Omnissa Secure Access Suite

Expand or collapse content Cloud Resources and usernames

UEM Admin Username: [email protected]

UEM Admin Password: Pa$$w0rd

Access URL: https://@lab.Variable(tenantName).us0.wss.workspaceone.com

Access Admin Username: [email protected](tenantName)@euclabuat.com

Access Password Reset URL: @lab.Variable(AccessURL)

@lab.Activity(Automated1)

Google Admin Console: https://admin.google.com

Google Admin Account: [email protected](tenantName)@euclabuat.com

Google Admin Password: TempPassword123!

Google Test Account: [email protected](tenantName)@euclabuat.com

Google Password: TempPassword123!

 

Objective 

In this lab, you will gain hands-on experience configuring and testing Omnissa Secure Access Suite. Working through a series of guided exercises, you will set up enterprise security policies, enforce data loss prevention controls, integrate identity and access management, and validate the end-to-end behavior of these controls using Chrome Profile on unmanaged devices.

  1. Assigning Chrome Enterprise Premium License
  2. Configure Chrome Enterprise Premium with foundational security and reporting policies
  3. Deploy and enforce Endpoint Verification across devices
  4. Define Application Boundaries to prevent data leakage between trusted and untrusted destinations
  5. Build Data Loss Prevention (DLP) rules to safeguard sensitive information
  6. Integrate Omnissa Access with the Chrome Admin Console for SSO and compliance
  7. Validate security policies on Un-managed device
  8. Test URL filtering policies for Generative AI and other restricted sites
Expand or collapse content Task 1: Assigning Chrome Enterprise Premium License

The first step to configure Chrome Enterprise Premium would be to enable/check if the targeted student user account has the Chrome Enterprise Premium License assigned. To validate the assignment follow the steps below.

Pre-requisites

Before you begin , ensure you have the following which can be found on the right side of your screen once you launch your lab. 

 

Select Instructions to view,

  1. Access URL
  2. Access Admin Username.
  3. Access Password Reset URL - Please reset the password to TempPassword123!using the Reset URL provided in the lab instructions.
  4. Google Admin Account
  5. Google Admin password
  6. Google Test account
  7. Google Test account password

Select Resource tab to view Control Center and Windows Virtual Machine (W11Client-01) credentials.

Instructions to launch Control Center or Windows Virtual Machine

  1. Launch the lab using the URL provided.

 

  1. During the lab you will need to move between the Control Center and the Windows Virtual machine , use the drop down as shown above to navigate between Control Center and the Windows Virtual Machine.
  1. To log into the Windows Virtual Machine or Control Center ,click the Keyboard icon and click CTRL+Alt+Delete.
  2. Wait for the login screen.
  3. Enter your Admin Password- Pa$$w0rd.
  4. Press Enter or click the Arrow to log in. 

Log into Google Admin console

  1. Log into the Control Center.
  2. On the Windows Desktop , locate the Google Chrome browser icon.
  3. Double-click the Google Chrome icon to launch the browser.
  4. Wait for Chrome to open and display the start page.
  5. In the  Chrome address bar , type the following URL https://admin.google.com.
  6. Press Enter to navigate to the Google Admin sign-in page.
  1. On the sign-in page , enter your Google Admin username it should be of the format  [email protected](tenantName)@euclabuat.com
  2. Enter Google Admin password - TempPassword123!and click Next.
  3. Click I understand.
  4. If you are prompted to Select Continue as [email protected](tenantName) or use  Chrome without an account , select Use Chrome without an account.
  5. Click Get set up. 

Assigning Chrome Enterprise License

  1. Once logged in , navigate to Directory > Users.

     

 

  1. Enter your user account  [email protected](tenantName) in the search filter.

     

  1. Click the OU [email protected](tenantName) to select it. 
  2. Select [email protected](tenantName) LabUser. 

     

  1. Click on Assign Licenses.
  1. Select Chrome Enterprise Premium(offline pricing)
  2. Click Assign

Note: For any Login issues or License assignment issues reach out to the Lab Instructor

Expand or collapse content Task 2 : Configuring Chrome Enterprise Premium with foundational security and reporting policies

The next task is to configure the core foundation security setting and enabling reports for administrators to track browser. 

