You can set policies for tenants on the Configure Policies tab.
You set policies on a per tenant basis. The Policy configuration screen displays the values of configuration parameters for Tenant appliances and Desktop Managers.
Click the Show Description button to show a brief description of each parameter. The default value appears in square brackets.
To change the value of a policy parameter:
- Double-click the row of the parameter you want to change.
- Enter the new value.
- Click OK to make the change or Cancel to retain the current value.
The screen displays only the most common policies by default. To see the full list, including advanced policies, select the web page and type “dtpolicy".
Configure Policies for RDSH Licensing Per Device
This feature provides proper handling of RDSH Per Device client access licenses (CALs) by saving the issued license, supplying it to the RDS host at the time of connection, and saving any upgrades. This prevents potential over-usage of Per Device CALs. It is implemented in Horizon Agent and Horizon Client, and requires Horizon Cloud implementation to support it.
There are two new policies you can set in Service Center to enable this functionality: rds.license.enable
and rds.license.brokeronly.enable
. The default value for both is false. The results of various settings for these policies is shown below.
rds.license.enable | rds.license.brokeronly.enable | Result |
---|---|---|
True | False | CALs are stored both in broker and client. |
True | True | CALs are stored only in broker. |
False | True/False | CALs are not stored in either place. Feature is disabled. |
Configure Policy for Single vCenter Server Configuration
To set up an environment with a single vCenter Server, you must set this policy to true
.
Policy | Description |
---|---|
allow.shared.hostmanager | Controls whether direct a host manager can be shared by management appliances and tenant pool resources.
|
Configure Policies for Agent Update Functionality
In order for the Agent Update functionality to work, you must specify the upgrade server URL in the agentupdate.updateserver.url policy.
Policy | Description |
---|---|
agentupdate.cachePath | File share location for downloading agent installers. The tenant appliance updates this location as needed. |
agentupdate.cipherList | Cryptographic cipher suite to use with SSL when connecting to Update Server [ECDHE-RSA-AES256-GCM-SHA384] |
agentupdate.enable | When enabled (set to true ), The tenant appliance scans for agent updates on the Update Server. Setting this policy to false disables the scan for new agents and also disables the scan for hot patch files on the file share. |
agentupdate.enablehotpatch | When this policy is set to true ), the tenant appliance scans for hot patch files placed on the file share by customer admin. Setting this policy to false disables the scan for hot patch files on the file share. |
agentupdate.job.repeatInterval | Interval (in ms) between scans for new agents on Update Server. Defaults to 24 hours [86400000]. |
agentupdate.job.startDelay | Wait time (in ms) for agent update scan to start after the tenant appliance starts up. Defaults to one minute [60000] . |
agentupdate.sslProtocol | Cryptographic protocols to use with SSL when connecting to Update Server [TLS_V1_2]. |
element.agentupdate.max.concurrent.updates.per.pool | Maximum number of VMs to update at a time in each pool. This value is also the maximum number of failures in a pool after which an agent update task gives up and fails. The default value is 30. |
Configure Policy for Direct Access to VMs
Policy | Description |
---|---|
element.agentcontroller.validate.user.logon.enabled | Controls whether direct access to VM is allowed. Default setting is false .
|
Configure Policies for Domain Security Settings
You use these settings to prevent communication of Active Directory domain names to unauthenticated users using the various Horizon clients. These settings govern whether the information about the Active Directory domains that are registered with your environment is sent to the Horizon end-user clients and, if sent, how it is displayed in end-user clients' login screens.
Policy | Description |
---|---|
secure.domain.list | Controls whether domain information is sent to the client. Settings are as follows.
This setting maps to the same setting in the Administration Console ( ). |
client.hide.domain.list | Controls whether the domain text box is displayed in the client. Settings are as follows.
Note: If the tenant has multiple domains, and the secure.domain.list setting is
true , then the client.hide.domain.list policy must also be set to
true to support launches from Horizon Client versions earlier than 5.0.
This setting maps to the same setting in the Administration Console ( ). |