Skip to main content

November 18, 2025

Connecting to Remote Desktops and Published Applications

End users can connect to a server and use remote desktops and published applications. For troubleshooting purposes, end users can reset remote desktops and published applications.

To connect to a remote desktop or published application, you must provide the name of a server and supply credentials for your user account. The connection procedure is slightly different for administrators and end users, so refer to the section that applies to your role.

Note: Use the following procedures to connect to an Omnissa Horizon Connection Server. To connect to the Omnissa Horizon Cloud Service - next-gen portal, refer instead to Launch a Desktop with Omnissa Horizon Client and Launch an Application with Horizon Client.

Connect to a Remote Desktop or Published Application for End Users

The following procedure describes the steps to connect to a remote desktop or published application for end users.

Before you begin, get the following information from your administrator:

  • Instructions about whether to turn on a VPN (virtual private network) connection.
  • Fully qualified domain name (FQDN) to use for connecting to the server.
  • If the port is not 443, the port number to use for connecting to the server.
  • Credentials to log in, such as an Active Directory user name and password, RSA SecurID user name and passcode, or RADIUS authentication credentials.
  • Domain name for logging in.

If you are using smart card authentication, see Smart Card Authentication Limitations section.

  1. Log in to the Chrome device.

  2. If a VPN connection is required, turn on the VPN.

  3. Open the Horizon Client app.

  4. If you are prompted to grant access to the Smart Card Connector, click Allow.

    This prompt appears the first time you start Horizon Client if smart card authentication is configured on the device.

  5. Connect to a server.

    OptionAction
    Connect to a new serverClick the plus sign (+), enter the name of the server as instructed by your administrator, enter a description of the server (optional), and click Connect.
    Connect to an existing serverClick the server shortcut.

    Connections between Horizon Client and servers always use TLS. The default port for TLS connections is 443. If the server is not configured to use the default port, use the format shown in this example: view.company.com:1443.

  6. If a smart card is required or optional, select the smart card certificate to use and enter your PIN.

  7. If you are prompted for RSA SecurID or RADIUS authentication credentials, enter the credentials, and click Login.

    The passcode might include both a PIN and the generated number on the token.

  8. If you are prompted a second time for RSA SecurID or RADIUS authentication credentials, enter the next generated number on the token.

    Do not enter your PIN, and do not enter the same generated number that entered previously. If necessary, wait until a new number is generated. If this step is required, it is required only when you mistype the first passcode or when configuration settings in the RSA server change.

  9. If you are prompted for a user name and password, supply your Active Directory credentials.

    a. Enter your user name and password as instructed by your administrator. You must be entitled by your administrator to use at least one desktop or application pool.

    b. Select a domain as instructed by your administrator.

    If you cannot select a domain, you must enter your user name in the format `username@domain` or `domain\username`.
    

    c. Tap Login.

  10. (Optional) To mark a remote desktop or published application as a favorite, click the gray star inside the icon for the remote desktop or published application.

    The star icon turns from gray to yellow. The next time you log in, you can click the star icon in the upper-right part of the browser window to show only favorite items.

  11. To connect to a remote desktop or published application, do one of the following in the desktop and application selector window.

    OptionAction
    Connect from the desktop/application iconClick the desktop or application icon.
    Connect from the desktop/application context menuRight-click the desktop or application icon or click the [] button next to the icon, and select Connect.
  12. If you are using smart card authentication, enter the smart card PIN again inside the remote session.

If, soon after connecting to a remote desktop or published application, you are disconnected and see a prompt that asks you to click a link to accept the security certificate, select whether to trust the certificate. See Trust a Self-Signed Root Certificate section.

If the time zone in the remote desktop or published application does not use the time zone set in the client device, set the time zone manually. See Setting the Time Zone section.

Note: By default, Horizon Client displays a notification message in the session window if your network connection become unstable, as described in Detect Unstable Network Connections section.

What to do next

Horizon Client provides navigation aids to help you use remote desktops and published applications. For information, see Using Remote Desktops and Using Published Applications sections.

Connect to a Remote Desktop or Published Application for Administrators

Before you have end users access their remote desktops and applications, test that you can connect to a remote desktop or application from a client device.

First, verify that you have completed the following prerequisites:

  • Get test login credentials, such as a user name and password, RSA SecurID user name and passcode, RADIUS authentication credentials, or smart card personal identification number (PIN).
  • Get the NETBIOS domain name for logging in. For example, you might use mycompany rather than mycompany.com.
  • If you are using smart card authentication, make sure that all smart card authentication requirements are met and that you are familiar with the limitations. For information, see Smart Card Authentication Requirements and Smart Card Authentication Limitations sections.
  • If you are outside the corporate network and require a VPN connection to access remote desktops and published applications, verify that the client device is set up to use a VPN connection and turn on that connection.
  • Verify that you have the fully qualified domain name (FQDN) of the server that provides access to the remote desktop or published application. Underscores (_) are not supported in server names. If the port is not 443, you also need the port number.

