Workspace ONE Access User Authentication Flows - Configuring Password (Cloud Deployment) From Start to Finish

Opening:
This is a quick and rough guide to enabling "Password (cloud deployment)" in Workspace ONE Access as VMware documentation no longer covers this completely.

Outcome:
This procedure will allow a customer admin to change from direct Password authentication via Workspace ONE Access Connector(s) to indirect Password (Cloud Deployment) authentication via Workspace ONE Access Connector(s).


Assumptions:
  1. Workspace ONE Access tenant exists
  2. Workspace ONE Access admin login capable


Logic Flow:
  1. Within the Workspace ONE Access admin console, navigate to Identity & Access Management > (Manage) > Identity Providers. Does Workspace ONE Access Built-in Identity Provider exist?
    1. Yes, continue on to 2.
    2. No.
      1. Create a new "Built-in" IDP by clicking the ADD IDENTITY PROVIDER button in the upper right.
  2. Is there a Connector assigned to the Built-in IDP?
    1. Yes, continue on to 3.
    2. No
      1. Go into Identity & Access Management > Identity Providers > Built-in (or whatever it might be renamed to). You should see a box in the Connectors section to select (and then add) your connector(s).
      2. After selecting your connector, click Add Connector.
      3. Repeat these three steps for each connector you wish to add.
  3. Does the Password (Cloud Deployment) box now appear under Connector Authentication Methods within the Built-in IDP?
    1. Yes, continue on to step 4.
    2. No, troubleshoot Step 2.
      NOTE: You may need to click the SAVE button and return back to the Built-in IDP screen in order to see a box. If one does not appear, ensure your connector(s) are properly added and show with a red X (which allows for deletion).
    3. Open a support ticket with VMware Support if necessary.
  4. Is the Password (Cloud Deployment) box checked?
    1. Yes, continue on to step 5.
    2. No, check the Password (Cloud Deployment) box.
    3. Click the SAVE button at the bottom of the Built-in IDP screen.
  5. Within the Workspace ONE Access admin console, navigate to Identity & Access Management > (Manage) > Policies and open the default_access_policy_set.
  6. Edit the default_access_policy_set and navigate to step "2 Configuration" within the EDIT POLICY wizard. Open each policy rule one at a time.
  7. Does the policy rule show "Password" as the authentication type in the "then the user may authenticate using" drop-down box?
    1. If NO, then continue on to the next policy rule.
    2. If YES, then modify the policy rule to replace Password with Password (cloud deployment) and click SAVE.
    3. If no more policy rules, click NEXT and SAVE on the EDIT POLICY wizard.
  8. Do the Password (Cloud Deployment) modifications now work locally and remotely?
    1. Yes. You are finished.
    2. No. Troubleshoot policy modifications in step 8. If necessary open a support ticket with VMware Support.




Resources:



Notes on Creating (or recreating) the Built-in IdP:
This is assuming the default "Built-in" IdP was deleted or not created from the start. iIn this event, one can just create a new "Built-in" IDP by clicking the ADD IDENTITY PROVIDER button in the upper right and selecting the option in the menu to create a built-in IdP.

Go into Identity & Access Management > Identity Providers > Built-in (or whatever it might be renamed to).You should see a box in the Connectors section to select (and then add) your connector(s). Do so.

Once you finish adding your connector(s), you will see "Password (cloud deployment)" show in the Connectors Authentication Methods section.Check it and click SAVE



Now go back to Identity & Access Management > Policies and edit your default_authentication_policy and swap out "Password" for "Password (Cloud Deployment)" for ALL policy rules which use "Password". Save each rule.

Edit each policy rule and change out "Password" for "Password (cloud deployment)". Click Save on each Policy Rule until all are correctly modified.