 

  1. In the Main Menu ,navigate to Devices > Chrome > Settings, then select the User & Browser settings tab.
  2. If you see a pop up , click Dismiss to close it.
  3. In the Settings explorer on the left, expand Skillable OU and select your organisational unit by typing [email protected](tenantName) in the search for Organizational units.
  4. Select your OU [email protected](tenantName).

Tips : 

  1. Use the search bar at the top of the settings page to find each policy by name quickly.
  2. Click Close once you've configured a setting to return to the User & browser settings page so you can configure the next setting. You may also need to close out any existing filters to view all the settings once more.
  1. For each setting below, click into the section, configure as described, and then click Save. The screenshot below shows an example of how to configure Enable Event reporting. 

Below is an example of Event reporting configuration

  • Event reporting: Select Disallow all and set it to Enable event reporting and click Save.Click Close. This is the foundation for threat detection, sending security events to the Admin console for analysis.
  • Managed browser reporting: Select Disable managed browser cloud reporting and set to Enable managed browser cloud reporting and click Save. Click Close. Provides a complete inventory of all enrolled browsers in your organization.
  • Managed profile reporting: Select Disabled managed profile reporting and set to Enable managed profile reporting for managed users and click Save . Click Close. It extends visibility to managed profiles on unmanaged (BYOD) devices.
  • Managed browser reporting upload frequency: Enter 3 as the upload frequency in hours and click Save. Click Close.The default is 24 hours; a shorter interval provides more up-to-date data for quicker security responses.
  • Real time URL check: Select None and set to Chrome Enterprise Premium and click Save. Click Close. It enables advanced, real-time phishing and malware protection via Google's Safe Browsing service.

The following setting are configured by default ,your task is to verify the settings

  • Upload content analysis:
    • Select Chrome Enterprise Premium if it is set to none by default.
    • Click Additional settings.
    • Check the boxes for Delay upload until analysis is complete and Block file upload on failure.
    • Inside Check for sensitive data, set Mode to On by default, except for the following URL patterns.
    • Under Check for malware, set Mode to On by default, except for the following URL patterns. It activates DLP scanning for file uploads and ensures files are cleared before the upload completes.
    • Save the settings.
  • Download content analysis:
    • Select None and set it to Chrome Enterprise Premium if it is set to none by default.
    • Click Additional settings.
    • Check the boxes for Delay file access until analysis is complete and Block file access on failure.
    • Inside Check for sensitive data, set Mode to On by default, except for the following URL patterns. It activates DLP and malware scanning for downloads, preventing users from opening a file until it's approved.
    • Save the settings.
    • Click Close.
  • Bulk text content analysis:
    • Select None and set to  Chrome Enterprise Premium.
    • Click Additional settings.
    • Check the boxes for Delay text entry until analysis is complete and Block text entry on failure.
    • Inside Check for sensitive data, set Mode to On by default, except for the following URL patterns. Set the minimum number of bytes to 1. It activates DLP scanning for pasted content, preventing sensitive data leakage.
    • Save the settings.
    • Click Close.

Note: Device Token Management can be configured only at Parent OU , you will not be able to configure it at the OU created for this Lab.It has already been set to delete token settings at Parent OU. 

  • Device Token Management: It automatically cleans up your managed browser list, preventing stale records.

Enable Advance Data Protection Features

Note : This configuration is only done at the Parent OU, Do not make any changes to these settings.The task is only to view the configuration and learn about functionality.  

