Skip to main content

July 21, 2025

Understanding Permissions and Access Groups

Horizon Console presents the combination of a role, an administrator user or group, and an access group as a permission. The role defines the actions that can be performed, the user or group indicates who can perform the action, and the access group contains the objects that are the target of the action.

Permissions appear differently in Horizon Console depending on whether you select an administrator user or group, an access group, or a role.

The following table shows how permissions appear in Horizon Console when you select an administrator user or group. The administrator user is called Admin 1 and it has two permissions.

Table 1: Permissions on the Administrators and Groups Tab for Admin 1

RoleAccess Group
Inventory AdministratorsMarketingDesktops
Administrators (Read only)/

The first permission shows that Admin 1 has the Inventory Administrators role on the access group called MarketingDesktops. The second permission shows that Admin 1 has the Administrators (Read only) role on the root access group.

The following table shows how the same permissions appear in Horizon Console when you select the MarketingDesktops access group.

Table 2: Permissions on the Access Groups Tab for MarketingDesktops

AdminRoleInherited
horizon-domain.com\Admin1Inventory Administrators 
horizon-domain.com\Admin1Administrators (Read only)Yes

The first permission is the same as the first permission shown in Table 1. The second permission is inherited from the second permission shown in Table 1. Because access groups inherit permissions from the root access group, Admin1 has the Administrators (Read only) role on the MarketingDesktops access group. When a permission is inherited, a check mark appears in the Inherited column.

The following table shows how the first permission in Table 1 appears in Horizon Console when you select the Inventory Administrators role.

Table 3: Permissions on the Role Permissions Tab for Inventory Administrators

AdministratorAccess Group
horizon-domain.com\Admin1/MarketingDesktops

For information about permissions and federation access groups, see the Cloud Pod Architecture in Horizon 8 document.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…