Object-specific privileges control operations on specific types of inventory objects. Roles that contain object-specific privileges can be applied to access groups. In a Cloud Pod Architecture environment, roles that contain certain object-specific privileges are applicable to federation access groups.
The following table describes the object-specific privileges. The predefined roles Administrators, Local Administrators, Help Desk Administrators, and Inventory Administrators contain these privileges.
Object-Specific Privileges
| Privilege | Privilege Set | User Capabilities | Object |
|---|---|---|---|
| Enable Farms and Desktop Pools | MACHINE_VIEW POOL_ENABLE POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Enable and disable desktop pools. | Desktop pool, application pool, farm |
| Entitle Desktop and Application Pools | MACHINE_VIEW POOL_ENTITLE POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Add and remove user entitlements. | Desktop pool, application pool |
| Manage Cloud Pod Architecture | FEDERATED_LDAP_VIEW FEDERATED_LDAP_MANAGE MACHINE_VIEW POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Configure and manage a Cloud Pod Architecture environment, including global entitlements, sites, home sites, and pods. To manage a Cloud Pod Architecture configuration, an administrator must have this privilege on the root federation access group. | Desktop pool, application pool, farm, machine, global entitlements |
| Manage Global Sessions | FEDERATED_SESSIONS_MANAGE FEDERATED_SESSIONS_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Manage global sessions in a Cloud Pod Architecture environment. | Global sessions |
| Manage Maintenance Operations on Automated Desktops and Farms | MACHINE_VIEW POOL_SVI_IMAGE_MANAGEMENT POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Schedule push image, schedule maintenance, and change the default image for a desktop pool and farm. | Desktop pool, farm |
| Manage Machine | MACHINE_MANAGE_OFFLINE_SESSION MACHINE_MANAGE_VDI_SESSION MACHINE_MANAGEMENT MACHINE_REBOOT MACHINE_VIEW MANAGE_REMOTE_PROCESS POOL_VIEW REMOTE_ASSISTANCE GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Perform all machine and session-related operations. | Machine |
| Manage Machine Alias and User Assignment | GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE MACHINE_USER_MANAGEMENT MACHINE_VIEW POOL_VIEW | Assign and unassign users for machines and update machine aliases. | Machine |
| Manage Machine Maintenance | GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE MACHINE_MAINTENANCE MACHINE_VIEW POOL_VIEW | Put machines into maintenance mode and take machines out of maintenance mode. | Machine |
| Manage Farms and Desktop and Application Pools | MACHINE_VIEW POOL_ENABLE POOL_ENTITLE POOL_MANAGEMENT POOL_SVI_IMAGE_MANAGEMENT POOL_VIEW VC_CONFIG_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Add, modify, and delete farms. Add, modify, delete, and entitle desktop and application pools. Add and remove machines. | Desktop pool, application pool, farm |
| Manage Sessions | MACHINE_MANAGE_VDI_SESSION MACHINE_VIEW POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Disconnect and log off sessions and send messages to users. | Session |
| Manage Reboot Operation | MACHINE_REBOOT MACHINE_VIEW POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Reset virtual machines or restart virtual desktops. | Machine |
| Manage Help Desk (Read only) | FEDERATED_LDAP_VIEW FEDERATED_SESSIONS_VIEW FOLDER_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE GLOBAL_CONFIG_VIEW HELPDESK_ADMINISTRATOR_VIEW MACHINE_VIEW POOL_VIEW | Read-only access to the Horizon Help Desk Tool, global settings, and global policies, except for administrators and roles and Cloud Pod Architecture configurations. | Desktop pool, application pool, farm, machine, session, global entitlements, global sessions |
| Manage Remote Processes and Applications | MACHINE_VIEW MANAGE_REMOTE_PROCESS POOL_VIEW GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Manage remote processes and applications on remote desktop. | Machine |
| Remote Assistance | MACHINE_VIEW POOL_VIEW REMOTE_ASSISTANCE GLOBAL_ADMIN_SDK_INTERACTIVE GLOBAL_ADMIN_UI_INTERACTIVE | Remote assistance to remote desktop. | Machine |
Using Object‑Specific Privileges When Creating Custom Roles
Object‑specific privileges define what actions an administrator can perform on Horizon inventory objects such as desktop pools, application pools, farms, machines, and sessions. When creating a custom role, these privilege sets determine the exact capabilities a user will have. Roles can be tailored by selecting only the specific privilege combinations needed for a particular administrative function.
The privilege sets listed in the table above can be combined to construct custom roles that support narrowly defined responsibilities. For example, you may need to allow Help Desk personnel to entitle users to pools while preventing them from performing broader machine or pool management operations. Creating such a limited‑scope role relies on selecting only the appropriate object‑specific privilege set.
Creating a Custom Role for Entitlement‑Only Access
A common use case is granting Help Desk staff the ability to add or remove user entitlements without allowing them to restart machines, manage sessions, modify pools, or perform maintenance operations. This can be accomplished by selecting only the privileges included in the “Entitle Desktop and Application Pools” privilege set.
Privileges Required for Entitlement‑Only Access
Select only the following privileges from the object‑specific privileges table:
POOL_ENTITLEPOOL_VIEWMACHINE_VIEWGLOBAL_ADMIN_UI_INTERACTIVEGLOBAL_ADMIN_SDK_INTERACTIVE
These permissions allow users to view pools and machines as needed and add or remove user entitlements, but do not grant authority to modify pools, manage machines, or perform administrative tasks.
Capabilities Granted
With this role assigned, users can:
- View desktop pools, application pools, and machines
- Add user entitlements
- Remove user entitlements
Capabilities Not Granted
Because no other privilege sets are included, the user cannot:
- Restart, reset, or manage machines
- Disconnect, log off, or send messages to sessions
- Use remote assistance
- Enable or disable pools
- Modify, create, or delete pools
- Perform image updates or schedule maintenance
- Add or remove machines
- Manage Cloud Pod Architecture or global entitlements
Steps for Creating the Entitlement‑Only Custom Role
- In Horizon Console, go to Settings > Administrators > Roles > Add Role.
- Name the role, for example: “Help Desk – Entitlements Only.”
- Under Object‑Specific Privileges, select:
POOL_ENTITLEPOOL_VIEWMACHINE_VIEW
- Under Global Interaction Privileges, select:
GLOBAL_ADMIN_UI_INTERACTIVEGLOBAL_ADMIN_SDK_INTERACTIVE
- Do not select privileges related to:
- Machine management
- Pool or farm management
- Session management
- Maintenance operations
- Remote assistance
- Cloud Pod Architecture
- Save the role and assign it to the appropriate AD group under Settings > Administrators.
Was this page helpful?