Procedure

  1. Log in to the Chrome device.

  2. If a VPN connection is required, turn on the VPN.

  3. Open the Horizon Client app.

  4. If you are prompted to grant access to the Smart Card Connector, click Allow.

    This prompt appears the first time you start Horizon Client if smart card authentication is configured on the device.

  5. Connect to a server.

    OptionAction
    Connect to a new serverClick the plus sign (+), enter the name of the server, enter a description of the server (optional), and click Connect.
    Connect to an existing serverClick the server shortcut.

    Connections between Horizon Client and servers always use TLS. The default port for TLS connections is 443. If the server is not configured to use the default port, use the format shown in this example: view.company.com:1443.

  6. If a smart card is required or optional, select the smart card certificate to use and enter your PIN.

  7. If you are prompted for RSA SecurID or RADIUS authentication credentials, enter the credentials, and click Login.

    The passcode might include both a PIN and the generated number on the token.

  8. If you are prompted a second time for RSA SecurID or RADIUS authentication credentials, enter the next generated number on the token.

    Do not enter your PIN, and do not enter the same generated number that entered previously. If necessary, wait until a new number is generated. If this step is required, it is required only when you mistype the first passcode or when configuration settings in the RSA server change.

  9. If you are prompted for a user name and password, supply the appropriate Active Directory credentials.

    a. Enter the test user name and password. The user must be entitled to use at least one desktop or application pool.

    b. Select a domain.

    If you cannot select a domain, you must enter the user name in the format username@domain or domain\username.

    c. Tap Login.

  10. (Optional) To mark a remote desktop or published application as a favorite, click the gray star inside the icon for the remote desktop or published application.

    The star icon turns from gray to yellow. The next time you log in, you can click the star icon in the upper-right part of the browser window to show only favorite items.

  11. To connect to a remote desktop or published application, do one of the following in the desktop and application selector window.

    OptionAction
    Connect from the desktop/application iconClick the desktop or application icon.
    Connect from the desktop/application context menuRight-click the desktop or application icon or click the [] button next to the icon, and select Connect.
  12. If you are using smart card authentication, enter the smart card PIN again inside the remote session.

If, soon after connecting to a remote desktop or published application, you are disconnected and see a prompt that asks you to click a link to accept the security certificate, select whether to trust the certificate. See Trust a Self-Signed Root Certificate section.

If the time zone in the remote desktop or published application does not use the time zone set in the client device, set the time zone manually. See Setting the Time Zone section.

Note: By default, Horizon Client displays a notification message in the session window if your network connection become unstable, as described in Detect Unstable Network Connections section.

Use Unauthenticated Access to Connect to Published Applications

If you have an Unauthenticated Access user account, you can log in to a server anonymously and connect to your published applications. The connection procedure is slightly different for administrators and end users, so refer to the section that applies to your role.

Procedure for End Users

Before you begin, get the following information from your administrator:

  • Server name to use for connecting to the server.
  • An Unauthenticated Access user account to use for logging in anonymously.
  1. Click the Settings toolbar button in the upper-right corner of the server selection page and toggle the Log in anonymously using Unauthenticated Access option to on.

  2. Connect to a server, enter an Unauthenticated Access user account, and click Login.

    The application selection window appears.

  3. Click the icon for the published application that you want to access.

Note: By default, Horizon Client displays a notification message in the session window if your network connection becomes unstable, as described in Detect Unstable Network Connections section.

Procedure for Administrators

Verify that you have completed the following prerequisites:

  • Perform the administrative tasks described in Preparing Horizon Connection Server section.
  • Set up Unauthenticated Access users on the Horizon Connection Server instance. For information, see "Providing Unauthenticated Access for Published Applications" in the Omnissa Horizon 8 Administration document.
  1. Click the Settings toolbar button in the upper-right corner of the server selection page and toggle the Log in anonymously using Unauthenticated Access option to on.

  2. Connect to a server, enter an Unauthenticated Access user account, and click Login.

    The application selection window appears.

  3. Click the icon for the published application that you want to access.

Note: By default, Horizon Client displays a notification message in the session window if your network connection becomes unstable, as described in Detect Unstable Network Connections section.

Detect Unstable Network Connections

Horizon Client can monitor your network quality during remote desktop sessions and notify you if it detects instability caused by high latency. Latency is the delay in sending and receiving data, and Horizon Client measures it using round-trip time (RTT)—the time it takes for data to travel to the server and back.

