After you add an Active Directory domain, you can use the Horizon Universal Console to edit that domain.
The prerequisites and steps involved in editing your Active Directory domain are very similar to the initial steps of configuring your Active Directory domain. For related information, see Setting up Your Active Directory Domain.
The prerequisites you must perform for this task depend on the domain information you plan to update. For example, if you change the protocol from LDAP to LDAPS, you must perform the LDAPS related prerequisites, such as preparing PEM-encoded root and intermediate CA certificates and making the appropriate LDAPS ports available.
Upcoming Expiration Notification for Active Directory Linked Credentials
You will be notified of the upcoming expiration of Active Directory Primary/Auxiliary Domain Bind/Join/True SSO account passwords by an in-app notification and emails. Immediately update with the new credentials prior to expiration or you will not be able to perform certain administrative functions.
You will be notified after expiration of the Active Directory Primary/Auxiliary Domain Bind/Join/True SSO Account passwords via in-App notification* and Emails. You need to immediately update the new Credentials failing which you will not be able to perform certain administrative functions e.g. create new Pools, change entitlements etc.
Note: In-App notifications will be visible on the Horizon Universal console.
Post Expiry Notification for the Active Directory Credentials
You will be notified after expiration of the Active Directory Primary/Auxiliary Domain Bind/Join/True SSO account passwords by an in-app notification and emails. Immediately update with the new credentials or you will not be able to perform certain administrative functions.
Procedure
-
Navigate to the console's Domains tab, click Integrations in the left pane, and in the Identity & Access tile, click Manage.
-
Select a domain to edit and click Edit.
-
Edit the information that you want to update.
Field Description General Information Edit the general information, such as Name and Default OU as appropriate. Domain Bind Accounts If appropriate update the user names and passwords for the two service accounts that you or your IT team have configured for this purpose, as described in the Active Directory requirements checklist for your capacity type: Domain Join Accounts If appropriate, provide the user names and passwords for the two service accounts that you or your IT team have configured for this purpose, as described in the Active Directory requirements checklist for your capacity type: Protocol If appropriate, change the protocol from LDAP to LDAPS or from LDAPS to LDAP. If changing from LDAP to LDAPS, use the Browse feature to upload your PEM-encoded root and intermediate CA certificates, which are referenced in the prerequisites for this task. -
Click Save.
-
(Optional) If you plan to use True SSO with your end users' virtual desktops and remote apps, in the wizard's Domain Enrollment Service Account section, switch on the Use Enrollment Service Account toggle.
When that toggle is switched on, the UI displays fields for you to enter the account credentials for the domain enrollment accounts that the True SSO feature requires. Provide that information.
Attention: If you instead plan to use SSO that relies on the CA, you can skip this step of entering domain enrollment account information.
A domain enrollment account is an enrollment service account that the True SSO feature uses to obtain short-term certificates from Microsoft AD CS (Active Directory Certificate Services). True SSO uses the certificates for authentication, to avoid prompting users for Active Directory credentials. You might see the Horizon Universal Console using the terms domain enrollment account, enrollment service account, and domain enrollment service account interchangeably.
After you complete the fields, the wizard makes available the Save action to complete saving the domain information to the system.
-
Click Save to complete saving all the information you provided in the wizard.
Your update of Active Directory with Horizon Edge is finished.
Was this page helpful?