Administration

Table Of Contents
n
(Optional) If you are using Workspace ONE or VMware Identity Manager, make a note of the URL of
the connector Web interface.
n
If you are creating an authenticator for Unified Access Gateway or a third-party appliance that
requires you to generate SAML metadata and create a static authenticator, perform the procedure on
the device to generate the SAML metadata, and then copy the metadata.
Procedure
1 In Horizon Administrator, select Configuration > Servers.
2 On the Connection Servers tab, select a server instance to associate with the SAML authenticator
and click Edit.
3 On the Authentication tab, select a setting from the Delegation of authentication to VMware
Horizon (SAML 2.0 Authenticator) drop-down menu to enable or disable the SAML authenticator.
Option Description
Disabled SAML authentication is disabled. You can launch remote desktops and
applications only from Horizon Client.
Allowed SAML authentication is enabled. You can launch remote desktops and
applications from both Horizon Client and VMware Identity Manager or the third-
party device.
Required SAML authentication is enabled. You can launch remote desktops and
applications only from VMware Identity Manager or the third-party device. You
cannot launch desktops or applications from Horizon Client manually.
You can configure each Connection Server instance in your deployment to have different SAML
authentication settings, depending on your requirements.
4 Click Manage SAML Authenticators and click Add.
5 Configure the SAML authenticator in the Add SAML 2.0 Authenticator dialog box.
Option Description
Type For Unified Access Gateway or a third-party device, select Static. For
VMware Identity Manager select Dynamic. For dynamic authenticators, you can
specify a metadata URL and an administration URL. For static authenticators, you
must first generate the metadata on the Unified Access Gateway or a third-party
device, copy the metadata, and then paste it into the SAML metadata text box.
Label Unique name that identifies the SAML authenticator.
Description Brief description of the SAML authenticator. This value is optional.
Metadata URL (For dynamic authenticators) URL for retrieving all of the information required to
exchange SAML information between the SAML identity provider and the
Connection Server instance. In the URL https://<YOUR HORIZON SERVER
NAME>/SAAS/API/1.0/GET/metadata/idp.xml, click <YOUR HORIZON
SERVER NAME> and replace it with the FQDN or IP address of the
VMware Identity Manager server or external-facing load balancer (third-party
device).
Administration URL (For dynamic authenticators) URL for accessing the administration console of the
SAML identity provider. For VMware Identity Manager, this URL should point to
the VMware Identity Manager Connector Web interface. This value is optional.
View Administration
VMware, Inc. 71