If your RTT is too high, you might experience lag, slow screen refreshes, or even disconnections. To help with this, Horizon Client displays network quality notifications. You can configure these alerts using either group policy (on the agent side) or within the client app itself. You can also customize the thresholds that determine when Horizon Client considers a connection unstable.

Configure the Display of Network Notification Messages

The way notifications are displayed depends on the version of Horizon Agent you're using.

Horizon Agent 2406 and Later

If you're using Horizon Agent for Windows 2406 or later, you can control network notifications using the Enable Displaying Network State agent GPO setting group policy (GPO) setting.

Important behavior:

  • If the client setting (described below) has never been changed, the agent GPO controls whether notifications appear.
  • If the client setting has been modified even once, it overrides the GPO, and the client setting is used instead.

This allows administrators to enforce a default, while still giving end users control once they make a change.

Horizon Agent 2312 and Earlier

Remote desktops running Horizon Agent for Windows 2312 or earlier do not have a GPO setting for network notifications. In this case, network notifications are controlled solely by the client network display setting.

Configure the Client Network Display Setting

To toggle network notifications directly in Horizon Client:

  1. Launch the Horizon Client.
  2. From the desktop and application selector window, click the Settings icon (gear) in the upper-right corner.
  3. Toggle the option Disable network state display.

When this setting is off, Horizon Client displays a warning when the connection becomes unstable.

Customize How Horizon Client Determines the Network Quality

Horizon Client calculates a network quality score from 0 to 100%, based on the round-trip time (RTT) it detects during a specified time interval. This score helps determine whether the connection is stable or degraded.

Calculate the Network Quality Score: Horizon Client compares the RTT value to a low and high threshold, then applies the following logic:

Definitions:
rtt = detected RTT value
lowBound = low threshold value
highBound = high threshold value
score = network quality score

If rtt >= highBound, then score = 0

If rtt <= lowBound, then score = 100

If lowBound < rtt < highBound, then score = 100 - (100 * ((rtt - lowBound) / (highBound - lowBound)))

This results in a percentage where a higher score means better network quality.

Determine the Network Stability: Once the score is calculated, Horizon Client uses the following thresholds to decide whether to show a notification:

Definitions:
score = network quality score
thresholdGood = minimum score required to indicate good network stability
thresholdPoor = high limit of score range indicating poor network stability

If score >= thresholdGood, the network is considered good and no notification is displayed.

If thresholdPoor <= score < thresholdGood, the network is considered OK and no notification is displayed.

If score < thresholdPoor, the network is considered poor and a notification is displayed.

To customize the threshold values used by Horizon Client to calculate the network quality score and determine network stability, configure the networkStateConfig policy in the Google Admin settings, as described in Client Features section.

Smart Card Authentication Limitations

With smart card authentication, you plug a smart card reader into the Chrome device, insert a smart card, and select a server in Horizon Client. During the authentication step, you enter a PIN instead of a user name and password. After you select a remote desktop or published application, all smart card commands and responses are redirected to the remote desktop or published application.

Smart card authentication has certain limitations when used with Horizon Client for Chrome.

  • After using HID Global ActivID ActivClient for smart card authentication for the first time, subsequent attempts to authenticate to the server or desktop might fail. As a workaround, unplug the smart card reader from the client system and plug it in again.
  • The Horizon Connection Server and Omnissa Unified Access Gateway smart card user name hints feature is not supported.
  • The Horizon Connection Server smart card removal policy is not supported.
  • Single sign-on is not supported. When you connect to a remote desktop or published application, you must enter the smart card PIN again inside the remote session.
  • After you use a smart card to authenticate to a server, you cannot switch to another authentication method, such as Active Directory authentication. To use a different authentication method the next time you connect to a server, you must log out of the Chrome OS or reboot the Chrome device.
  • After you select a certificate and enter your PIN, the certificate you selected is cached on the Chrome device and is used the next time you connect to a server. To select a different certificate the next time you connect to a server, you must reboot the Chrome device.

Trust a Self-Signed Root Certificate

Sometimes, when connecting to a remote desktop or published application for the first time, the browser might prompt you to accept the self-signed certificate that the remote machine uses. You must trust the certificate before you can connect to the remote desktop or published application.

Chrome gives you the option to trust the self-signed certificate permanently. If you do not trust the certificate permanently, you must verify the certificate every time you restart your browser.

Procedure

  1. If the browser presents an untrusted certificate warning, or a warning appears stating that your connection is not private, examine the certificate to verify that it matches the certificate that your company uses.You might need to contact your system administrator for assistance. For example, in Chrome, you might use the following procedure.

    a. Click the lock icon in the address bar.

    b. Click the Certificate information link.

    c. Verify that the certificate matches the certificate that your company uses.You might need to contact your system administrator for assistance.

