Skip to main content

Create a Pool

After you have at least one image in the Horizon Universal Console, you can create a pool based on that image.

Prerequisites

Before creating a pool, ensure that the following requirements are in place:

  • End-user identity provider: Verify that you have configured an identity provider to use for end-user identity. If using Microsoft Entra ID as the identity provider for user identity, verify that Microsoft Entra ID Connect configuration is complete. For related information, refer to: Identity and Access Management.

  • Machine identity provider: Verify that you have the configuration in place for a machine identity provider. This provider establishes the machine identity of the virtual machines that provide remote desktops and applications. When you are using Microsoft Entra ID for user identity, you can also use it for machine identity or instead use your Active Directory domain for machine identity.

    Note: When using Microsoft Entra ID for machine identity, be mindful that when deleting a Microsoft Entra ID joined pool or VM, the pool's specified provider requires specific permissions to delete the device entry from Microsoft Entra ID when the pool or VM is deleted.

  • Required permissions are:

    • Scope: Microsoft Graph (https://graph.microsoft.com)
    • Permission: Device.ReadWrite.All Read and Write devices
    • Admin Consent Required: Yes
  • To use the Microsoft Azure portal to add the application permissions to the provider's service principal, navigate to App Registrations, select the service principal's app registration, and use the Azure Portal's API permissions to add Microsoft Graph application permission Device.ReadWrite.All.

  • If using your Active Directory domain for machine identity, ensure that you have configured the Active Directory domain. For more information refer to: Setting up Your Active Directory Domain.

  • When using Workspace ONE Access for end-user identity, you must configure an Active Directory domain to use for the machine identity.

  • Ensure the Horizon Edge is created successfully and the Horizon Edge Gateway and UAG deployments are displaying healthy (green) states in the Horizon Universal Console at Capacity > Horizon Edges.

  • Ensure that the VDI or multi-session image which you will use in this pool is published successfully. You can check the image state in the Horizon Universal Console at Images.

Microsoft Azure Dedicated Host Prerequisites

Before attempting to create a Microsoft Azure pool, you must complete the following steps in Azure to use the Azure dedicated host feature.

  • Create a Host Group, select the Availability Zone if required (which can only be managed through Azure) and enable the Automatic placement option.

  • Create/add one or more Hosts to the Host Group.

After these steps are completed, you can enable the toggle Use Azure dedicated hosts when creating a pool. Once activated, a list of available associated Host Groups is visible. For more information refer to: Azure Dedicated Hosts.

Support for Microsoft Azure Entra ID (Azure AD) Hybrid Joined Desktops

For your Horizon Cloud managed desktops, you have a few choices for how machines are identified:

  • You can use Active Directory Domain Services (which is typically on-premises).
  • You can use Entra ID (also known as Azure AD, which is cloud-based).
  • You can also use Entra ID hybrid-join. This option lets your desktops connect to both your on-premises Active Directory and cloud-based Entra ID resources.

When you're setting up or changing a desktop pool, you will see an option to Defer VM availability until hybrid join. This toggle is located in the Machine Identity (Domain) section of the user interface and is used when you are working with an on-premises Active Directory server.

Important Note: If you enable both "Reuse VM ID" and "hybrid-join" for the same desktop template, there's a potential issue. When floating pool virtual machines (VMs) are recreated, they will reuse their existing computer account in Active Directory. However, the corresponding device entry in Azure Entra ID might not update correctly, which could lead to problems with those recreated VMs.

Procedure

  1. From the Horizon Universal Console, select Pools in the left menu.

  2. Click Add and then select your preferred provider type.

  3. Enter a unique Pool name and add a Description.

  4. Select a Pool type.

    • Dedicated single-session for the persistent VDI desktop experience where each desktop is mapped to a single user.
    • Floating single-session for the non-persistent VDI desktop experience where multiple users can use the desktop at different times and the desktop resets after each user session.
    • Multi-session for session-based published desktops and applications.
  5. Under the Desktops section, you will see many sub-sections. Under the Destination sub-setion, select your options to complete the Site, Horizon Edge, and Provider drop downs.

    • For a Microsoft Azure Pool, if you have dedicated host groups configured, enable the toggle to Use dedicated host. Then select the Host Group.

    • If you are using a dedicated host the option to enable Use availability zones will be disabled as they are configured directly by the cloud provider.

    • When you enable Use Azure Availability Zones, the VMs for a pool are distributed across all the availability zones to prevent downtime of all of the VMs in the pool if a failure occurs in a given availability zone. Note: Amazon availability zones are specified in the Networks section below. For more information, refer to: Azure services that support availability zones.

