Skip to main content

March 25, 2025

Configure Smart Card Settings in Omnissa Horizon Console

You can use Horizon Console to specify settings to accommodate different smart card authentication scenarios.

Prerequisites

  • Modify Omnissa Horizon Connection Server configuration properties on your Horizon Connection Server host.
  • Verify that Horizon clients make HTTPS connections directly to your Horizon Connection Server host. Smart card authentication is not supported if you off-load TLS to an intermediate device.

Procedure

  1. In Horizon Console, select Settings > Servers.

  2. On the Horizon Connection Servers tab, select the Horizon Connection Server instance and click Edit.

  3. To configure smart card authentication for remote desktop and application users, perform these steps.

    1. On the Authentication tab, select a configuration option from the Smart card authentication for users drop-down menu in the Horizon Authentication section.

      OptionAction
      Not allowedSmart card authentication is disabled on the Horizon Connection Server instance.
      OptionalUsers can use smart card authentication or password authentication to connect to the Horizon Connection Server instance. If smart card authentication fails, the user must provide a password.
      RequiredUsers are required to use smart card authentication when connecting to the Horizon Connection Server instance. When smart card authentication is required, authentication fails for users who select the Log in as current user check box when they connect to the Horizon Connection Server instance. These users must reauthenticate with their smart card and PIN when they log in to Horizon Connection Server. Note: Smart card authentication replaces Windows password authentication only. If SecurID is enabled, users are required to authenticate by using both SecurID and smart card authentication.
    2. Configure the smart card removal policy.

      You cannot configure the smart card removal policy when smart card authentication is set to Not Allowed.

      OptionAction
      Disconnect users from Horizon Connection Server when they remove their smart cards.Select the Disconnect user sessions on smart card removal check box.
      Keep users connected to Horizon Connection Server when they remove their smart cards and let them start new desktop or application sessions without reauthenticating.Deselect the Disconnect user sessions on smart card removal check box.

      The smart card removal policy does not apply to users who connect to the Horizon Connection Server instance with the Log in as current user check box selected, even if they log in to their client system with a smart card.

    3. Configure the smart card user name hints feature.

      You cannot configure the smart card user name hints feature when smart card authentication is set to Not Allowed.

      OptionAction
      Enable users to use a single smart card certificate to authenticate to multiple user accounts.Select the Allow smart card user name hints check box.
      Disable users from using a single smart card certificate to authenticate to multiple user accounts.Deselect the Allow smart card user name hints check box.
  4. To configure smart card authentication for administrators logging in to Horizon Console, select a configuration option from the Smart card authentication for administrators drop-down menu in the Horizon Authentication section.

    OptionAction
    Not allowedSmart card authentication is disabled on the Horizon Connection Server instance.
    OptionalAdministrators can use smart card authentication or password authentication to log in to Horizon Console. If smart card authentication fails, the administrator must provide a password.
    RequiredAdministrators are required to use smart card authentication when they log in to Horizon Console.
  5. Click OK.

  6. Restart the Horizon Connection Server service.

    You must restart the Horizon Connection Server service for changes to smart card settings to take effect, with one exception. You can change smart card authentication settings between Optional and Required without having to restart the Horizon Connection Server service.

    Currently logged in user and administrators are not affected by changes to smart card settings.

What to do next

Prepare Active Directory for smart card authentication, if required. See "Prepare Active Directory for Smart Card Authentication" in the Horizon Installation and Upgrade document.

Verify your smart card authentication configuration. See Verify Your Smart Card Authentication Configuration in Horizon Console.

Previous topic:Modify Horizon Connection Server Configuration Properties

Next topic:Configure Smart Card Authentication on Third Party Solutions

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…