The following checklist elements are required for configuring your environment to support Horizon Cloud on Nutanix.
Note: Horizon Cloud on Nutanix is currently available in Limited Availability (LA) mode only.
Machine Identity Requirements
On-premises Active Directory is required for machine identity. To enable VDI desktops to join the specified Active Directory Domain, domain controllers must be reachable from the network where the desktops are to be deployed. You must create a primary and auxiliary domain join accounts.
The Active Directory domain join account is used to perform Sysprep operations and join computers to the domain. Set the account password to never expire. The account requires the following Active Directory permissions:
- Read All Properties
- Reset Password
- Create Computer Objects
- Delete Computer Objects
- Write All Properties
For more information refer to the Active Directory table in the Machine Identity Requirements section of Requirements Checklist for Deploying a Microsoft Azure Edge.
User Identity Requirements
Horizon Cloud relies on an external identity provider and currently supports Microsoft Entra ID (Azure Active Directory) and Workspace ONE Access. The identity provider that you configure with Horizon Cloud performs the authentication required when users attempt to access their desktops.
Regardless of whether you employ Microsoft Entra ID or Workspace ONE Access, you must connect an on-premises Active Directory to the external identity provider. For details, see Setting Up Your Identity Provider.
Nutanix AHV and Prism Central Requirements
The following Nutanix Prism Central configurations are required.
Nutanix AHV Hypervisor Installation and Cluster Setup
- Use Nutanix Foundation tool or manual Phoenix installer to install AHV on the physical hosts.
- For a cluster, minimum 3 AHV hosts are required.
- Re-image all nodes using Foundation for a clean installation.
- After installation, join the nodes into a cluster via Prism Element.
- Ensure each host and CVM has unique IPs and proper DNS and NTP configurations.
- If you intend to create a multi-node cluster later, do not select Create single node cluster during install.
- Plan your Management and CVM IP addresses.
Network Configuration with VLANs
- Create 3 VLANs/networks for DMZ, Management, and Desktop traffic. These 3 networks are needed by Horizon Cloud.
- Configure VLAN tagging on physical switches and map them correctly using Prism Element networking.
- Create networks in Prism with VLAN tagging to keep traffic segregated by function.
- Ensure ACLs are configured to control traffic flow, especially between DMZ and internal networks.
- Create separate bridges in AHV for each VLAN or tag VLANs on a shared bridge such as br0.
Storage Configuration
- Use Nutanix recommended storage pool configuration: one storage pool per cluster is typical.
- Specify a Replication factor value of 3 for 5+ node clusters.
- Create storage containers within the Nutanix recommended storage pool for VMs.
- Enable compression/deduplication to optimize usage.
- Follow best practices for raid and disk configuration on nodes before imaging.
- By default, Nutanix distributed storage provides high availability and local I/O performance.
Licensing for VDI Workloads
- Nutanix VDI licenses are based on a term license, typically yearly, and based on Maximum Concurrent Users.
- Must be applied to a dedicated cluster supporting only VDI workloads.
- Starter, Pro, and Ultimate editions provide increasing features, with Ultimate including advanced replication and security.
- VDI licenses are independent of core-based licensing. Consult the Nutanix VDI product page for ordering part numbers and detailed license features.
Prism Central Installation and Configuration Considerations
Prism Central manages multiple Nutanix clusters and provides analytics, lifecycle management, and reporting.
- Prism Central should be deployed on-prem as a single node for smaller environments or as a scale-out 3-node cluster for high availability. The 3-node Prism Central deployment runs 3 VMs for fault tolerance.
- An Admin account with full privileges is required for installation and cluster management.
- For additional security, custom roles with granular permissions can be created and assigned by using information found in your Nutanix Prism Central User Guide.
- A single Prism Central instance supports up to 12k VMs, scale-out supports up to 25k.
- Ensure network configuration allows communication between Prism Central and cluster nodes.
While the Admin should have the admin role, you can optionally create a custom role and assign it to a user by using Authorization Policies. For related information, see Security and User Management in Nutanix Prism product documentation.
Refer to the following table for the minimum required permission for a custom role.
| Object | Permission |
|---|---|
| Cluster | View Cluster |
| Cluster Host | View Cluster Host |
| Subnet | View Subnet |
| Storage Containers | View Storage Containers |
| AHV Virtual Machine | View Virtual Machine |
| AHV Virtual Machine | View VM by ID |
| AHV Virtual Machine | Allow Virtual Machine Power Off |
| AHV Virtual Machine | Allow Virtual Machine Power On |
| AHV Virtual Machine | Clone Virtual Machine |
| AHV Virtual Machine | ACPI Reboot Virtual Machine |
| AHV Virtual Machine | ACPI Shutdown Virtual Machine |
| AHV Virtual Machine | View Existing Virtual Machine |
| AHV Virtual Machine | Update Virtual Machine |
| AHV Virtual Machine | Delete Virtual Machine |
| AHV Virtual Machine | Revert Existing Virtual Machine |
| AHV Virtual Machine | Reset Virtual Machine |
| AHV Virtual Machine | Update Virtual Machine Categories |
| AHV Virtual Machine | Unmount Virtual Machine CDROM |
| AHV Virtual Machine | Update Virtual Machine NGT Config |
| Recovery Point | Create Recovery Point |
| Recovery Point | Delete Recovery Point |
| Recovery Point | View Recovery Point |
| Task | View Task |
| Category Management | Create Or Update Name Category |
| Category Management | Create Or Update Value Category |
| Category Management | Delete Name Category |
| Category Management | Delete Value Category |
| Category Management | View Value Category |
| VM Templates (Templates) | View VM Templates |
| VM Templates (Templates) | Deploy VM Templates |
Networking Requirements
For networking requirements, see Configure Network Settings for Nutanix Edge Deployments.
Was this page helpful?