Horizon Administration
Horizon Administration
Using VMware Horizon Console
Log In to Horizon Console
Tips for Using the Horizon Console Interface
Configuring Horizon Connection Server
Configuring vCenter Server in Horizon Console
Remove a vCenter Server Instance from VMware Horizon
Conflicting vCenter Server Unique IDs
Disable or Enable Horizon Connection Server in Horizon Console
Understanding VMware Horizon Services
Stop and Start VMware Horizon Services
Services on a Connection Server Host in a VMware Horizon 8 Environment
Configuring Untrusted Domains
Domain Bind Account Properties
Add a Domain Bind Account
Manage Auxiliary Domain Bind Accounts
Configuring Settings for Client and Console Sessions
Set Options for Client Sessions and Connections
Global Settings for Client and Console Sessions
Global Security Settings for Client Sessions and Connections
Global Client Restriction Settings for Client Sessions
VMware Customer Experience Improvement Program
Setting Up Smart Card Authentication
Logging In with a Smart Card
Configure Smart Card Authentication on Horizon Connection Server
Obtain the Certificate Authority Certificates
Obtain the CA Certificate from Windows
Add the CA Certificate to a Server Truststore File
Modify Horizon Connection Server Configuration Properties
Configure Smart Card Settings in Horizon Console
Configure Smart Card Authentication on Third Party Solutions
Verify Your Smart Card Authentication Configuration in Horizon Console
Using Smart Card Certificate Revocation Checking
Logging in with CRL Checking
Logging in with OCSP Certificate Revocation Checking
Configure CRL Checking
Configure OCSP Certificate Revocation Checking
Smart Card Certificate Revocation Checking Properties
Using Smart Card Caching Emulation
Setting Up Other Types of User Authentication
Using Two-Factor Authentication
Logging in Using Two-Factor Authentication
Enable Two-Factor Authentication in Horizon Console
Troubleshooting RSA SecureID Access Denied
Troubleshooting RADIUS Access Denial
Using SAML Authentication
Using SAML Authentication for VMware Workspace ONE Access Integration
Configure a SAML Authenticator in Horizon Console
Configure Proxy Support for VMware Workspace ONE Access
Change the Expiration Period for Service Provider Metadata on Connection Server
Generate SAML Metadata So That Connection Server Can Be Used as a Service Provider
Response Time Considerations for Multiple Dynamic SAML Authenticators
Configure Workspace ONE Access Policies in Horizon Console
Configure Biometric Authentication
Authenticating Users and Groups
Restricting Remote Desktop Access Outside the Network
Configure Remote Access
Configuring Unauthenticated Access
Create Users for Unauthenticated Access
Enable Unauthenticated Access for Users
Entitle Unauthenticated Access Users to Published Applications
Search Unauthenticated Access Sessions
Delete an Unauthenticated Access User
Unauthenticated Access From Horizon Client
Configure Login Deceleration for Unauthenticated Access to Published Applications
Configure Users for Hybrid Logon in Horizon Console
Using the Log In as Current User Feature Available with Windows-Based Horizon Client
Authentication with Windows Hello for Business
Setting Up True SSO
Set Up an Enterprise Certificate Authority
Create Certificate Templates Used with True SSO
Install and Set Up an Enrollment Server
Export the Enrollment Service Client Certificate
Import the Enrollment Service Client Certificate on the Enrollment Server
Configure SAML Authentication to Work with True SSO
Configure Horizon Connection Server for True SSO
Command-line Reference for Configuring True SSO
Commands for Managing Enrollment Servers
Commands for Managing Connectors
Commands for Managing Authenticators
Advanced Configuration Settings for True SSO
Horizon Agent Configuration Settings
Enrollment Server Configuration Settings
Connection Server Configuration Settings
Identify an AD User That Does not Have an AD UPN
Unlock a Desktop With True SSO and Workspace ONE
Using the Dashboard to Troubleshoot Issues Related to True SSO
Entitling Users and Groups
Add Entitlements to a Desktop or Application Pool in Horizon Console
Remove Entitlements from a Desktop or Application Pool in Horizon Console
Review Desktop or Application Pool Entitlements
Configuring Shortcuts for Entitled Pools
Create Shortcuts for a Desktop Pool in Horizon Console
Create Shortcuts for an Application Pool in Horizon Console
Implementing Client Restrictions for Desktop Pools, Published Desktops, and Application Pools
Configuring Role-Based Delegated Administration
Understanding Roles and Privileges
Using Access Groups to Delegate Administration of Pools and Farms in Horizon Console
Different Administrators for Different Access Groups
Different Administrators for the Same Access Group
Understanding Permissions and Access Groups
Manage Administrators
Create an Administrator in Horizon Console
Remove an Administrator in Horizon Console
Manage and Review Permissions
Add a Permission in Horizon Console
Delete a Permission in Horizon Console
Review Permissions in Horizon Console
Manage and Review Access Groups
Add an Access Group in Horizon Console
Move a Desktop Pool or Farm to a Different Access Group in Horizon Console
Remove an Access Group in Horizon Console
Review the Objects in an Access Group
Review the vCenter Virtual Machines in an Access Group
Manage Custom Roles
Add a Custom Role in Horizon Console
Modify the Privileges in a Custom Role in Horizon Console
Remove a Custom Role in Horizon Console
Predefined Roles and Privileges
Predefined Administrator Roles
Global Privileges