  1. In the Main Menu , click Security > Access and Data Control and scroll down to Data Protection.
  2. Scroll down to view all the Data protection settings.
    • Data insights scanning and report > For Google Chrome: It activates additional reporting for content that is downloaded, uploaded, or printed.
    • Optical character recognition (OCR) > For Google Chrome: It enhances DLP by allowing scans to read text inside images and PDFs.
    • Sensitive content storage: It stores the actual content that triggers a DLP rule, which is invaluable for security investigations. (Ignore if not seen on the console).
Expand or collapse content Task 3: Deploy and enforce Endpoint Verification across devices

Force Install Endpoint verification extension

Endpoint Verification is a key element of a zero-trust security framework, gathering critical device information required to define and enforce device-based access policies. In this task you will be configuring an extension which ensures the device attributes like operating system , device model and encryption status is collected and shared to Google administrator. 

  1. In the Main Menu, click Devices > Chrome > Apps & extensions and select the Users & browsers tab.

     

 

  1. In the Apps & Extension explorer on the left, use the search filter and enter [email protected](tenantName) to select your OU.
  1. Click the Yellow + menu, bottom right of screen and select Add from Chrome Web Store and select Add from Chrome Web Store.
  2. Click the Search box and search for Endpoint Verification and press ENTER. Or search with the App ID:callobklhcbilhphinckomhgkigmfocg.
  3. Click Select on the top right to install the official extension by Google.
  4. In the installation policy menu, Click Allow Install to expand the drop down and select Force install + pin to the browser toolbar.
  5. Click Save found on the top right corner of the page.
Expand or collapse content Task 4 : Define Application Boundaries to prevent data leakage between trusted and untrusted destinations

This task once completed will prevent data from being copied from trusted corporate websites and pasted into untrusted destinations, such as other Chrome profiles, incognito sessions, or applications outside the browser. It serves as a critical safeguard against data exfiltration.

Note : Ensure you have selected the OU assigned to you- [email protected](tenantName). 

  1. In the Main Menu, click Devices > Chrome > Settings. Be sure you're in the Users & browser settings tab.
  2. In the left pane, use the filter to search for  organizational unit by entering [email protected](tenantName) and selecting it.
  3. Search for the Restricted sources for pasting setting and then click Restricted sources for pasting from the results.
  4. Set the Restriction type to Allow copying from the following content sources, except when pasting to certain destinations.
  5. In the Content sources field, enter https://support.google.com/chrome.
  6. In the Block pasting to section, select the checkboxes for:
    • Block pasting to Other Chrome profiles
    • Block pasting to Incognito mode
    • Block pasting to Applications other than Chrome
  7. Click Save.
Expand or collapse content Task 5: Configure DLP and URL filtering rules

This task strengthens data protection by identifying sensitive information, such as credit card numbers, and regulating access to specific web categories to reduce the risk of data loss and support acceptable use policies

Create a "Block viewing Credit Card Number" rule for managed browsers

  1. In the Main Menu , click Security > Access and data control > Data protection.
  2. Go to the Data protection rules and detectors card and then click Manage Rules, then Add rule > New Rule.
  3. Set Name to Block viewing CCN - [email protected](tenantName).
  4. Enter Description ( Optional)
  5. Scroll down to Apps section and select Chrome.
  6. Select the File uploaded, File downloaded, Content pasted options for Chrome.
  7. Click Continue.
  8. In the Actions section, for Chrome actions, select Block. (User message is optional and not required for this policy)
  9. Set Alerting to High.
  10. Click Continue.
  11. In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use the search filter and enter [email protected](tenantName)to select your organizational unit.Click Done.
  12. Click Add Condition to define the triggers for the rule.
  13. Field:All content (set by default).
  14. What to scan for: select Matches predefined data type (recommended) from the menu options.
  15. Set Data type to Global: Credit card number.

You will have to scroll to find the value Gobal : Credit card number 

  1. Set Likelihood Threshold to Medium.
  2. Keep Minimum unique matches and Minimum match count , default value is already set to 1.
  3. Under Context conditions, select None.
  4. Click Continue.
  5. Review configuration and click Create. 

Create a custom detector for an allowlist

Note : Custom detectors are configured for the tenant and not OU specific, you can only view the configuration. DO NOT make any changes. 

This control supports DLP policy enforcement by defining approved Generative AI tools as an allowlist, which serves as an exception mechanism in the following rule while maintaining protection against unauthorized data sharing.

