Skip to main content

September 2, 2026

Edge with Enterprise App Registration - Plan a Future Service Principal Role for the Microsoft Azure Subscription

To support multitenancy Horizon Edge deployment for Horizon Cloud on Microsoft Azure, you'll choose and apply permissions in your Microsoft Azure portal to a subscription ID that you create as part of the Horizon Edge definition process.

Note: This information is for the scenario in which you intend to create a Horizon Edge for Microsoft Azure as an Omnissa-managed Enterprise App registration type (also referred to as multitenancy) in Horizon Cloud. For this scenario, Omnissa will create your Azure service principal as part of the Edge definition process. If instead, you are planning to create a Horizon Edge using the traditional Manual Enterprise App registration type (also referred to as single tenancy), you must create your own service principal before you can begin to add and deploy a Horizon Edge for Microsoft Azure in Horizon Cloud. If you intend to create the Horizon Edge using the traditional manual method, see Edge with Manual App Registration - Create a Service Principal for the Microsoft Azure Subscription. For related information about these two methods, see the Procedure section of Add and Deploy a Microsoft Azure Edge.

Creating an Edge with Enterprise App Registration is the recommended method.

With multitenancy, your organization accepts our consent link and Omnissa creates a service principal on your tenant and then the app ID and secrets key become something that Omnissa owns and manages on your organization’s behalf. You can add up to 5 Omnissa managed service principals for a provider. To support a total of 5,000 VMs, add 5 Omnissa managed service principals. When you have multiple Omnissa managed service principals, they share the same directory ID, but each Omnissa service principal has its own application ID.

Important: Use the same role for each service principal.

Creating a Horizon Edge for Microsoft Azure as an Omnissa-managed Enterprise App registration type in Horizon Cloud allows administrators to use Omnissa-managed credentials to access Azure subscriptions, eliminating your need to manually manage service principal secrets and key rotations. The Omnissa-managed method places the responsibility of maintaining the service principal secrets key on Omnissa. This provides an added degree of security, as you do not need to provide your secrets key information to Omnissa. You simply grant access to a role that can manage the secrets key for the service principal and assign that role to Omnissa.

Note: If an Omnissa managed app is deleted, you must also manually remove the corresponding app registration from the Microsoft Azure portal if consent was previously granted.

To support this capability, you'll assign a role of your choosing to the service principal when you create the service principal during the Edge definition process. You will assign the role from within your Microsoft Azure portal as part of the Horizon Edge definition process. For details, see the Procedure section of Add and Deploy a Microsoft Azure Edge.

The Contributor role is typically used because it covers all the API calls that Horizon Cloud must perform within the subscription. The role assignment must be a direct assignment. The use of a group-based assignment of a role, in which the role is assigned to a group and the service principal is a member in that group, is not supported.

If your organization prefers to avoid the use of the Contributor role in the subscription, Horizon Cloud supports use of a custom role instead. If used, the custom role needs to provide for the specific API calls that Horizon Cloud needs to use. For more information, see To Use a Custom Role for Horizon Cloud App Registration.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…