Omnissa Secure Access Suite
UEM Admin Username: [email protected]
UEM Admin Password: Pa$$w0rd
Access URL: https://@lab.Variable(tenantName).us0.wss.workspaceone.com
Access Admin Username: [email protected](tenantName)@euclabuat.com
Access Password Reset URL: @lab.Variable(AccessURL)
@lab.Activity(Automated1)
Google Admin Console: https://admin.google.com
Google Admin Account: [email protected](tenantName)@euclabuat.com
Google Admin Password: TempPassword123!
Google Test Account: [email protected](tenantName)@euclabuat.com
Google Password: TempPassword123!
Objective
In this lab, you will gain hands-on experience configuring and testing Omnissa Secure Access Suite. Working through a series of guided exercises, you will set up enterprise security policies, enforce data loss prevention controls, integrate identity and access management, and validate the end-to-end behavior of these controls using Chrome Profile on unmanaged devices.
- Assigning Chrome Enterprise Premium License
- Configure Chrome Enterprise Premium with foundational security and reporting policies
- Deploy and enforce Endpoint Verification across devices
- Define Application Boundaries to prevent data leakage between trusted and untrusted destinations
- Build Data Loss Prevention (DLP) rules to safeguard sensitive information
- Integrate Omnissa Access with the Chrome Admin Console for SSO and compliance
- Validate security policies on Un-managed device
- Test URL filtering policies for Generative AI and other restricted sites
The first step to configure Chrome Enterprise Premium would be to enable/check if the targeted student user account has the Chrome Enterprise Premium License assigned. To validate the assignment follow the steps below.
Pre-requisites
Before you begin , ensure you have the following which can be found on the right side of your screen once you launch your lab.
Select Instructions to view,
- Access URL
- Access Admin Username.
- Access Password Reset URL - Please reset the password to
TempPassword123!using the Reset URL provided in the lab instructions. - Google Admin Account
- Google Admin password
- Google Test account
- Google Test account password
Select Resource tab to view Control Center and Windows Virtual Machine (W11Client-01) credentials.
Instructions to launch Control Center or Windows Virtual Machine
- Launch the lab using the URL provided.
- During the lab you will need to move between the Control Center and the Windows Virtual machine , use the drop down as shown above to navigate between Control Center and the Windows Virtual Machine.
- To log into the Windows Virtual Machine or Control Center ,click the Keyboard icon and click CTRL+Alt+Delete.
- Wait for the login screen.
- Enter your Admin Password-
Pa$$w0rd. - Press Enter or click the Arrow to log in.
Log into Google Admin console
- Log into the Control Center.
- On the Windows Desktop , locate the Google Chrome browser icon.
- Double-click the Google Chrome icon to launch the browser.
- Wait for Chrome to open and display the start page.
- In the Chrome address bar , type the following URL
https://admin.google.com. - Press Enter to navigate to the Google Admin sign-in page.
- On the sign-in page , enter your Google Admin username it should be of the format
[email protected](tenantName)@euclabuat.com - Enter Google Admin password -
TempPassword123!and click Next. - Click I understand.
- If you are prompted to Select Continue as [email protected](tenantName) or use Chrome without an account , select Use Chrome without an account.
- Click Get set up.
Assigning Chrome Enterprise License
Once logged in , navigate to Directory > Users.
Enter your user account
[email protected](tenantName)in the search filter.
- Click the OU
[email protected](tenantName)to select it. Select [email protected](tenantName) LabUser.
- Click on Assign Licenses.
- Select Chrome Enterprise Premium(offline pricing)
- Click Assign
Note: For any Login issues or License assignment issues reach out to the Lab Instructor
Force Install Endpoint verification extension
Endpoint Verification is a key element of a zero-trust security framework, gathering critical device information required to define and enforce device-based access policies. In this task you will be configuring an extension which ensures the device attributes like operating system , device model and encryption status is collected and shared to Google administrator.
In the Main Menu, click Devices > Chrome > Apps & extensions and select the Users & browsers tab.
- In the Apps & Extension explorer on the left, use the search filter and enter
[email protected](tenantName)to select your OU.
- Click the Yellow + menu, bottom right of screen and select Add from Chrome Web Store and select Add from Chrome Web Store.
- Click the Search box and search for
Endpoint Verificationand press ENTER. Or search with the App ID:callobklhcbilhphinckomhgkigmfocg. - Click Select on the top right to install the official extension by Google.
- In the installation policy menu, Click Allow Install to expand the drop down and select Force install + pin to the browser toolbar.