  1. In the Main Menu , click Security > Access and data control > Data protection.
  2. In the Data protection rules and detectors section, click Manage detectors.
  3. View the Wordlist by clicking on it.
  4. The site used is gemini.google.com.
  5. Close the page by going back to Home. 

Create a URL filtering rule to block unapproved generative AI sites

  1.  In the Main menu navigate to Rules, then select Create Rule > Data protection.
  2. Enter Name "Block Unapproved Gen AI [email protected](tenantName)".
  3. Adding Description is optional.
  4. In the Apps section, choose Chrome.
  5. For Chrome, select URL Visited as the activity to monitor, then click Continue.
  6. Under Actions, set the Chrome action to Block.
  7. Select Custom message , enter your custom message " Your Omnissa Administrator has blocked access to this website".
  8. Configure the Alerting level as High, and then select Continue.
  9. In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use search filter to enter your organizational unit [email protected](tenantName) and Select. . Click Done.
  10. In Content Conditions, create the following criteria:
    • Click Add a condition and configure it as URL Category > Matches > Click Select Category > Scroll down and Search for Generative AI.
    • Click Select.
  11. Click Add Condition to add another condition.
  12. In the newly added condition block, enable the NOT (-) operator.
  13. Within the NOT block, configure the condition as:
    • URL → Matches words from a word list
    • Select the Approved Gen AI Tools detector.
    • Set Match Mode to Match any word.
    • Set Minimum Total times any word detected to 1.
  14. In the Context conditions keep the settings to None.
  15. Click Continue and then select Create to save and activate the rule.

Why blocking shadow gen AI is important: Blocking unapproved shadow gen AI tools is a critical security measure. Employees might unknowingly paste sensitive corporate data—such as source code, financial projections, or customer PII—into a public AI tool. By creating a rule that blocks the general category but allows a specific, vetted tool, you enable productivity safely while protecting the organization from the risks of uncontrolled AI usage.

Create Website blocking , Watermarking and Copy Paste restrictions

In this task, you will configure Data Protection policies in Chrome Enterprise Premium to safeguard sensitive corporate data. You will learn how to block access to unauthorized websites, apply watermarking to approved web applications to increase user awareness and deter data leakage, and enforce copy-and-paste restrictions to prevent sensitive information from being transferred to unauthorized destinations. These controls help organizations strengthen data security while maintaining user productivity.

Blocking un-authorized Websites

  1. In the Main menu, navigate to Rules , then select Create Rule > Data protection
  1. Enter Name "Block Unapproved Sites - [email protected](tenantName)".
  2. In Apps section , choose Chrome.
  3. For Chrome, select URL visited as the activity monitor and click Continue.
  4. Under Actions , Select Block .
  5. Select Custom message , enter your custom message "Your Omnissa administrator has blocked access to this website".
  6. Configure Alerting to High and then select Continue.
  7. In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use search filter to enter your organizational unit [email protected](tenantName) and Select .Click Done.
  8. In Content Conditions , create the following criteria:
    • Click Add Condition and configure Content type to scan as URL > What to scan* ,Select Contains text string > Enter text to match as makemytrip.com.
    • Do not enable Case Sensitive .
  9. In the Context conditions keep the settings to None.
  10. Click Continue and then select Create to save and activate the rule.

Watermarking sensitive sites

  1. In the Main menu, navigate to Rules , then select Create Rule > Data protection
  2. Enter Name " Watermarking Sensitive Sites - [email protected](tenantName) ".
  3. Entering a Description is optional.
  4. In Apps section , choose Chrome.
  5. For Chrome, select URL visited as the activity monitor and click Continue.
  6. Under Actions , Select Audit only.
  7. Select Add watermark over page content.
  8. Enter your Watermark message " This site is restricted " .
  9. Configure Alerting to low and then select Continue.
  10. In the Scope section, choose select organizational units and/or groups and select the Include organizational units . Use the search filter to enter your organizational unit [email protected](tenantName) and Select.Click Done.
  11. In Content Conditions , create the following criteria:
    • Click Add Condition and configure Content type to scan as URL > What to scan for*,Select  Contains text string > Enter text to match as Slack.com.
  12. In the Context conditions keep the settings to None.
  13. Click Continue and then select Create to save and activate the rule.

