Skip to main content

September 2, 2026

Editing an Edge Deployment

You can edit various edge and provider settings after you have performed an initial deployment.

After you deploy the Horizon Edge and Unified Access Gateway using Horizon Cloud, you can edit some of the fields - including Unified Access Gateway settings - or you can delete the Edge. For Amazon WorkSpaces Core, you can also copy an agent pairing spec in preparation for working with images.

While editing the Edge, you can choose to route outbound requests to the Internet through a proxy server. If the proxy details are edited, the Edge may be redeployed. This may impact one or more of the following services until the redeployment is complete:

  • Single sign-on for desktop connectivity. Note that you can still connect to your desktops with your user name and password.
  • Certificate update for Unified Access Gateway.
  • Monitoring data loss for Workspace ONE Intelligence.
  • Agent DCT (Data Collection Tool) log collection.
  • Addition and replication of App Volume applications across fileshares.
  • Configured tests in type Simulated Resource Launch on the Availability Monitor will fail during the redeployment process.

Note: To copy an agent pairing spec file for Amazon WorkSpaces Core images only, see Copy an Agent Pairing Spec for Image Preparation.

Procedure

  1. Log in to the Horizon Universal Console. See Log in to Horizon Cloud.

  2. Click Horizon Edges on the Home page.

  3. Select the Horizon Edge that you want to edit.

  4. Click Edit to open the UI stepper page of sequential edit sections.

    Note: The stepper UI options differ based on the specified Horizon Edge provider type.

  5. On the General Information step, you can optionally edit the Name and Description of the Horizon Edge and click Next to continue.

  6. On the Primary Provider step, you can perform the following operations:

    • For the Microsoft Azure provider type, you can select the Dedicate to Horizon gateway appliances check box to dedicate the primary provider to the deployment of Horizon gateway appliances of Horizon Edge Gateway and Unified Access Gateway. If the check box is not selected, the provider also delivers desktops and applications as described in on-screen text. You can also manage Azure resource tags as needed by expanding the Advanced option. You can edit and delete existing tags and add tags to be applied to the resource groups specific to this provider.

    • For the Amazon WorkSpaces Core provider type, you can manage Amazon resource tags as needed by expanding the Advanced option. You can edit and delete existing tags and add tags to be applied to the resource groups specific to this provider.

    • In the Additional Service Principals section for the Microsoft Azure provider type, you can add additional service principals for the primary provider. Provide the service principal’s information (the Application ID, Application Key, and Expiry Date) that you created in the Microsoft Azure portal for this purpose.

  7. For the Microsoft Azure provider type, you can add Secondary Providers to this Horizon Edge with up to five unique service principals per provider, for a maximum total Horizon Edge capacity of 20,000 VMs. Click Next.

  8. In the Networks section, Select or Edit tenant (desktop) subnets for the Primary Provider and the Secondary Providers. Click Next.

    You can select the subnets at a later stage. However, you will not be able to deploy any resources into a provider until you select at least one subnet.

  9. Select the Site, or Add New site.

  10. If you add a new site, enter Site name. Optionally, add Description and then click Next.

  11. Click Next to open the Connectivity section and optionally change the network connection type.

    For more information about network connection choices, see the Requirements Checklist for the specific provider type at .

    Note: If you are using this UI sequence to change the deployment type of an existing Horizon Edge Gateway, you cannot also change the network connection type while making that change.

  12. In the Horizon Edge Gateway section, edit the Horizon Edge Gateway settings as appropriate depending on your goals and the selected deployment type (Azure Kubernetes Service or Single Virtual Machine).

    For Azure, you can initially deploy the Horizon Edge Gateway using the Single Virtual Machine deployment type and later change to the Azure Kubernetes Service (AKS) deployment type. You cannot, however, change a successfully deployed Edge from the Azure Kubernetes Service (AKS) deployment type to the Single Virtual Machine deployment type.

    Note: If deployment fails when changing the deployed Edge from deployment type Single Virtual Machine to Azure Kubernetes Service, you can attempt to change back to the Single Virtual Machine deployment type. However, once the change from Single Virtual Machine to Azure Kubernetes Service deployment is successful, you cannot change back to the Single Virtual Machine deployment type.

  13. To enable single sign-on for resources that are part of this Horizon Edge, toggle Use SSO and select the appropriate configuration from the SSO Configurations drop-down menu.