- Click Save found on the top right corner of the page.
This task once completed will prevent data from being copied from trusted corporate websites and pasted into untrusted destinations, such as other Chrome profiles, incognito sessions, or applications outside the browser. It serves as a critical safeguard against data exfiltration.
Note : Ensure you have selected the OU assigned to you- [email protected](tenantName).
- In the Main Menu, click Devices > Chrome > Settings. Be sure you're in the Users & browser settings tab.
- In the left pane, use the filter to search for organizational unit by entering
[email protected](tenantName)and selecting it. - Search for the
Restricted sources for pastingsetting and then click Restricted sources for pasting from the results. - Set the Restriction type to Allow copying from the following content sources, except when pasting to certain destinations.
- In the Content sources field, enter
https://support.google.com/chrome. - In the Block pasting to section, select the checkboxes for:
- Block pasting to Other Chrome profiles
- Block pasting to Incognito mode
- Block pasting to Applications other than Chrome
- Click Save.
This task strengthens data protection by identifying sensitive information, such as credit card numbers, and regulating access to specific web categories to reduce the risk of data loss and support acceptable use policies
Create a "Block viewing Credit Card Number" rule for managed browsers
- In the Main Menu , click Security > Access and data control > Data protection.
- Go to the Data protection rules and detectors card and then click Manage Rules, then Add rule > New Rule.
- Set Name to
Block viewing CCN - [email protected](tenantName). - Enter Description ( Optional)
- Scroll down to Apps section and select Chrome.
- Select the File uploaded, File downloaded, Content pasted options for Chrome.
- Click Continue.
- In the Actions section, for Chrome actions, select Block. (User message is optional and not required for this policy)
- Set Alerting to High.
- Click Continue.
- In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use the search filter and enter
[email protected](tenantName)to select your organizational unit.Click Done. - Click Add Condition to define the triggers for the rule.
- Field:All content (set by default).
- What to scan for: select Matches predefined data type (recommended) from the menu options.
- Set Data type to Global: Credit card number.
You will have to scroll to find the value Gobal : Credit card number
- Set Likelihood Threshold to Medium.
- Keep Minimum unique matches and Minimum match count , default value is already set to 1.
- Under Context conditions, select None.
- Click Continue.
- Review configuration and click Create.
Create a custom detector for an allowlist
Note : Custom detectors are configured for the tenant and not OU specific, you can only view the configuration. DO NOT make any changes.
This control supports DLP policy enforcement by defining approved Generative AI tools as an allowlist, which serves as an exception mechanism in the following rule while maintaining protection against unauthorized data sharing.
- In the Main Menu , click Security > Access and data control > Data protection.
- In the Data protection rules and detectors section, click Manage detectors.
- View the Wordlist by clicking on it.
- The site used is gemini.google.com.
- Close the page by going back to Home.
Create a URL filtering rule to block unapproved generative AI sites
- In the Main menu navigate to Rules, then select Create Rule > Data protection.
- Enter Name "
Block Unapproved Gen AI [email protected](tenantName)". - Adding Description is optional.
- In the Apps section, choose Chrome.
- For Chrome, select URL Visited as the activity to monitor, then click Continue.
- Under Actions, set the Chrome action to Block.
- Select Custom message , enter your custom message "
Your Omnissa Administrator has blocked access to this website". - Configure the Alerting level as High, and then select Continue.
- In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use search filter to enter your organizational unit
[email protected](tenantName)and Select. . Click Done. - In Content Conditions, create the following criteria:
- Click Add a condition and configure it as URL Category > Matches > Click Select Category > Scroll down and Search for Generative AI.
- Click Select.
- Click Add Condition to add another condition.
- In the newly added condition block, enable the NOT (-) operator.
- Within the NOT block, configure the condition as:
- URL → Matches words from a word list
- Select the Approved Gen AI Tools detector.
- Set Match Mode to Match any word.
- Set Minimum Total times any word detected to
1.
- In the Context conditions keep the settings to None.
- Click Continue and then select Create to save and activate the rule.
Why blocking shadow gen AI is important: Blocking unapproved shadow gen AI tools is a critical security measure. Employees might unknowingly paste sensitive corporate data—such as source code, financial projections, or customer PII—into a public AI tool. By creating a rule that blocks the general category but allows a specific, vetted tool, you enable productivity safely while protecting the organization from the risks of uncontrolled AI usage.
