Skip to main content

September 2, 2026

Getting Started with Horizon Cloud on an Amazon WorksSpaces Core Edge Deployment

When you plan to deploy a Horizon Cloud environment using Amazon WorkSpaces Core as your capacity provider, you begin by deploying a Horizon Edge. A Horizon Edge represents the edge of your Horizon Cloud infrastructure, where the cloud-managed Control Plane connects to your Amazon resources, such as compute, networking, gateways, and desktop capacity hosted in AWS.

This introductory topic explains the overall purpose, high-level concepts, and preparatory steps to understand before you proceed with the checklist and other tasks.

What a Horizon Cloud on Amazon WorkSpaces Core Edge Deployment Provides

Flexibility and Scalability - You can start small and grow. Each Horizon Edge can draw from an AWS account and, optionally, additional capacity providers. You can also add more Horizon Edges or providers in the future as demand increases.

Unified Cloud Management - Even though capacity lives in Amazon Web Services, management and orchestration remain centralized through the Horizon Cloud Control Plane, providing consistent access and control across locations.

Key Concepts

  • Capacity Provider - For Amazon WorkSpaces Core deployments, your AWS account acts as the capacity provider that supplies compute, network, and WorkSpaces Core resources for the Horizon Edge.

  • Amazon Virtual Private Cloud (VPC) - Each Horizon Edge requires a dedicated VPC. The VPC must include correctly configured subnets for management components, external access, if applicable, and desktop capacity.

  • Gateways and Networking - A Horizon Edge includes gateway appliances for user access and management. Proper networking is required (subnets, route tables, NAT gateways, load balancing, security groups, and other AWS networking constructs) to ensure that traffic flows securely and efficiently.

  • Identity & Permissions - You must configure IAM permissions in AWS, including IAM roles and policies that allow the Horizon Cloud Control Plane to deploy and manage the required resources in your AWS account on your behalf.

What to Expect

Be prepared to put the following in place:

  • An AWS Account - Preferably an account dedicated to Horizon Edge deployments to reduce conflicts with unrelated workloads.

  • AWS Identity and Permissions Configured - Create the required IAM roles and policies with the correct permissions so the Horizon Cloud deployment wizard can provision WorkSpaces Core capacity and supporting resources in AWS.

  • Plan Your Networking Topology

    • Decide whether to use an existing VPC or create a new one.
    • Plan the required subnets for management and desktop workloads.
    • Plan NAT or Internet access if needed, load balancing, route tables, and security group rules.
    • Consider VPC peering or AWS Direct Connect if integrating with existing infrastructure, such as on-premises AD or DNS.
  • Prepare DNS, Domain, and Identity Integration - If you plan to provide domain-joined desktops or single sign-on, ensure your Active Directory and DNS infrastructure is ready. Depending on your deployment model, this might reside in AWS, on-premises, or in a hybrid identity environment.

How This Getting Started Section is Structured

The topics following this introduction are organized to take you step-by-step through everything you need before deployment, including:

  • A requirements checklist
  • Preparing AWS accounts, IAM roles, and permissions
  • Networking: VPCs, subnets, NAT, load balancing, route tables, security groups
  • DNS, domain, and identity prerequisites, including Active Directory and SSO considerations
  • AWS-specific configuration and registration steps within Horizon Cloud
  • (Optional) Guidance for scaling, additional capacity providers, and multi-Edge deployments

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…