Skip to main content

November 3, 2025

Enabling Horizon Cloud Entitlement On-Ramp to Access Horizon 8 and Horizon Cloud on Azure Desktops

The Horizon Cloud Entitlement On-Ramp global setting allows users to access both Horizon 8 and Horizon Cloud on Azure desktops with their credentials from a single Horizon Client for Windows, eliminating the need for multiple URLs, logout, or additional authentication to the cloud.

Prerequisites

  • Verify that you have registered a supported identity provider (IDP) -- Microsoft Entra ID or Omnissa Access (on-premises/cloud) -- in your Horizon Cloud Service - next-gen tenant. The registered identity provider facilitates the synchronization of on-premises Active Directory user identities to that identity provider.
  • Verify that you are running Horizon Connection Server version 2312 or later.
  • Verify that you have deployed the Horizon 8 Edge to connect your Horizon 8 pod to the Horizon Cloud Service - next-gen Control Plane.
  • In the Horizon Universal Console, with Microsoft Azure as your capacity provider, create a pool, deploy desktop instances, and assign entitlements.
  • In Horizon Console, create Horizon 8 pools and assign entitlements for local or Cloud Pod Architecture.
  • Verify that your end users are running Horizon Client for Windows 2312 or later.

How Horizon Cloud Entitlement On-Ramp Works

The Horizon Cloud Entitlement On-Ramp feature uses Connection Server as a brokering mechanism to grant users access to entitled Horizon Cloud on Azure desktops. You can use either Microsoft Entra ID or Workspace ONE Access (on-premises/cloud) as the identity provider (IDP) for your Horizon Cloud Service - next-gen tenant.

Your chosen identity provider facilitates the synchronization of user accounts, group memberships, and other directory objects from on-premises Active Directory to the cloud-based identity provider. This synchronization ensures that users experience consistent authentication, whether they are accessing on-premises or cloud-based resources.

If you use Workspace ONE Access as your identity provider, a connector is deployed to synchronize user accounts and group memberships with the Workspace ONE Access platform.

When a user connects to a Connection Server instance, Connection Server validates that user's entitlements to any Horizon Cloud on Azure desktops. Horizon Client then displays these desktops alongside Horizon 8 desktops in the same desktop and application selector window. In this way, users can access their Horizon Cloud on Azure entitlements directly through the Connection Server or Unified Access Gateway FQDN. A separate URL for the Horizon Cloud Service - next-gen portal is no longer required.

Each Horizon 8 entitlement shown in the selector window may be either a local entitlement or global entitlement. Horizon 8 entitlements and Horizon Cloud on Azure entitlements appear as individual desktops in the selector window and the user must select which desktop to connect to. At this time, Horizon Cloud Entitlement On-Ramp does not support the capability to define a connection policy between Horizon 8 and Horizon Cloud on Azure entitlements.

Important: Take note of the following feature limitations:

  • Currently, only Horizon Client for Windows 2312 or later is supported for this feature. Support will be available for other Horizon clients in the future.
  • If you configure client restriction messages from both Horizon Console and Horizon Universal Console, these messages do not appear simultaneously on the client. Instead, the first message appears momentarily before being replaced with the second message.

Horizon Cloud Entitlement On-Ramp can be enabled at the Horizon 8 pod level and at the user level. By default, it is deactivated for all users. This feature must be activated by an administrator, as described in the next sections on this page.

Activate Horizon Cloud Entitlement On-Ramp in the Horizon Cloud Control Plane

Use the Horizon Universal Console to perform the first part of the feature activation process.

  1. Log in to the Horizon Universal Console.

  2. On the Home page, click Horizon Edges on the Horizon Edges tile.

  3. In the Horizon Edges tab on the Capacity page, click on the name of a Horizon Edge with a Provider Type of Horizon 8 to its Horizon Edge details page.

  4. In the Cloud Entitlement On-Ramp tile, click Enable.

    The Horizon Universal Console pushes the configuration to the Horizon Edge Gateway for a Horizon 8 deployment, where it in turn pushes the configuration to the Horizon Connection Server and activates the Horizon Cloud Entitlement On-Ramp feature in Horizon Console.

  5. Proceed to the next section on this page to add user entitlements in Horizon Console.

Add Horizon Cloud Entitlement On-Ramp Entitlements in Horizon Console

After activating the Horizon Cloud Entitlement On-Ramp feature in the Horizon Cloud Control Plane, you must configure Cloud Entitlement On-Ramp entitlements in Horizon Console for applicable users and groups.

  1. Log in to the Horizon Console.

  2. In Global Settings, verify that the setting Cloud Entitlement On-Ramp is enabled.

    Note: If the setting does not appear enabled, check the network connectivity between the Horizon Edge Gateway, the Horizon Universal Console, and Horizon Connection Server.

  3. Navigate to Users and Groups > Cloud Entitlement On-Ramp and click Add.

  4. Add the users and groups that need access to Horizon Cloud on Azure desktops.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…