In Horizon Cloud, complete the following steps in Horizon Universal Console to register the first Active Directory domain with the service or register additional Active Directory domains.
As described in Identity and Access Management, the service uses the registered Active Directory for machine identity for the virtual desktops and remote applications.
Prerequisites
-
Active Directory Requirements
The console's Domain Registration wizard requires input of specific information. Before doing these steps in the console, verify that you or your IT team have fulfilled the Active Directory related requirements as described in the Active Directory requirements section in the requirements checklist for your capacity type:
-
LDAPS-Specific Key Points and Requirements
If you plan to use LDAPS in your deployment, note the following key points and requirements.
-
PEM-encoded root and intermediate CA certificates must be ready for upload.
-
Self-signed certificates are not supported.
-
The service requires that your DNS have SRV records for the domains configured to use LDAPS. Choosing to use LDAPS for a domain implicitly mandates the use of SRV records.
-
As a strong recommendation, your AD environment should be configured to enforce channel binding. Enforcing channel binding is a vital part of correctly securing LDAPS, especially to avoid man-in-the-middle (MITM) attacks.
-
Your firewall configuration must allow outbound connections from the Horizon Edge Gateway to your domain controllers with the following ports and protocols as described in the port and protocol requirements for your capacity type:
-
Port 88/TCP - Kerberos authentication
-
Ports 636/TCP and 3269/TCP - LDAPS communication
-
You must have a HTTP revocation endpoint defined for all certificates in the trust chain except for the root certificate and that endpoint must be reachable over
HTTP. This requirement includes the following points: -
The service will perform revocation checks using the OCSP or CRL
HTTPURLs that are defined in your certificates. -
The service cannot perform a revocation check if a certificate does not define an OCSP or CRL endpoint for the HTTP protocol. In that case, LDAPS connectivity fails.
-
Line of sight revocation must be available to endpoints. Your firewalls must not block outbound traffic to your revocation endpoint over
HTTP.
-
Procedure
-
Click Integrations in the left pane, and in the Identity & Access tile, click Manage.
-
On the Domains tab, start the console's Domain Registration wizard by clicking Add.
-
In the first wizard step, provide the indicated information
Field Description Name The name of the Active Directory domain. Description Optional description. DNS Domain Name The fully qualified name for this Active Directory domain (for example our-ad.example.com).Default OU Type an appropriate default OU. This OU is the Active Directory organizational unit (OU) that you want the service to use as a default when it adds the machine identities it creates for the virtual desktops and remote apps..
Type the OU's full distinguished name, such asOU=MyOrg,DC=our-ad,DC=example,DC=com.
Note: If you want to use the default ofCN=Computers, you must type that into the field. Even though you might see the UI display this default value in the field, the wizard will not make the Next button available unless you type it directly in this field.Domain Bind Accounts Provide the user names and passwords for the two service accounts that you or your IT team have configured for this purpose, as described in the Active Directory requirements section in the requirements checklist for your capacity type: - Requirements Checklist for Deploying a Microsoft Azure Edge
- Requirements Checklist for Deploying an Amazon WorkSpaces Core Edge
- Requirements Checklist for Deploying a vSphere Edge
Ensure that the accounts entered here meet the requirements detailed in the requirements checklist.Domain Join Accounts Provide the user names and passwords for the two service accounts that you or your IT team have configured for this purpose, as described in the Active Directory requirements section in the requirements checklist for your capacity type: - Requirements Checklist for Deploying a Microsoft Azure Edge
- Requirements Checklist for Deploying an Amazon WorkSpaces Core Edge
- Requirements Checklist for Deploying a vSphere Edge
Ensure that the accounts entered here meet the requirements detailed in the requirements checklist.Protocol Select the protocol, LDAP or LDAPS, to use to connect your Active Directory to the Horizon Edge Gateway.
If you select LDAPS, use the Browse feature to upload your PEM-encoded root and intermediate CA certificates, which are referenced in the prerequisites for this task.When you have input all the required information, the system makes the Next button available.
-
Proceed to the next wizard step by clicking Next.
At this point, the wizard makes available the Save action to complete saving the domain information to the system.
- If you aren't planning to use SSO, you can complete the UI wizard at this point by clicking Save.
- If you plan to use the True SSO feature, continue to the next step in this page. Use of the True SSO feature requires a Microsoft Enterprise Certificate Authority, as described in Supported Certificate Authority Types for Using SSO with a Horizon Edge.
- If you plan to use SSO that relies on the Horizon Cloud CA or certificate authorities other than a Microsoft Enterprise Certificate Authority, you can complete the UI wizard at this point by clicking Save. Later you can complete that SSO configuration using the steps in Add an SSO Configuration for Horizon Cloud CA.
-
(Optional) If you plan to use True SSO with your end users' virtual desktops and remote apps, in the wizard's Domain Enrollment Service Account section, switch on the Use Enrollment Service Account toggle.
When that toggle is switched on, the UI displays fields for you to enter the account credentials for the domain enrollment accounts that the True SSO feature requires. Provide that information.
Attention: If you instead plan to use SSO that relies on the Horizon Cloud CA, you can skip this step of entering domain enrollment account information.
A domain enrollment account is an enrollment service account that the True SSO feature uses to obtain short-term certificates from Microsoft AD CS (Active Directory Certificate Services). True SSO uses the certificates for authentication, to avoid prompting users for Active Directory credentials. You might see the Horizon Universal Console using the terms domain enrollment account, enrollment service account, and domain enrollment service account interchangeably.
After you complete the fields, the wizard makes available the Save action to complete saving the domain information to the system.
Click Save to complete saving all the information you provided in the wizard.
Results
Your configuration of Active Directory with Horizon Edge is finished.
What to do next
At completion of the preceding steps, the service has the Active Directory domain information that it requires for a Horizon Cloud deployment.
To learn about adding the ability for your end users to have single sign-on (SSO) when accessing their desktops and applications, see Supported Certificate Authority Types for Using SSO with a Horizon Edge.
Was this page helpful?