Create Website blocking , Watermarking and Copy Paste restrictions
In this task, you will configure Data Protection policies in Chrome Enterprise Premium to safeguard sensitive corporate data. You will learn how to block access to unauthorized websites, apply watermarking to approved web applications to increase user awareness and deter data leakage, and enforce copy-and-paste restrictions to prevent sensitive information from being transferred to unauthorized destinations. These controls help organizations strengthen data security while maintaining user productivity.
Blocking un-authorized Websites
- In the Main menu, navigate to Rules , then select Create Rule > Data protection
- Enter Name "
Block Unapproved Sites - [email protected](tenantName)". - In Apps section , choose Chrome.
- For Chrome, select URL visited as the activity monitor and click Continue.
- Under Actions , Select Block .
- Select Custom message , enter your custom message "
Your Omnissa administrator has blocked access to this website". - Configure Alerting to High and then select Continue.
- In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use search filter to enter your organizational unit
[email protected](tenantName)and Select .Click Done. - In Content Conditions , create the following criteria:
- Click Add Condition and configure Content type to scan as URL > What to scan* ,Select Contains text string > Enter text to match as
makemytrip.com. - Do not enable Case Sensitive .
- Click Add Condition and configure Content type to scan as URL > What to scan* ,Select Contains text string > Enter text to match as
- In the Context conditions keep the settings to None.
- Click Continue and then select Create to save and activate the rule.
Watermarking sensitive sites
- In the Main menu, navigate to Rules , then select Create Rule > Data protection
- Enter Name "
Watermarking Sensitive Sites - [email protected](tenantName)". - Entering a Description is optional.
- In Apps section , choose Chrome.
- For Chrome, select URL visited as the activity monitor and click Continue.
- Under Actions , Select Audit only.
- Select Add watermark over page content.
- Enter your Watermark message "
This site is restricted" . - Configure Alerting to low and then select Continue.
- In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use the search filter to enter your organizational unit [email protected](tenantName) and Select.Click Done.
- In Content Conditions , create the following criteria:
- Click Add Condition and configure Content type to scan as URL > What to scan for*,Select Contains text string > Enter text to match as
Slack.com.
- Click Add Condition and configure Content type to scan as URL > What to scan for*,Select Contains text string > Enter text to match as
- In the Context conditions keep the settings to None.
- Click Continue and then select Create to save and activate the rule.
Enforce Copy and Paste restriction of content to un-authorized sites
- In the main menu, navigate to Chrome browser > Settings.
- Under the Settings tab ,use the search filter by entering
[email protected](tenantName)and Select it. - Use the Search filter below Users and Browsers settings tab to search for
Restricted destination for pastingsettings. - Click on Restricted destination for pasting.
- Select Locally applied in the inheritance settings (if you don not see a drop down, click on the hyperlink to change settings).
- In the Configuration section use the drop down to select " Block pasting content to the following destination , except when copied from certain sources".
- In the Paste destinations , enter websites URL
https://google.comto which you would want to restrict content to pasted into . - In the Show a warning when pasting content copied from the following sources enter the website URL
https://indiatoday.into which you would allow users to copy content from and paste within the same chrome profile with a warning. - In the Allow pasting content copied from the following sources , enter the website URL
https://yahoo.comto which you are allowing users to copy content from.
In this task, you will integrate the Chrome Admin Console with Omnissa Access to validate conditional access policies. The objective is to compare the user experience when accessing a web application from a managed Chrome browser or Chrome profile versus an unmanaged Chrome browser or profile, ensuring that access is granted or restricted based on the device and browser management status.
- Omnissa Access Console URL -
https://@lab.Variable(tenantName).us0.wss.workspaceone.com - Omnissa Access admin Username-
[email protected](tenantName)@euclabuat.com. - Omnissa Access admin Password -
TempPassword123!
If you have not reset your Omnissa Access admin Password , please do it before you start this task. The Omnissa Access admin Password Reset URL is : @lab.Variable(AccessURL)@lab.Activity(Automated1)
Set the Password to : TempPassword123!
- Select W11Client using drop down.
- Click the Keyboard symbol and Click CTRL+ALT+DELETE.
- Enter Password -
Pa$$w0rd - Hit enter to login.
- Once you have logged in, search for Chrome browser on Desktop and double click to launch Chrome Browser.
- On the search bar enter Omnissa Access Console URL
https://@lab.Variable(tenantName).us0.wss.workspaceone.com- and click Enter. - Enter Omnissa Access admin Username
[email protected](tenantName)@euclabuat.comand passwordTempPassword123!. - Hit enter to login.
