You configure entitlements to control which remote desktops and applications your users can access. You can configure the restricted entitlements feature to control desktop access based on the Horizon Connection Server instance that users connect to when they select remote desktops. You can also restrict access to a set of users outside the network from connecting to remote desktops and published applications within the network.

For information about configuring global entitlements in a Cloud Pod Architecture environment, see the Administering Cloud Pod Architecture in Horizon document.

Note: When you entitle users and groups in Active Directory, Connection Server searches and counts only those users and groups that belong to the same domain in the Active Directory group. Connection Server does not search for users and groups across all domains in a forest for an Active Directory group. Therefore, in Horizon Console when you navigate to Users and Groups to see the entitled group details, Connection Server provides the counts of only those users and groups that belong to the same domain in the Active Directory group.