Skip to main content

September 2, 2026

Identity and Access Management in a Horizon Cloud Environment

The preparatory information that follows outlines how to deploy and use identity and access management in a Horizon Cloud environment.

Understanding User Identity and Machine Identity

A key aspect of how Horizon Cloud manages identity is that Horizon Cloud makes a distinction between user identity and machine identity, and it relies on both types of identity when establishing a secure connection between a client and a remote desktop or application.

In Horizon Cloud, you must set up an identity configuration consisting of an identity provider to authenticate the user identity and an identity provider to authenticate the machine identity.

  • User Identity

    Horizon Cloud requires you to register a user identity provider. The service uses this identity provider to authenticate client users attempting to access remote desktops and applications.

    Therefore, user identity refers to people, such as employees and others, who log in to access resources. In this situation, Horizon Cloud is not, itself, the identity system. You use one of the supported identity providers to authenticate users, evaluate group membership, assign resources, and apply Single Sign-On (SSO). Moreover, you control your directoy and access policies, not Horizon Cloud.

  • Machine Identity

    Horizon Cloud also requires you to register a machine identity provider. The service uses this identity provider to establish the machine identity of virtual machines that provide remote desktops and applications. Through the machine identity provider, the service joins remote desktops and the virtual machine sources for remote applications to the trusted network domain that client users are entitled to access.

    Therefore, machine identity refers to the approach that Horizon Cloud uses to confirm trust in the virtual desktops and RDSH servers that users connect to. Trust is verified using device certificates, machine registrations, and secure agent communication. In this situation, Horizon Cloud handles machine trust, not an identity provider, which allows for scalable and secure multi-cloud support.

Requirements for User Identity and Machine Identity

For a breakdown of how Horizon Cloud handles user identity and machine identity and details of the requirements involved, see the identity sections of the appropriate topic depending on your capacity provider:

Administrators and Role-Based Access Control RBAC

For administrator access to your environment, the service provides role-based access control using the features of Omnissa Cloud Services. These controls ensure that only authorized personnel have the appropriate levels of access. The controls are based on the principle of least privilege. For more information, see Adding More Users and Assigning Roles.

Security Considerations

For information about security controls in Horizon Cloud, see Horizon Cloud security overview in Omnissa Tech Zone.

What to do next

When you have completed the applicable domain and identity provider configurations for your intended use, as described in the topics that follow, deploy the appropriate Horizon Edge as described in Using and Managing Horizon Cloud.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…