- Click Accept.
- On the login page, click TA on the right corner.
- Click Access Console.
- Navigate to Integrations, under Authentication Methods select Google Chrome Enterprise Device Signals.
- Click Configure.
- Enable Google Chrome Enterprise Device Signal Adapter by clicking on the toggle to Yes.
- Copy the URLs matcher and IDP Service Account email to notepad as this will be used while configuring Google Admin console.
- Ensure " Allow access if not a managed Chrome browser " is set to No.
- Ensure " Verify devices disk encryption status " is set to No.
- Ensure " Verify devices firewall status " is set to No.
- Ensure " Verify device screen lock status" is set to No.
- Click Save.
Configure Identity Provider
- On your Omnissa Access tenant ,navigate to Integrations > Identity Provider > System Identity Provider.
- Ensure System Directory is Enabled.
- Scroll down to Authentication Methods , enable Google Chrome Enterprise Device Signals by selecting them. ( Password (local Directory) will be enabled by default , do not make any changes)
- Click Save.
Configure Application Policy
Create an authentication policy application to validate if the user is accessing the application from a managed compliant browser.
Configure authentication policy using the steps below.
- Navigate to Resources > Policies > Add Policy.
- Enter Policy Name like "
Chrome Browser only" and provide a Description (optional). - Click Next.
- Click on Add Policy Rule.
- Select All device Types for “and the user accessing content from” configuration.
- Select Password (Local Directory) for “then the user may authenticate using” configuration.
- Select Add Authentication and select Google Chrome Enterprise Device Signals as secondary authentication.
- Under Advanced Properties, add a custom message like “
Access denied. You must access this app using a managed Chrome browser". - Save the configuration.
- Click Next.
- Click Save.
Configure Web application
To configure a web application, follow the steps below.
On your Omnissa Access Console, navigate to Resources > Web Apps.
- Click on New.
Click Browse from catalog, enter
BambooHRin the search filter.
- Select it by clicking on the " +" symbol.
- Click Next.
- Fill in the mandatory fields like
- Single Sign-On URL -
https://euclabuat.bamboohr.com/saml/consume.php - Recipient URL -
https://euclabuat.bamboohr.com - Application ID -
BambooHR-SAML - Username Format -
Email Address - Application parameters - Enter
euclabuat.comfor Value
- Single Sign-On URL -
- Click Next.
- Select the Access Policy "Chrome Browser only " in drop down created in the previous step and Click Next.
- Click Save & Assign the application to the users.
- To assign the application ,enter user name
[email protected](tenantName). - Set deployment type to Automatic.
- Click Save.
Configure the Connector in Google Admin Console
The final step to integrate Omnissa Access with Chrome Enterprise is to configure the Connector.
- Log into
https://admin.google.comusing your Google Admin Username:[email protected](tenantName)@euclabuat.comand Password:TempPassword123! - Navigate to Chrome browser > Connectors > NEW PROVIDER CONFIGURATION >Scroll down and search for Omnissa.
- Click Setup in the Omnissa.
- Enter Configuration name like,
[email protected](tenantName). - Enter the URL patterns to allow one per line by copying the details from Omnissa Access console. (Copy it from the notepad)
- Enter the Service account, one per line by copying the details from Omnissa Access console.(Copy it from notepad)
- Select Managed browser and profiles in the drop down.
- Click Add Configuration.
- Click X to close the configuration page.
- In the Main menu , navigate to Chrome browsers > Connectors.
- Select your Organization Unit by entering
[email protected](tenantName)in Search for organizational units. - Select the Connector Omnissa - [email protected](tenantName) configured for your OU.
- Click Save on the top right corner to complete configurations.
It's time to test the policies configured on the Google admin console , to test the policies you will need to log into the Windows VM which is an unmanaged device. Follow the instructions below to gain access to the Windows VM and begin testing.
Connect to Windows VM
Select win11Client using the dropdown.
- Click Keyboard icon and select CTRL+ALT+DELETE .
- Enter Password -
Pa$$w0rdand hit enter or click on the arrow symbol. - Once logged into the Windows VM, search for Google Chrome Browser and launch it by double clicking.
- If prompted to sign in do not sign in.
- Copy and paste the following URL into the Chrome browser in the VM
https://dlptest.com/sample-data/
- From the Sample Data Library, click Name+CCN+ZIP.
- Click Download PDF to download a sample pdf file.
- Expected result: The file should download. This shows a default profile has no controls.
Note: If the file download is blocked, ensure you are not signed in with any account.
