Administration

Table Of Contents
2 On the Connection Servers tab, select a server instance to associate with the SAML authenticator
and click Edit.
3 On the Authentication tab, from the Delegation of authentication to VMware Horizon (SAML 2.0
Authenticator) drop-down menu, select Allowed or Required.
You can configure each View Connection Server instance in your deployment to have different SAML
authentication settings, depending on your requirements.
4 Click Manage SAML Authenticators and click Add.
5 Configure the SAML authenticator in the Add SAML 2.0 Authenticator dialog box.
Option Description
Label You can use the FQDN of the VMware Identity Manager server instance.
Description (Optional) You can use the FQDN of the VMware Identity Manager server
instance.
Metadata URL URL for retrieving all of the information required to exchange SAML information
between the SAML identity provider and the View Connection Server instance. In
the URL https://<YOUR HORIZON SERVER
NAME>/SAAS/API/1.0/GET/metadata/idp.xml, click <YOUR HORIZON
SERVER NAME> and replace it with the FQDN of the VMware Identity Manager
server instance.
Administration URL URL for accessing the administration console of the SAML identity provider
(VMware Identity Manager instance). This URL has the format
https://<Identity-Manager-FQDN>:8443.
6 Click OK to save the SAML authenticator configuration.
If you provided valid information, you must either accept the self-signed certificate (not
recommended) or use a trusted certificate for View and VMware Identity Manager.
The SAML 2.0 Authenticator drop-down menu displays the newly created authenticator, which is
now set as the selected authenticator.
7 In the System Health section on the View Administrator dashboard, select Other components >
SAML 2.0 Authenticators, select the SAML authenticator that you added, and verify the details.
If the configuration is successful, the authenticator's health is green. An authenticator's health can
display red if the certificate is untrusted, if the VMware Identity Manager service is unavailable, or if
the metadata URL is invalid. If the certificate is untrusted, you might be able to click Verify to validate
and accept the certificate.
8 Log in to the VMware Identity Manager administration console, go to the View Pools page, and select
the Suppress Password Popup check box.
What to do next
n
Extend the expiration period of the View Connection Server metadata so that remote sessions are not
terminated after only 24 hours. See Change the Expiration Period for Service Provider Metadata on
Connection Server.
View Administration
VMware, Inc. 99