Skip to main content

August 24, 2026

Using Per-Pod SAML Configuration

Horizon supports defining SAML authentication settings at the pod level, allowing you to apply a single SAML configuration to all Connection Servers within the same pod. This capability simplifies administration in multi-server or multi-pod environments and provides more detailed control of authentication behavior.

By default, SAML authentication settings were previously configured on each Connection Server. In larger environments, this required repeated configuration and increased the risk of inconsistent settings across servers. With pod-level configuration, you can assign a SAML configuration directly to a Horizon Pod. All Connection Servers that belong to that pod inherit the configuration.

This feature allows individual pods use different identity providers, metadata sources, authentication contexts, or certificate settings. This helps with different or region-specific authentication requirements.

Behavior and Compatibility

  • When you enable a pod-level SAML configuration, the settings apply uniformly to every Connection Server in that pod.

  • Pod-level configurations do not affect other pods in the environment; each pod can be configured independently.

  • Existing environments that use per-Connection-Server SAML settings continue to operate normally. Per-server configuration remains supported for compatibility.

Note: When using pod-level SAML configuration, all Connection Servers within the pod must use the same SAML encryption certificate (vdm.enc). Certificate management, including uploading a custom encryption certificate, is performed using the standard Horizon certificate management features.

When to Use Pod-Level SAML Configuration

Use pod-level configuration when you want to:

  • Ensure consistent SAML settings across all servers in a pod.

  • Reduce repetitive configuration steps on each Connection Server.

  • Support different SAML identity providers or authentication requirements across multiple pods.

  • Simplify onboarding of new or replaced Connection Servers, which will inherit the pod’s SAML configuration.

Transitioning from Per-Server to Pod-Level Configuration

Administrators can optionally migrate existing SAML settings from individual Connection Servers into a pod-level configuration.
If no pod-level configuration is defined, Horizon continues to rely on per-server SAML settings to maintain compatibility with existing deployments.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…