Enforce Copy and Paste restriction of content to un-authorized sites

  1. In the main menu, navigate to Chrome browser > Settings.
  2. Under the Settings tab ,use the search filter by entering [email protected](tenantName) and Select it.
  3. Use the Search filter below Users and Browsers settings tab to search for Restricted destination for pasting settings.
  4. Click on Restricted destination for pasting.
  5. Select Locally applied in the inheritance settings (if you don not see a drop down, click on the hyperlink to change settings).
  6. In the  Configuration section use the drop down to select " Block pasting content to the following destination , except when copied from certain sources".
  7. In the Paste destinations , enter websites URL https://google.com to which you would want to restrict content to pasted into .
  8. In the Show a warning when pasting content copied from the following sources enter the website URL  https://indiatoday.in to which you would allow users to copy content from and paste within the same chrome profile with a warning.
  9. In the Allow pasting content copied from the following sources , enter the website URL https://yahoo.com to which you are allowing users to copy content from. 
Expand or collapse content Task 6: Integrate Omnissa Access with the Chrome Admin Console for SSO and compliance

In this task, you will integrate the Chrome Admin Console with Omnissa Access to validate conditional access policies. The objective is to compare the user experience when accessing a web application from a managed Chrome browser or Chrome profile versus an unmanaged Chrome browser or profile, ensuring that access is granted or restricted based on the device and browser management status.

  • Omnissa Access Console URL - https://@lab.Variable(tenantName).us0.wss.workspaceone.com
  • Omnissa Access admin Username- [email protected](tenantName)@euclabuat.com.
  • Omnissa Access admin Password - TempPassword123!

If you have not reset your Omnissa Access admin Password , please do it before you start this task. The Omnissa Access admin Password Reset URL is : @lab.Variable(AccessURL)@lab.Activity(Automated1)

Set the Password to : TempPassword123!

  1. Select W11Client using drop down.
  1. Click the Keyboard symbol and Click CTRL+ALT+DELETE.
  2. Enter Password -Pa$$w0rd
  3. Hit enter to login.
  4. Once you have logged in, search for Chrome browser on Desktop and double click to launch Chrome Browser.
  5. On the search bar enter Omnissa Access Console URL https://@lab.Variable(tenantName).us0.wss.workspaceone.com - and click Enter.
  6. Enter Omnissa Access admin Username [email protected](tenantName)@euclabuat.com and password  TempPassword123!.
  7. Hit enter to login.
  8. Click Accept.
  9. On the login page, click TA on the right corner.
  1. Click Access Console.
  2. Navigate to Integrations, under Authentication Methods select Google Chrome Enterprise Device Signals.
  1. Click Configure.
  2. Enable Google Chrome Enterprise Device Signal Adapter by clicking on the toggle to Yes.
  3. Copy the URLs matcher and IDP Service Account email to notepad as this will be used while   configuring Google Admin console.
  4. Ensure " Allow access if not a managed Chrome browser " is set to No.
  5. Ensure " Verify devices disk encryption status " is set to No.
  6. Ensure " Verify devices firewall status " is set to No.
  7. Ensure " Verify device screen lock status" is set to No.
  8. Click Save.

Configure Identity Provider

  1. On your Omnissa Access tenant ,navigate to Integrations > Identity Provider > System Identity Provider.
  1. Ensure System Directory is Enabled.
  1. Scroll down to Authentication Methods , enable Google Chrome Enterprise Device Signals by selecting them. ( Password (local Directory) will be enabled by default , do not make any changes)
  2. Click Save. 

Configure Application Policy

Create an authentication policy application to validate if the user is accessing the application from a managed compliant browser. 

Configure authentication policy using the steps below. 