Object-Specific Privileges
Privilege Scopes
Internal Privileges
Minimum vCenter Server Privileges for Managing Full Clones and Instant Clones
Required Privileges for Common Tasks
Privileges for Managing Pools
Privileges for Managing Machines
Privileges for Managing Users and Administrators
Privileges for Managing a Cloud Pod Architecture Environment
Privileges for Managing Access Groups and Federation Access Groups
Privileges for Managing Sessions and Global Sessions
Privileges for Horizon Help Desk Tool Tasks
Privileges and Roles for General Administration Tasks and Commands
Best Practices for Administrator Users and Groups
Setting Group Policies for Horizon Components
VMware View Server Configuration ADMX Template Settings
VMware View Common Configuration ADMX Template Settings
Maintaining Horizon Components
Backing Up and Restoring VMware Horizon Configuration Data
Backing Up Horizon Connection Server Data
Schedule VMware Horizon Configuration Backups
Horizon Configuration Backup Settings
Export Configuration Data from Horizon Connection Server
Restoring Horizon Connection Server Configuration Data
Import Configuration Data into Horizon Connection Server
Setting Up Clients in Kiosk Mode
Configure Clients in Kiosk Mode
Prepare Active Directory and VMware Horizon for Clients in Kiosk Mode
Set Default Values for Clients in Kiosk Mode
Display the MAC Addresses of Client Devices
Add Accounts for Clients in Kiosk Mode
Enable Authentication of Clients in Kiosk Mode
Verify the Configuration of Clients in Kiosk Mode
Connect to Remote Desktops from Clients in Kiosk Mode
Monitoring and Troubleshooting in Horizon Console
Using Horizon Help Desk Tool in Horizon Console
Start Horizon Help Desk Tool in Horizon Console
Troubleshooting Users in Horizon Help Desk Tool
Session Details for Horizon Help Desk Tool
Session Processes for Horizon Help Desk Tool
Application Status for Horizon Help Desk Tool
Troubleshoot Desktop or Application Sessions in Horizon Help Desk Tool
Using the VMware Logon Monitor
Logon Monitor Configuration Settings
Using VMware Horizon Performance Tracker
Configuring VMware Horizon Performance Tracker
Configure the Horizon Performance Tracker Group Policy Settings
Run Horizon Performance Tracker
Configuring Load Balancers for Horizon Connection Server Health Monitoring
Monitor VMware Horizon Components
Monitor Horizon Connection Server Load Status
Monitor Services on Horizon Connection Server
Monitoring Term License Usage
Change the Product License Key or License Modes in Horizon Console
Reset Perpetual License Usage Data
Monitor Machine Status
Monitor Events in VMware Horizon
VMware Horizon Event Messages
Collecting Diagnostic Information for VMware Horizon
Create a Data Collection Tool Bundle for Horizon Agent
Using DCT to Collect Logs for Remote Desktop Features and Components
Horizon Client for Windows Log Files
Horizon Client for Mac Log Files
Horizon Client for Linux Log Files
Horizon Client Log Files on Mobile Devices
Horizon Agent Log Files on Windows Machines
Linux Desktop Log Files
Save Diagnostic Information for Horizon Client for Windows
Collect Diagnostic Information for Horizon Connection Server
Collect Diagnostic Information for Horizon Agent, Horizon Client, or Horizon Connection Server from the Console
Collect Logs in Horizon Console
Horizon Connection Server Integration with Skyline Collector Appliance
Update Support Requests
Send Feedback
Troubleshooting VMware Horizon Server Certificate Revocation Checking
Troubleshooting Smart Card Certificate Revocation Checking
Further Troubleshooting Information
Using the vdmadmin Command
vdmadmin Command Usage
vdmadmin Command Authentication
vdmadmin Command Output Format
vdmadmin Command Options
Configuring Logging in Horizon Agent Using the -A Option
Overriding IP Addresses Using the -A Option
Updating Foreign Security Principals Using the ‑F Option
Listing and Displaying Health Monitors Using the ‑H Option
Listing and Displaying Reports of VMware Horizon Operation Using the ‑I Option
Generating VMware Horizon Event Log Messages in Syslog Format Using the ‑I Option
Assigning Dedicated Machines Using the ‑L Option
Displaying Information About Machines Using the -M Option
Reclaiming Disk Space on Virtual Machines Using the ‑M Option
Configuring Domain Filters Using the ‑N Option
Configuring Domain Filters
Example of Filtering to Include Domains
Example of Filtering to Exclude Domains
Displaying the Machines and Policies of Unentitled Users Using the ‑O and ‑P Options
Configuring Clients in Kiosk Mode Using the ‑Q Option
Displaying the First User of a Machine Using the -R Option
Removing the Entry for a Connection Server Instance Using the ‑S Option
Providing Secondary Credentials for Administrators Using the ‑T Option
Displaying Information About Users Using the ‑U Option
Unlocking or Locking Virtual Machines Using the ‑V Option
Detecting and Resolving LDAP Entry and Schema Collisions Using the -X Option
Integrating VMware Horizon with the Event Database
Event Database Tables and Schemas
Horizon Connection Server Events
Horizon Agent Events
Horizon Console Events
Event Message Attributes
Sample Database Queries and Views
Customizing LDAP Data
Introduction to LDAP Configuration Data
Modifying LDAP Configuration Data
Export LDAP Configuration Data
Defining a Desktop Pool in an LDIF Configuration File
Sample LDIF Configuration File Desktop Pool Entries
Import LDAP Configuration Data
Connecting the VMware Horizon Deployment to the Horizon Control Plane
Using the Horizon PowerCLI Module
Set Up the Horizon PowerCLI Module
Run Example Horizon PowerCLI Scripts