    • Enable Hibernate toggle to active for Microsoft Azure and/or Amazon WorkSpaces Core Dedicated Single-Session Pools.

    • Important: Once the pool is enabled for hibernation, you will not be able to remove that ability from VMs as well. Refer to: Hibernate Pools and Virtual Machines for more information.

  6. In the Image sub-section, set the Generation type and then select the Image from the drop down.

    For a Microsoft Azure Pool, both generation 1 and 2 image VMs are supported. If you select V1, only images with a Microsoft Azure generation 1 VM and models that support generation 1 can be selected. Your selection for the Generation type acts as a filter to determine which images are listed in the Image and Model drop-down menus.

  7. Select the Marker of the image selected.

    For a Microsoft Azure Pool, you must use one or more markers or tags to later edit the pools of an image version. For more information refer to: Add Version to an Existing Microsoft Azure Compute Gallery Image, also: Using Azure Resource Tags and Using Amazon Resource Tags.

    Note: If a marker associated with an older agent version is selected, a warning message is displayed. As a best practice, select a marker with the latest agent version.

  8. Select the check box next to Do you have a valid license for this Windows OS and select the next check box to confirm you have an eligible license for this Windows OS.

  9. In the VM details sub-section, specify the VM details information. Content differs depending on your selected provider type. Some options, such as hibernate, depend on your selected pool type.

    For Amazon WorkSpaces Core Pools specify the following options:

    • Hardware

    • Show only hibernate enabled hardware toggle

    • Power management (Always On) toggle

    • User Volume in GBs

    • User Volume Encryptions Disks toggle

    • Root Volume in GBs

    • Root Volume Encryption Disks toggle

    • Enabling the Always On power management mode ensures that all VMs in the desktop pool remain powered on continuously. A fixed monthly fee is applied to each VM upon provisioning and is charged at the beginning of each month. This option is recommended for pools with VMs that are used for over 80 hours per month, as it can result in cost savings during periods of high usage.

    • Disabling the Always On power management mode activates Horizon Power Management, allowing power management policies and schedules configured in the pool group to take effect. The fixed monthly fee will still apply for the current month, but starting from the first day of the following month, VMs will be billed at an hourly rate.

    For Microsoft Azure Pools

    • Select a Microsoft Azure VM Model type to use for the pool, or accept the default. The Model setting refers to the compatibility of different Microsoft Azure VM types and sizes with Horizon Cloud. To select a different model, click the X, then click the drop-down menu, and select a model. Refer to: Microsoft Azure VM Types and Sizes for Horizon Cloud (89090) for more information.

    • If you are using the Azure dedicated host option, VM models will be filtered based on the models available to the selected Azure Host Group.

    • Use the Filter Model settings to reduce the number of Microsoft Azure VM model options listed when you configure the Model setting, if not the list of models is very long. You can filter the Microsoft Azure VM model list by Tag, CPU, RAM, Series, GPU Type, and Disk Type. Click + to add other filters. The reduced list includes a subset of models based on your specific requirements.

      FilterOperatorDescription
      Tagequals- Recommended: Microsoft Azure VM models that work particularly well for pools.
      - High Performance: Azure VM models that offer premium disk support.
      - Custom: Custom tags that can be added and configured by the administrator.
      CPUequalsThe CPU filter uses a from/to range to define acceptable CPU values.
      RAMequalsMemory uses a from/to range to define acceptable RAM values.
      Disk TypeequalsUse the Disk Type filter to select Premium, which provides premium disk support.
    • You can change the Disk size value from 127 to 4095 GB. The default Disk size value is 127. When you create or edit a pool you have the option of increasing the OS disk size value. When that option is used, the OS disk of each VM in that pool is created with that size. However, as a result of default behavior of VMs in Microsoft Azure, even though the VM’s disk is expanded, the partition containing the C drive is not expanded to encompass the entire disk. That new space on the VM’s disk is unused until you take actions in the VM to expand the C drive partition to encompass the new space.

    • If you want to encrypt disks for all VMs in this pool, enable the Encrypt Disks toggle option.

    • With the Auto Scale toggle enabled, an administrator can select both the running and stopped disk type. When the VMs are powered off, the disk types are set and auto-converted. Once powered back on, the disk type returns to its original settings. The Auto Scale toggle can be activated in two places. It can be toggled in the Create a Pool page and/or on the global Settings > Pool Settings page available from the left pane Horizon Universal Console UI. To set a global policy, use the global Settings > Pool Settings page. However, if only specific desktop pools need this feature, use the option on the Create a Pool page to activate or deactivate the option when creating a pool. The toggle specified on the Create a Pool page takes precedence over the Settings > Pool Settings page.