  1. Navigate to Resources > Policies > Add Policy.
  2. Enter Policy Name like "Chrome Browser only" and provide a Description (optional).
  3. Click Next.
  4. Click on Add Policy Rule.
  1. Select All device Types for “and the user accessing content from” configuration.
  2. Select Password (Local Directory) for “then the user may authenticate using” configuration.
  3. Select Add Authentication and select Google Chrome Enterprise Device Signals as secondary authentication.
  1. Under Advanced Properties, add a custom message like “Access denied. You must access  this app using a managed Chrome browser".
  2. Save the configuration.
  3. Click Next.
  4. Click Save.

Configure Web application

To configure a web application, follow the steps below. 

  1. On your Omnissa Access Console, navigate to Resources > Web Apps.

     

  1. Click on New.
  2. Click Browse from catalog, enter BambooHR in the search filter.

     

  1. Select it by clicking on the " +" symbol.
  2. Click Next.
  3. Fill in the mandatory fields like
  1. Click Next.

 

  1. Select the Access Policy "Chrome Browser only " in drop down created in the previous step and Click Next.

 

  1. Click Save & Assign the application to the users.
  1. To assign the application ,enter user name [email protected](tenantName).
  2. Set deployment type to Automatic.
  3. Click Save.

Configure the Connector in Google Admin Console

The final step to integrate Omnissa Access with Chrome Enterprise is to configure the Connector.

  1. Log into https://admin.google.com using your Google Admin Username: [email protected](tenantName)@euclabuat.com and Password: TempPassword123!
  2. Navigate to Chrome browser > Connectors > NEW PROVIDER CONFIGURATION >Scroll down and search for Omnissa.
  1. Click  Setup in the Omnissa.
  1. Enter Configuration name like,[email protected](tenantName).
  2. Enter the URL patterns to allow one per line by copying the details from Omnissa Access console. (Copy it from the notepad)
  3. Enter the Service account, one per line by copying the details from Omnissa Access console.(Copy it from notepad)
  4. Select Managed browser and profiles in the drop down.
  5. Click Add Configuration.
  6. Click X to close the configuration page.
  7. In the Main menu , navigate to Chrome browsers > Connectors.
  8. Select your Organization Unit by entering [email protected](tenantName) in Search for organizational units.
  9. Select the Connector Omnissa - [email protected](tenantName) configured for your OU. 
  1. Click Save on the top right corner to complete configurations.
Expand or collapse content Task 7: Validate security policies on Un-managed device

It's time to test the policies configured on the Google admin console , to test the policies you will need to log into the Windows VM which is an unmanaged device. Follow the instructions below to gain access to the Windows VM and begin testing. 

Connect to Windows VM

  1. Select win11Client using the dropdown.

     

  1. Click Keyboard icon and select CTRL+ALT+DELETE .
  2. Enter Password - Pa$$w0rd and hit enter or click on the arrow symbol.
  3. Once logged into the Windows VM, search for Google Chrome Browser and launch it by double clicking.
  4. If prompted to sign in do not sign in.
  5. Copy and paste the following URL into the Chrome browser in the VM

https://dlptest.com/sample-data/

  1. From the Sample Data Library, click Name+CCN+ZIP.
  2. Click Download PDF to download a  sample pdf file.
  3. Expected result: The file should download. This shows a default profile has no controls.

Note: If the file download is blocked, ensure you are not signed in with any account.

Sign in to create a Managed Profile

  1. Log into your Windows Virtual machine by selecting W11client

     

  1. Click CTRL+ALT+DELETE.
  2. Enter Password - Pa$$w0rd
  3. Launch Chrome browser , click the profile avatar > Add a chrome profile.
  1. Click Sign in.

 

  1. Sign in with the Google Test Account[email protected](tenantName)@euclabuat.com and password TempPassword123! .
  2. Click I understand.
  3. Click Continue
  4. Click No thanks.
  5. Click Done.

