Skip to main content

August 24, 2026

Object-Specific Privileges

Object-specific privileges control operations on specific types of inventory objects. Roles that contain object-specific privileges can be applied to access groups. In a Cloud Pod Architecture environment, roles that contain certain object-specific privileges are applicable to federation access groups.

The following table describes the object-specific privileges. The predefined roles Administrators, Local Administrators, Help Desk Administrators, and Inventory Administrators contain these privileges.

Object-Specific Privileges

PrivilegePrivilege SetUser CapabilitiesObject
Enable Farms and Desktop Pools MACHINE_VIEW POOL_ENABLE POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEEnable and disable desktop pools.Desktop pool, application pool, farm
Entitle Desktop and Application Pools MACHINE_VIEW POOL_ENTITLE POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEAdd and remove user entitlements.Desktop pool, application pool
Manage Cloud Pod Architecture FEDERATED_LDAP_VIEW FEDERATED_LDAP_MANAGE MACHINE_VIEW POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEConfigure and manage a Cloud Pod Architecture environment, including global entitlements, sites, home sites, and pods. To manage a Cloud Pod Architecture configuration, an administrator must have this privilege on the root federation access group.Desktop pool, application pool, farm, machine, global entitlements
Manage Global Sessions FEDERATED_SESSIONS_MANAGE FEDERATED_SESSIONS_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEManage global sessions in a Cloud Pod Architecture environment.Global sessions
Manage Maintenance Operations on Automated Desktops and Farms MACHINE_VIEW POOL_SVI_IMAGE_MANAGEMENT POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVESchedule push image, schedule maintenance, and change the default image for a desktop pool and farm.Desktop pool, farm
Manage Machine MACHINE_MANAGE_OFFLINE_SESSION MACHINE_MANAGE_VDI_SESSION MACHINE_MANAGEMENT MACHINE_REBOOT MACHINE_VIEW MANAGE_REMOTE_PROCESS POOL_VIEW REMOTE_ASSISTANCE GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEPerform all machine and session-related operations.Machine
Manage Machine Alias and User Assignment GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE MACHINE_USER_MANAGEMENT MACHINE_VIEW POOL_VIEWAssign and unassign users for machines and update machine aliases.Machine
Manage Machine Maintenance GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE MACHINE_MAINTENANCE MACHINE_VIEW POOL_VIEWPut machines into maintenance mode and take machines out of maintenance mode.Machine
Manage Farms and Desktop and Application Pools MACHINE_VIEW POOL_ENABLE POOL_ENTITLE POOL_MANAGEMENT POOL_SVI_IMAGE_MANAGEMENT POOL_VIEW VC_CONFIG_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEAdd, modify, and delete farms. Add, modify, delete, and entitle desktop and application pools. Add and remove machines.Desktop pool, application pool, farm
Manage Sessions MACHINE_MANAGE_VDI_SESSION MACHINE_VIEW POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEDisconnect and log off sessions and send messages to users.Session
Manage Reboot Operation MACHINE_REBOOT MACHINE_VIEW POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEReset virtual machines or restart virtual desktops.Machine
Manage Help Desk (Read only) FEDERATED_LDAP_VIEW FEDERATED_SESSIONS_VIEW FOLDER_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE GLOBAL_CONFIG_VIEW HELPDESK_ADMINISTRATOR_VIEW MACHINE_VIEW POOL_VIEWRead-only access to the Horizon Help Desk Tool, global settings, and global policies, except for administrators and roles and Cloud Pod Architecture configurations.Desktop pool, application pool, farm, machine, session, global entitlements, global sessions
Manage Remote Processes and Applications MACHINE_VIEW MANAGE_REMOTE_PROCESS POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVEManage remote processes and applications on remote desktop.Machine
Remote Assistance MACHINE_VIEW POOL_VIEW REMOTE_ASSISTANCE GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVERemote assistance to remote desktop.Machine

Using Object‑Specific Privileges When Creating Custom Roles

Object‑specific privileges define what actions an administrator can perform on Horizon inventory objects such as desktop pools, application pools, farms, machines, and sessions. When creating a custom role, these privilege sets determine the exact capabilities a user will have. Roles can be tailored by selecting only the specific privilege combinations needed for a particular administrative function.

The privilege sets listed in the table above can be combined to construct custom roles that support narrowly defined responsibilities. For example, you may need to allow Help Desk personnel to entitle users to pools while preventing them from performing broader machine or pool management operations. Creating such a limited‑scope role relies on selecting only the appropriate object‑specific privilege set.

Creating a Custom Role for Entitlement‑Only Access

A common use case is granting Help Desk staff the ability to add or remove user entitlements without allowing them to restart machines, manage sessions, modify pools, or perform maintenance operations. This can be accomplished by selecting only the privileges included in the “Entitle Desktop and Application Pools” privilege set.

Privileges Required for Entitlement‑Only Access

Select only the following privileges from the object‑specific privileges table:

  • POOL_ENTITLE
  • POOL_VIEW
  • MACHINE_VIEW
  • GLOBAL_ADMIN_UI_INTERACTIVE
  • GLOBAL_ADMIN_SDK_INTERACTIVE

These permissions allow users to view pools and machines as needed and add or remove user entitlements, but do not grant authority to modify pools, manage machines, or perform administrative tasks.

Capabilities Granted

With this role assigned, users can:

  • View desktop pools, application pools, and machines
  • Add user entitlements
  • Remove user entitlements

Capabilities Not Granted

Because no other privilege sets are included, the user cannot:

  • Restart, reset, or manage machines
  • Disconnect, log off, or send messages to sessions
  • Use remote assistance
  • Enable or disable pools
  • Modify, create, or delete pools
  • Perform image updates or schedule maintenance
  • Add or remove machines
  • Manage Cloud Pod Architecture or global entitlements

Steps for Creating the Entitlement‑Only Custom Role

  1. In Horizon Console, go to Settings > Administrators > Roles > Add Role.
  2. Name the role, for example: “Help Desk – Entitlements Only.”
  3. Under Object‑Specific Privileges, select:
    • POOL_ENTITLE
    • POOL_VIEW
    • MACHINE_VIEW
  4. Under Global Interaction Privileges, select:
    • GLOBAL_ADMIN_UI_INTERACTIVE
    • GLOBAL_ADMIN_SDK_INTERACTIVE
  5. Do not select privileges related to:
    • Machine management
    • Pool or farm management
    • Session management
    • Maintenance operations
    • Remote assistance
    • Cloud Pod Architecture
  6. Save the role and assign it to the appropriate AD group under Settings > Administrators.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…