Skip to main content

Setting up Your Active Directory Domain

In Horizon Cloud, complete the following steps in Horizon Universal Console to register the first Active Directory domain with the service or register additional Active Directory domains.

As described in Horizon Cloud Identity and Access Management, the service uses the registered Active Directory for machine identity for the virtual desktops and remote applications.

Prerequisites

  • Active Directory Requirements

    The console's Domain Registration wizard requires input of specific information. Before doing these steps in the console, verify that you or your IT team have fulfilled the Active Directory related requirements as described in the Active Directory requirements section in the requirements checklist for your capacity type:

  • LDAPS-Specific Key Points and Requirements

    If you plan to use LDAPS in your deployment, note the following key points and requirements.

    • PEM-encoded root and intermediate CA certificates must be ready for upload.

    • Self-signed certificates are not supported.

    • The service requires that your DNS have SRV records for the domains configured to use LDAPS. Choosing to use LDAPS for a domain implicitly mandates the use of SRV records.

    • As a strong recommendation, your AD environment should be configured to enforce channel binding. Enforcing channel binding is a vital part of correctly securing LDAPS, especially to avoid man-in-the-middle (MITM) attacks.

    • Your firewall configuration must allow outbound connections from the Horizon Edge Gateway to your domain controllers with the following ports and protocols as described in the port and protocol requirements for your capacity type:

    • Port 88/TCP - Kerberos authentication

    • Ports 636/TCP and 3269/TCP - LDAPS communication

    • You must have a HTTP revocation endpoint defined for all certificates in the trust chain except for the root certificate and that endpoint must be reachable over HTTP. This requirement includes the following points:

    • The service will perform revocation checks using the OCSP or CRL HTTP URLs that are defined in your certificates.

    • The service cannot perform a revocation check if a certificate does not define an OCSP or CRL endpoint for the HTTP protocol. In that case, LDAPS connectivity fails.

    • Line of sight revocation must be available to endpoints. Your firewalls must not block outbound traffic to your revocation endpoint over HTTP.

Procedure

  1. Click Integrations in the left pane, and in the Identity & Access tile, click Manage.

  2. On the Domains tab, start the console's Domain Registration wizard by clicking Add.

  3. In the first wizard step, provide the indicated information

    FieldDescription
    NameThe name of the Active Directory domain.
    DescriptionOptional description.
    DNS Domain NameThe fully qualified name for this Active Directory domain (for example our-ad.example.com).
    Default OUType an appropriate default OU. This OU is the Active Directory organizational unit (OU) that you want the service to use as a default when it adds the machine identities it creates for the virtual desktops and remote apps..

    Type the OU's full distinguished name, such as OU=MyOrg,DC=our-ad,DC=example,DC=com.

    Note: If you want to use the default of CN=Computers, you must type that into the field. Even though you might see the UI display this default value in the field, the wizard will not make the Next button available unless you type it directly in this field.
    Domain Bind AccountsProvide the user names and passwords for the two service accounts that you or your IT team have configured for this purpose, as described in the Active Directory requirements section in the requirements checklist for your capacity type: These service accounts are used to perform lookups in the Active Directory domain. The first entered account is the primary one that the service uses for this purpose. The auxiliary account is a backup to the primary one.

    Ensure that the accounts entered here meet the requirements detailed in the requirements checklist.
    Domain Join AccountsProvide the user names and passwords for the two service accounts that you or your IT team have configured for this purpose, as described in the Active Directory requirements section in the requirements checklist for your capacity type: These service accounts are used to join the machine identities to the Active Directory domain and to perform Sysprep operations. The first entered account is the primary one that the service uses for this purpose. The auxiliary account is a backup to the primary one.

    Ensure that the accounts entered here meet the requirements detailed in the requirements checklist.
    ProtocolSelect the protocol, LDAP or LDAPS, to use to connect your Active Directory to the Horizon Edge Gateway.

    If you select LDAPS, use the Browse feature to upload your PEM-encoded root and intermediate CA certificates, which are referenced in the prerequisites for this task.

    When you have input all the required information, the system makes the Next button available.

  4. Proceed to the next wizard step by clicking Next.

    At this point, the wizard makes available the Save action to complete saving the domain information to the system.

    • If you aren't planning to use SSO, you can complete the UI wizard at this point by clicking Save.
    • If you plan to use the True SSO feature, continue to the next step in this page. Use of the True SSO feature requires a Microsoft Enterprise Certificate Authority, as described in Supported Certificate Authority Types for Using SSO with a Horizon Edge.
    • If you plan to use SSO that relies on the Omnissa CA or certificate authorities other than a Microsoft Enterprise Certificate Authority, you can complete the UI wizard at this point by clicking Save. Later you can complete that SSO configuration using the steps in Add an SSO Configuration to Horizon Cloud for an Omnissa CA.
  5. (Optional) If you plan to use True SSO with your end users' virtual desktops and remote apps, in the wizard's Domain Enrollment Service Account section, switch on the Use Enrollment Service Account toggle.

    When that toggle is switched on, the UI displays fields for you to enter the account credentials for the domain enrollment accounts that the True SSO feature requires. Provide that information.

    Attention: If you instead plan to use SSO that relies on the Omnissa CA, you can skip this step of entering domain enrollment account information.

    A domain enrollment account is an enrollment service account that the True SSO feature uses to obtain short-term certificates from Microsoft AD CS (Active Directory Certificate Services). True SSO uses the certificates for authentication, to avoid prompting users for Active Directory credentials. You might see the Horizon Universal Console using the terms domain enrollment account, enrollment service account, and domain enrollment service account interchangeably.

    After you complete the fields, the wizard makes available the Save action to complete saving the domain information to the system.

    Click Save to complete saving all the information you provided in the wizard.

Results

Your configuration of Active Directory with Horizon Edge is finished.

What to do next

At completion of the preceding steps, the service has the Active Directory domain information that it requires for a Horizon Cloud deployment.

To learn about adding the ability for your end users to have single sign-on (SSO) when accessing their desktops and applications, see Supported Certificate Authority Types for Using SSO with a Horizon Edge.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…