SSO Validation

In this section, we will validate that the SSO configuration is working on our iOS device.

1. Open Settings

Open Settings

Tap Settings.

Navigate to General Settings, Digital Workspace
  1. Tap General.
  2. Scroll down to find the Device Management option.
  3. Tap Device Management.

3. Open the Digital Workspace profile

Open the Digital Workspace profile

Tap the Workspace Services profile.

4. View More Details

View More Details

Tap More Details.

5. Open the Singe Sign On Account

Open the Singe Sign On Account

You should see the Single Sign On Account that you added in the Profile created in the previous section.

Tap testsso.

6. Verify Settings

Verify Settings

Verify that the following Single Sign-On settings are correct:

  1. Principal Name is set to "aduser".
  2. Realm is set to VIDMPREVIEW.COM.
  3. URL Prefix Matches is set to "https://{tenantName}.vidmpreview.com/".  This URL will be your VMware Identity Manager Tenant URL.
  4. Eligible App IDs includes "com.apple.mobilesafari".

NOTE - If any of these settings are incorrect, return to the AirWatch Console and inspect your iOS Identity KDC Cert Profile that was previously created.

7. Clear the Safari Cache

Clear the Safari Cache

Navigate back to the main Settings page.

  1. Scroll down to find the Safari settings.
  2. Tap Safari.
  3. Scroll down to find Clear History and Website Data.
  4. Tap Clear History and Website Data.

8. Confirm the Clear History and Data Prompt

Click Clear.

9. Launch Safari on the iOS Device

Launch Safari on the iOS Device

Tap the Safari icon, it should be on the bottom tray.

Navigate to Identity Manager in Safari
  1. Enter the URL of your Identity Manager tenant in the URL bar.
  2. Click Go

11. Workspace One Single Sign-On

Workspace One Single Sign-On

Notice that Identity Manager is signing you in without requiring any authentication.

12. Identity Manager Application Catalog

Identity Manager Application Catalog

You are now signed into Workspace One using Single Sign On automatically without having to enter any credentials!

There are no applications visible because they haven't been added in Identity Manager or AirWatch.