    Note: Changing the model used by an existing pool will only effect new VMs. Existing VMs in the pool will continue to use the previously selected model.

    An administrator can label a model as hidden if they do not want the model to be available for new pools however, a hidden model can continue to be used by an existing pool. A model will be marked deprecated if Microsoft Azure no longer provides the model. When editing a pool, if the currently selected model is marked as deprecated, update the model to a different one to allow the pool to create more virtual machines in the future, e.g. when expanding the pool.

  10. In the Machine Identity (Domain) sub-section, select a Machine Identity provider to use for this pool.

    • The Defer VM availability until hybrid join option is available for Microsoft Azure if the specified Machine Identity provider is an on-premises Active Directory server. Enabling this option allows the pool to access both on-premises and cloud-based resources. Refer to the onscreen help for the prerequisites that are required for using this option.

    • The Active Directory domain is configured in your Horizon Cloud environment for the purpose of providing machine identity. With this selection, you can replace the default CN=Computers organization unit (OU) with a specific Computer OU into which the pool's machines will be created in that Active Directory domain. By default, the pool's machines are created in CN=Computers.

    • When you select Microsoft Entra ID, the Computer OU field is deactivated because the system doesn't use computer OUs in this case.

      When using Microsoft Entra ID for the pool's machine identity, you must configure RBAC in Microsoft Entra ID so that only the users or user groups that have Virtual Machine Administrator Login or Virtual Machine User Login role can log into their entitlements.

    • When you configure RBAC at the resource group level, to help identify the resource groups associated with the Microsoft Entra ID joined pools, the following tags are used on the pools' resource groups:

      • pool-name: indicates the pool name entered when creating the pool
      • add-joined: if set with true, it indicates the VMs from the pool are Microsoft Entra ID joined machines
  11. If using the Amazon WorkSpaces Core provider type, in the Machine Identity (Domain) section, specify a Directory ID. This will be directory created in the Amazon Web Services (AWS) Console.

    • During pool creation, Omnissa automatically generates and configures a Network Security Group (NSG) that is attached to your WorkSpaces directory. This preconfigured NSG implements security controls optimized for all workspaces registered under this directory. The automatically provisioned NSG is specifically designed for WorkSpaces environments and ensures proper connectivity and security.

    • Avoid custom security groups. Attaching custom security groups to WorkSpaces directories can lead to connectivity issues and unpredictable behavior. Configure your network to allow all inbound traffic from your VPC to Active Directory rather than creating AD rules (inbound/outbound) based on security groups used in the WorkSpaces directory. These recommendations help prevent connection failures, streamline troubleshooting, and maintain consistent security across your environment.

    • If you choose to implement a custom security group despite these recommendations, ensure it includes all required inbound and outbound rules for desktop connectivity. For assistance with custom configurations, please contact our support team at: Omnissa Customer Connect.

    • For Windows Server images, the workspace directory tenancy must be set as SHARED.

    • For Windows 10/11 images, the workspace directory tenancy must be set as DEDICATED. This requirement also applies to dedicated pools.

    • Administrative Unit (AUs) can also be selected to have the device ids of the Entra ID-joined pool VMs as members of the selected AU and to restrict permissions scope. This feature is optional and can be selected when creating a Microsoft Entra ID-joined pool. However once the pool is created, the AU field’s value cannot be changed when the pool is reusing VM names.

    Note: All Windows 11 and Windows 10 devices are supported, except Home editions Windows Server 2019 and newer Virtual Machines running in Azure (Server core is not supported).

  12. In the Provisioning sub-section, configure as needed.

    • Select how VMs are provisioned in the Provision VMs section between On demand and All at once.
    • Enter the number of Maximum VMs that can be provisioned for this pool.
    • If the On demand option is selected, specify the number of Minimum spare VMs and Maximum spare VMs.

    Note: Spare VMs are VMs not currently in use that are powered on ready for new user sessions. The system will try to maintain the spare VMs equal to (Minimum spare VMs + Maximum spare VMs) / 2. Provision and deprovision operations are triggered based on the difference between the existing spare VMs and this number.