Test the application boundary rule

  1. Test Download: Browse https://dlptest.com/sample-data/and click Name+CCN+ZIP and select Download PDF.
    • Expected result: The download should be blocked.
  2. Test Paste: Browse https://dlptest.com/https-post/ Copy a sample Credit Card Number from the PDF you downloaded in the baseline test and try to paste it into the "Test Message" field.

    Note: You can use Google Chrome to view the PDF file. 

    • Expected result: The paste action should be blocked.
  3. Test Upload: On the same page, try to upload the sensitive PDF file.
    • Expected result: The file upload should be blocked.
  4. Test Block pasting to Un-authorized sites , profile and applications : Browse https://support.google.com/chrome , copy content like "How can we help you" seen in the webpage and try pasting it to ,
  • Note Pad (Application) :
    • Expected Result : The past option will be blocked and warning message is seen " Pasting this content here is blocked by your administrator"
  • Another Chrome profile :
    • Expected Result: The past option will be blocked and warning message is seen " Pasting this content here is blocked by your administrator"
  • Incognito page:
    • Expected Result: The past option will be blocked and warning message is seen " Pasting this content here is blocked by your administrator"

Test Data protection rule 

  1. Launch Chrome browser and ensure you have logged into chrome using your student credentials.
  2. Browsehttps://support.google.com and keep the tab open.
  3. Open a new tab and browse https://apple.com, copy any content from the website and try pasting it into the search box of google website.
    • Expected Result : You should see a warning " Your administrator has blocked this action"
  4. Open a new tab and browse https://yahoo.com , copy any content from the website and try pasting in into the search box of google website.
    • Expected Result : You should be able to copy content.
  5. Open a new tab and browse https://indiatoday.in, copy any content from the website and try pasting it into the search box of https://support.google.comwebsite.
    • Expected Result: You will see an warning " This action might violate your organization policies " , you will have the permission to Paste anyway or Don't paste.

Test Conditional Access

Using an un-managed browser 

  1. Launch Chrome browser and ensure you are NOT signed in to the browser using your student credentials.
  2. Browse your Omnissa Access tenant https://@lab.Variable(tenantName).us0.wss.workspaceone.com.
  3. Sign in to Omnissa Access tenant using your student credentials

    Username: [email protected](tenantName)@euclabuat.com

    Password :  TempPassword123!

  4. Click Apps.
  5. Click BambooHR to launch it. 

Expected Result : You should see "Access Denied" as you have tried to access a site which can be done only using a managed browser or a managed profile. 

Using a managed profile browser

  1. Launch Chrome browser and ensure you have signed  into chrome browser using your student credentials.
  2. Browse your Omnissa Access tenant https://@lab.Variable(tenantName).us0.wss.workspaceone.com.
  3. Sign in to Omnissa Access tenant using your student credentials

    Username: [email protected](tenantName)@euclabuat.com

    Password :  TempPassword123!

  4. Click Apps.
  5. Click BambooHR to launch it. 

Expected Result : You should successfully access the site as you accessed it using a managed browser. 

Test Blocking Un-authorized sites and Watermarking

Testing Blocking Un-authorised site

Launch Chrome browser and ensure you have signed into chrome browser using student Username - [email protected](tenantName) and Password - TempPassword123! and browse https://makemytrip.com.

  • Expected Result: You should see a warning " The site ahead is blocked by your organization " .

Testing Watermarking sensitive site

Launch Chrome browser and ensure you have signed into chrome browser using your student Username - [email protected](tenantName) and Password - TempPassword123!  and browse https://slack.com.

  • Expected Result: You should see a watermark on the page with a message " Confidential Site [email protected](tenantName)@euclabuat.com ,date & time" . 
Expand or collapse content Task 8 : Test URL filtering policies for Generative AI sites

Launch Chrome browser and ensure you have signed into chrome browser using your student Username - [email protected](tenantName) and Password - TempPassword123! and browse https://chatgpt.comor https://copilot.microsoft.com.

  • Expected Result: You should see a warning " Your organisation says: Your not allowed to access this AI website" as only gemini AI site is allowed.
  • You now browse https://gemini.google.com , it will be successful as its approved.

This is the end of the Lab

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.