  2. Accept the security certificate.

    In Chrome, you can click the Advanced link on the browser page, and click Proceed to server-name (unsafe).

Results

The remote desktop or published application starts.

Share Location Information

When the Geolocation Redirection feature is enabled for a remote desktop or published application, you can share the client system's location information with the remote desktop or published application.

To share the location information of the local device, you must enable the geolocation settings in Horizon Client.

Prerequisites

An administrator must configure the Geolocation Redirection feature for the remote desktop or published application. This task includes enabling the Geolocation Redirection feature when you install Horizon Agent. It also includes setting group policies to configure Geolocation Redirection features, and enabling the Horizon Geolocation Redirection IE Plugin.

For complete requirements, see System Requirements for Geolocation Redirection section.

Procedure

  1. Using Horizon Client, connect to a server and click the Settings (gear) icon.

  2. Configure the geolocation settings and click Close.

    OptionDescription
    Share your locationAllow the application inside the remote session to use your location. By default, this setting is deactivated.
    Do not show geo permission dialog when connecting to a desktop or applicationDo not prompt for permission for the remote desktop or application to use the location of the device. By default, this setting is deactivated.

## Hide the Horizon Chrome Client After Launch

You can hide the Horizon Chrome Client window after you open a remote desktop or published application. The setting can be configured from the Google Admin Console.

By default, the end user can toggle this setting, but it is disabled unless set by the administrator. When configured by an administrator through the Google Admin Console, the setting becomes locked and greyed out in the client UI.

Procedure

  • When the end user launches a virtual machine (VM), the entitlement page automatically closes. If a remote application is selected first, the entitlement page remains open until the VM is launched.
  • To hide the Horizon Chrome Client window after launching a remote desktop or published application, administrators can configure this behavior in the Google Admin Console.
  • To show the entitlement page again, users can select Open Entitlement Page from the menu dropdown. (If the entitlement page is open, this option is removed from the menu.)
  • When the user closes the VM, a "no windows" timeout is applied.

## Setting the Time Zone

The time zone that a remote desktop or published application uses is set to the time zone in your local system automatically.

When you use Horizon Web Client, if the time zone cannot be correctly determined due to certain daylight saving policies, you might need to set the time zone manually.

To set the correct time zone manually before you are connected to a remote desktop or published application, click the Settings toolbar button in the upper-right corner of the desktop and application selector window. Turn off the Set Time Zone Automatically option in the Settings window and select one of the time zones from the drop-down menu. The value you select is saved as your preferred time zone to use when connecting to a remote desktop or published application.

To set the correct time zone manually after you are connected to a remote desktop or published application, return to the desktop and application selector window and change the current time zone setting.

Manage Server Shortcuts

After you connect to a server, Horizon Client creates a server shortcut. You can edit and remove server shortcuts.

Horizon Client saves the server name or IP address in a shortcut, even if you mistype the server name or type the wrong IP address. You can delete or change this information by editing the server name or IP address. If you do not type a server description, the server name or IP address becomes the server description.

Procedure

  1. Right-click the server shortcut.

    A context menu appears.

  2. Use the context menu to delete the server shortcut or edit the server name or server description.

  3. If you edited the server shortcut, click Complete to save your changes.

Log Out or Disconnect

If you disconnect from a remote desktop without logging out, applications in the remote desktop might remain open. You can also disconnect from a server and leave published applications running.

Procedure

  • Disconnect from a remote desktop.

    OptionDescription
    From within the remote desktopPoint your mouse at the top of the remote desktop window until the menu bar appears and then click the Disconnect button. Alternatively, click the X (Close) button in the upper-right corner of the remote desktop window.
    From the Session Management CenterClick the Settings toolbar button in the upper-right corner of the desktop and application selector window, open the Session Management Center, select the remote desktop session, and click Disconnect. You can also open the Session Management Center by right-clicking the remote desktop icon in the shelf and clicking Session Management Center.
  • Log out from a remote desktop.

    OptionDescription
    From within the remote desktopPoint your mouse at the top of the remote desktop window until the menu bar appears and then click the Log out button.
    From the Session Management CenterClick the Settings toolbar button in the upper-right corner of the desktop and application selector window, open the Session Management Center, select the remote desktop session, and click Log off. You can also open the Session Management Center by right-clicking the remote desktop icon in the shelf and clicking Session Management Center.
  • Close a published application.

    OptionDescription
    From within the published applicationClick the X (Close) button in the corner of the published application window.
    From the shelfRight-click the published application icon in the shelf and click Close.
  • To log out from a server, click the Log Out button in the upper-right corner of the desktop and application selector window.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…