  13. In the Properties sub-section, configure as needed.

    • VM name prefix - Enter a prefix to use for the pool's VMs.
    • Reuse VM names - This option specifies to reuse VM names after the VMs have been deleted.
    • Time zone - Select the time zone that the VMs should use. If the clock should automatically be adjusted for daylight saving time, select the check box. Note that the time zone setting is not available for multi-session pools. Note that the Time zone option is not present for the Amazon WorkSpaces Core provider type.
    • Desktop admin username and Desktop admin password - Enter the credentials for the local admin account used to access the image's operating system, and to use during the image conversion process. You can edit the admin credentials from pools when adding additional VMs, this means that any new VMs added will have different admin credentials than the original ones had. Note: for Amazon WorkSpaces Core, these credential fields are not currently used in any pool operations.
    • Use outbound proxy - You can enable this toggle to route outbound requests to the Internet through a proxy server. The Time zone option is not present for the Amazon WorkSpaces Core provider type.
  14. (Optional) To add Resource Tags for Microsoft Azure and Amazon WorkSpaces Core, expand the Advanced sub-section.

    If inherited tags exist, they will be displayed here. Click Add to add a tag that will be applied to the resource groups specific to this pool, click Done when you finish. For more information refer to: Using Azure Resource Tags and Using Amazon Resource Tags.

  15. (Optional) To use a Post Customization Script, expand the Advanced sub-section and provide the information needed.

    This optional feature allows admins to run a one time script at the end of provisioning the VMs and before the machine is made available for end users to connect to.

    • Post customization script path (optional): The path to the script that will be run during VM provisioning. Example: C:\windows\system\script.exe

    • Post customization script parameters (optional): Parameters or values required for the script to run successfully. Example: parameter1 parameter2

    • Script execution time (optional): Specifies the duration the system will wait after starting the script on a VM before marking it as available for user sessions. Use this delay to allow scripts to fully execute. This delay ensures that script has enough time to complete, functioning similarly to a fixed static timer.

    • Mark VM deployment as failed if the script fails to start: When enabled, this setting will mark the deployment as failed if the script fails to start. However, if the script starts but encounters an issue during execution, the deployment will still be considered successful.

    Note: The post-customization script will run on only newly provisioned VMs with agent version 25.3.0 or higher. Existing VMs or those with earlier agent versions will not execute the script.

  16. Click Next to save your changes and move to the Networks section.

  17. The Networks section content differs depending on your selected provider type.

    • For Microsoft Azure, select the virtual networks and tenant (desktop) subnets for Microsoft Azure. Note: The Azure dual-stack option cannot be modified when you edit a pool.

    • For Amazon WorkSpaces Core, set the specified VPC options for both Availability Zone 1 and its Subnet, and Availability Zone 2 and its Subnet. Refer to: Availability Zones for WorkSpaces Personal for more information.

      Important: Amazon WorkSpaces Core prevents changing subnets for registered WorkSpaces directories. Once a WorkSpaces directory is registered with specific subnets, the subnet configuration cannot be modified without first deregistering the directory. This process requires removing all workspaces from that directory because a) existing pools cannot have their network configuration modified and b) any new pools created using the same directory will inherit identical subnet configurations. This limitation necessitates careful planning of subnet allocation during initial network configuration.

    • By default, virtual desktops use IPv4 addresses. If you want the virtual machine to use IPv4 and IPv6 addresses, activate the Enable dual-stack support option and select subnets that are configured as dual stack. Note: When you enable the dual-stack option, only subnets that are configured as dual stack are listed.

  18. (Optional) The Dynamic Environment Manager is an optional feature you can configure.

  19. Click Save to save the newly created pool to your environment.

  20. The system will then prompt you to either add the pool you just created to a pool group or to select finish.

    • Select Finish to return to the Pools main page. Your newly created pool will be listed there.

    • Select Add To Pool Group to start adding this new pool to a new or existing pool group. You can also select a pool and add it to a pool group by clicking Add To Pool Group if a pool doesn’t have an associated pool group. For more information refer to: Create a Single-Session Pool Group or Create a Multi-Session Pool Group.

    Note: An additional VM will be temporarily created within each selected VM subnet to test the accessibility of the required endpoints for Horizon Cloud, including connectivity to your Active Directory. Once those endpoints are tested, the VM(s) will automatically be deleted by Horizon Cloud, and the pool creation will continue in the usual way. The provisioning experience will not change if validation passes. Once the provisioning is finished, the status will show Ready.

If the subnet validation fails, the results will be shown in the console under the pool status by displaying a Status: Error. Resolve the network issues and then click Retry for the pool creation process to continue. For more information, refer to: Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in a Microsoft Azure Environment or Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in an Amazon WorkSpaces Core Environment.

Results

When you see a pool listed on the main Pools page, you can perform actions on the pool such as editing the pool's definition and deleting the pool. For a pool that doesn't have an associated pool group, you can add a pool to a pool group by selecting the pool and clicking Add to Pool Group.

What to do next

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…