Sign in to create a Managed Profile
Log into your Windows Virtual machine by selecting W11client
- Click CTRL+ALT+DELETE.
- Enter Password -
Pa$$w0rd - Launch Chrome browser , click the profile avatar > Add a chrome profile.
- Click Sign in.
- Sign in with the Google Test Account
[email protected](tenantName)@euclabuat.comand passwordTempPassword123!. - Click I understand.
- Click Continue
- Click No thanks.
- Click Done.
Test the application boundary rule
- Test Download: Browse
https://dlptest.com/sample-data/and click Name+CCN+ZIP and select Download PDF.- Expected result: The download should be blocked.
Test Paste: Browse
https://dlptest.com/https-post/Copy a sample Credit Card Number from the PDF you downloaded in the baseline test and try to paste it into the "Test Message" field.Note: You can use Google Chrome to view the PDF file.
- Expected result: The paste action should be blocked.
- Test Upload: On the same page, try to upload the sensitive PDF file.
- Expected result: The file upload should be blocked.
- Test Block pasting to Un-authorized sites , profile and applications : Browse
https://support.google.com/chrome, copy content like "How can we help you" seen in the webpage and try pasting it to ,
- Note Pad (Application) :
- Expected Result : The past option will be blocked and warning message is seen " Pasting this content here is blocked by your administrator"
- Another Chrome profile :
- Expected Result: The past option will be blocked and warning message is seen " Pasting this content here is blocked by your administrator"
- Incognito page:
- Expected Result: The past option will be blocked and warning message is seen " Pasting this content here is blocked by your administrator"
Test Data protection rule
- Launch Chrome browser and ensure you have logged into chrome using your student credentials.
- Browse
https://support.google.comand keep the tab open. - Open a new tab and browse
https://apple.com, copy any content from the website and try pasting it into the search box of google website.- Expected Result : You should see a warning " Your administrator has blocked this action"
- Open a new tab and browse
https://yahoo.com, copy any content from the website and try pasting in into the search box of google website.- Expected Result : You should be able to copy content.
- Open a new tab and browse
https://indiatoday.in, copy any content from the website and try pasting it into the search box ofhttps://support.google.comwebsite.- Expected Result: You will see an warning " This action might violate your organization policies " , you will have the permission to Paste anyway or Don't paste.
Test Conditional Access
Using an un-managed browser
- Launch Chrome browser and ensure you are NOT signed in to the browser using your student credentials.
- Browse your Omnissa Access tenant
https://@lab.Variable(tenantName).us0.wss.workspaceone.com. Sign in to Omnissa Access tenant using your student credentials
Username:
[email protected](tenantName)@euclabuat.comPassword :
TempPassword123!- Click Apps.
- Click BambooHR to launch it.
Expected Result : You should see "Access Denied" as you have tried to access a site which can be done only using a managed browser or a managed profile.
Using a managed profile browser
- Launch Chrome browser and ensure you have signed into chrome browser using your student credentials.
- Browse your Omnissa Access tenant
https://@lab.Variable(tenantName).us0.wss.workspaceone.com. Sign in to Omnissa Access tenant using your student credentials
Username:
[email protected](tenantName)@euclabuat.comPassword :
TempPassword123!- Click Apps.
- Click BambooHR to launch it.
Expected Result : You should successfully access the site as you accessed it using a managed browser.
Test Blocking Un-authorized sites and Watermarking
Testing Blocking Un-authorised site
Launch Chrome browser and ensure you have signed into chrome browser using student Username - [email protected](tenantName) and Password - TempPassword123! and browse https://makemytrip.com.
- Expected Result: You should see a warning " The site ahead is blocked by your organization " .
Testing Watermarking sensitive site
Launch Chrome browser and ensure you have signed into chrome browser using your student Username - [email protected](tenantName) and Password - TempPassword123! and browse https://slack.com.
- Expected Result: You should see a watermark on the page with a message " Confidential Site [email protected](tenantName)@euclabuat.com ,date & time" .
Launch Chrome browser and ensure you have signed into chrome browser using your student Username - [email protected](tenantName) and Password - TempPassword123! and browse https://chatgpt.comor https://copilot.microsoft.com.
- Expected Result: You should see a warning " Your organisation says: Your not allowed to access this AI website" as only gemini AI site is allowed.
- You now browse
https://gemini.google.com, it will be successful as its approved.








































0 Comments
Add your comment