authentication seings, depending on your requirements.
4 Click Manage SAML Authenticators and click Add.
5 Congure the SAML authenticator in the Add SAML 2.0 Authenticator dialog box.
Option Description
Label
You can use the FQDN of the VMware Identity Manager server instance.
Description
(Optional) You can use the FQDN of the VMware Identity Manager server
instance.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 85