In the App Volumes Directory Services Domains page, you can register Active Directory or Entra ID as the domain. Depending on the registered domain, you can assign applications to users, computers, groups, and organizational units (OUs).
Note:
- With Entra ID as the registered domain, you can assign application groups to users, groups, and computers.
- To integrate App Volumes Manager with Azure Virtual Desktop through the Azure Marketplace offer, only Entra ID can be configured as the registered domain. For this integration, App Volumes Manager must be installed in the Azure Marketplace. For more information about this deployment, see the Deploy App Volumes Manager through Azure Marketplace section in the App Volumes Install Guide at Omnissa Product Documentation.
App Volumes Manager connects securely with Entra ID using pre-installed certificates present within App Volumes Manager.
You can register either Active Directory or Entra ID as a domain type only during a fresh install of App Volumes Manager. After you register a domain type, you cannot change the domain type. The registered domain can be edited or removed using the Edit and Remove functionalities respectively.
Prerequisites
Depending on the domain type selected, ensure that you follow these prerequisites:
| Domain Type | Prerequisites |
|---|---|
| Active Directory |
|
| Entra ID |
For more information about how to register an application in Microsoft Entra ID, see the Microsoft Documentation |
Active Directory Parameters
If you register Active Directory as the domain, the following parameter information must be provided:
| Parameter | Description |
|---|---|
| Domain Type | Active Directory |
| Active Directory Domain Name | A fully qualified domain name of the Active Directory domain where users and target computers are residing, for example, corp.example.com. Note: When the domain name is configured to use the NETBIOS name while logging into App Volumes Manager, ensure that the NETBIOS name does not contain a period (.). |
| Domain Controller Hosts (Optional) |
IP address (10.98.87.67) or FQDN (dc01.corp.example.com). You can also provide the virtual IP address of a load balancer that is used as the front-end server of the domain controller. This option provides High Availability (HA) capability for connections to Active Directory. Note: Do not include any non-ASCII characters in the domain controller name. You can add multiple domain controller hosts; use commas to separate the names of the hosts. Important: If you do not add a domain controller host, the system detects the hosts that are available and connect to the nearest domain controller. |
| LDAP Base (Optional) | Distinct name of the Active Directory container or organizational unit that stores required entities (if you want to limit the scope of enumeration). By default, App Volumes Manager enumerates all users, groups, OUs, and computer objects within Active Directory. Example: OU=Engineering, DC=corp, DC=omnissa, DC=com |
| Username | The user name of the service account that has access to the target Active Directory domain. For example, admin-1. The user can be an administrator with read-only permissions. |
| Password | The password for the service account. Ensure that domain policies do not enforce password expiration for the service account. |
| Security |
To configure the LDAP connection, select one of the following options from the drop-down menu:
|
| Port (Optional) | A port number other than the default. The default port is used if this text box is left blank. |
Procedure
-
In the App Volumes Manager admin UI, go to CONFIGURATION > Domains.
-
Click Register Domain.
-
In the Register Domain page, perform the appropriate steps depending on the domain type:
Domain Type Steps Active Directory Enter the values for the Active Directory parameters.
See Active Directory Paramters.Entra ID - Enter the Domain Type as
Entra ID. - Enter these values which are obtained when registering App Volumes as an application in Microsoft Entra ID: Directory (tenant ID), Application (client) ID, Secret ID, and Client Secret.
- If you have configured the Redirect URIs and the required Manifest setting in the Azure portal, then select the Redirect URIs and Manifest checkbox for confirmation.
- Enter the Domain Type as
-
Click Register.
If Entra ID is the domain type, then in the Entra ID Registration Successful window, click Continue.
You are redirected to the screen which has the Sign in with Microsoft button.
Enter your Microsoft Azure credentials, follow the prompts, and click Get Started in App Volumes Manager.
What To Do Next
-
If you have configured Entra ID as the registered domain for integrating App Volumes Manager with Azure Virtual Desktop, then complete the rest of the App Volumes Manager configurations and Configure App Volumes Manager Integration with Azure Virtual Desktop.
-
To update and change the configured information for the registered domain type, go to the Domains page, select the desired domain in the list, and use the Edit functionality.
Note: For the Entra ID domain type, the Client Secret must be updated before it expires.
-
To remove a registered domain, go to the Domains page, select the desired domain in the list, and use the Remove functionality.
Note: A minimum of one domain must be registered at all times. If there's just a single domain, then this domain cannot be removed.
-
To register another Entra ID domain, click Register Domain.
You can register multiple Entra ID domains. These domains are listed in the Directory Services Domains page. Registering multiple domains allows you to log into App Volumes Manager using the domain of your choice at the time of login. Additionally, having multiple domains allows you to create entitlements for users in each of these domains.
If multiple domains are present, a Domain column is displayed in addition to other details in the DIRECTORY tab and the Assignments page.
Handling Authentication Failures
When Active Directory is the registered domain type, then App Volumes inherits the authentication and account policies of Active Directory.
Active Directory implements authentication measures such as inserting random delays between failed authentications, configuring the number of failed authentication attempts, and so on.
For additional information, see Windows Authentication Overview and Group Policy Settings Used in Windows Authentication.
Was this page helpful?