  14. If desired, reconfigure the Proxy settings.

    Activating the Use outbound proxy toggle might impact one or more of the following services until the redeployment is complete.

    • Single sign-on for desktop connectivity. Note that you can still connect to your desktops with your user name and password.
    • Certificate update for Universal Access Gateway. Ensure that all certificates prerequisites are met.
    • Monitoring data loss for Workspace ONE Intelligence.
    • Agent DCT (Data Collection Tool) log collection.
    • Addition and replication of App Volume applications across fileshares.
    • Configured tests in type Simulated Resource Launch on the Availability Monitor might fail during the redeployment process.
  15. (Optional): If the provider type is Microsoft Azure or Amazon WorkSpaces Core, you can manage Azure resource tags as needed.

    1. Expand the Advanced node. If inherited tags exist, those tags are listed for your reference.

    2. Click Add, manage resource tags as needed, and then click Done. You can edit and delete existing tags and you can add tags to be applied to the resource groups specific to this Microsoft Azure Edge. You cannot change CIDR values while in Edit mode.

    3. Click Next. Several options are not editable, as reflected in the UI.

    • Azure Kubernetes Service

      This deployment type is for Edge Gateway (AKS). This deployment type is typically used for production environments.

    • Single Virtual Machine

      This deployment type is for Edge Gateway (VM) and its options are similar to the Azure Kubernetes Service deployment type. The Single Virtual Machine deployment type is typically used for simple environments such as proof-of-concepts.

      You can change the deployed Horizon Edge Gateway's deployment type from Single Virtual Machine to Azure Kubernetes Service (AKS), however you cannot change the network connectivity type when making that change. Only one operation is supported at a time. After successfully changing the deployment type to Azure Kubernetes Service (AKS), you cannot change the Edge back to the Single Virtual Machine deployment type.

  16. In the Unified Access Gateway section, you can perform the following operations:

    • You can select the Automatic Public IP toggle to switch the option on or off.

      The Automatic Public IP toggle is switched on by default. If a manual custom IP is selected, an external UAG will be deployed with a private front-end IP address on the DMZ network. You must then take care of the routing from this private IP address to the customer-provided public one.

    • For a Microsoft Azure or Amazon WorkSpaces Core deployment, you can change the UAG Deployment Type from Basic to Advanced to support additional connections for each Horizon Edge. For example, if you have a deployed a NAT gateway or firewall in front of a load balancer, the Basic method uses source-ip-affinity and only supports 2000 connections for each Horizon Edge. The Advanced deployment type uses hash-affinity and supports up to 18000 connections for each Horizon Edge. The Advanced option requires you to select a new UAG management subnet with a /28 subnet mask from the list.

      Note: Changing the Deployment Type from Basic to Advanced or Advanced to Basic will redeploy all the resources, including the load balancer. This action might change the IP address of the load balancer, thus requiring a change in the DNS mapping of the FQDN and load balancer IP address if the IP address changes. The Advanced option requires you to select a new UAG management subnet with a /28 subnet mask from the list. If a change in the load balancer IP does occur, you must update the DNS record with the new IP address. For related information, see Configure Required DNS Records After Deploying Horizon Edge Gateway and Unified Access Gateway.

  17. (Optional) Expand the Advanced node if you want to perform one or more of the following operations:

    • If you are deploying the Unified Access Gateway as Blast Extreme, you can specify that either port 8443 or port 443 be used.

    • You can specify an NTP server and Proxy information, as shown and described in the onscreen help for those options.

    • You can use tags to be applied to the resource groups specific to this provider.

    • If the provider type is Microsoft Azure, you can manage Azure resource tags as needed by expanding the Advanced node.

    • If the provider type is Amazon WorkSpaces Core, you can manage Amazon resource tags as needed by expanding the Advanced node.

  18. Click Save.

If Deployment Fails When Changing Edge Deployment Type for Azure or Amazon

If the deployment fails when changing the Edge deployment type, a message appears describing why the deployment failed and providing an option to either retry the deployment or view the logs. When you click Retry, you can correct the reason for the failure. If the failure occurs when changing from Single Virtual Machine to Kubernetes Service, you can attempt to change back to Single Virtual Machine. However, once the change from Single Virtual Machine to Kubernetes Service is successful, you cannot change back to Single Virtual Machine.

For related information, see Retry Horizon Edge Gateway Deployment and Retry Unified Access Gateway Deployment

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…