Using App Volumes applications functionality, you can manage the entire lifecycle of applications, including packaging, updating, and retiring applications. You can also customize application entitlements to deliver specific versions of an application to end users.
If you intend to use but do not see App Volumes in the console, contact your account representative to verify whether your license and tenant account configuration allows you to use App Volumes. After the license is activated, App Volumes is automatically available for use in the Horizon Universal console.
For operations such as importing or deleting application packages, provisioning file shares, and replication of application packages from staging to delivery file shares, the Horizon Edge deployment must be connected. For more information about file shares, see the Horizon Edge-related prerequisites section on this page.
For guest operating system support, see the Omnissa Product Interoperability Matrix.
Overview of App Volumes Functionality in Horizon Cloud
The following table provides an overview of App Volumes functionality in Horizon Cloud.
| Functional Area | Description |
|---|---|
| Deployment |
|
| Management Console |
|
| App Volumes 4 agent | Unified performance-optimized agent used both for on-premises, Microsoft Azure, Amazon Workspaces Core, and vSphere deployments. |
| Packaging |
|
| Application Lifecycle Management | Supports Simplified Application Management (SAM) capability that is already a part of App Volumes 4 on-prem. Administrators can now manage the entire life cycle of the application, including packaging, updating, and retiring. |
| Application Assignment |
|
| Identity Provider | App Volumes supports Active Directory and Microsoft Entra ID. |
| Hybrid Cloud Support | On-prem App Volumes customers can now import their application packages from their on-prem deployments into Horizon Cloud on Microsoft Azure or Amazon Workspaces Core. Reuse on-prem packages. Repackaging is not required. |
Overview of the App Volumes Application Process
Making App Volumes applications available to users is a two-step process:
-
Add an App Volumes application in the Horizon Universal Console. There are two ways of doing this:
-
Add an App Volumes application by creating and importing a new application package.
If an application package has not yet been created, you can create it with the Add Package option, which uses App Volumes to create the application package and automatically import it. See Add an App Volumes Application Using Horizon Cloud.
Alternately, you can also create an application package while creating an application using the Add Application functionality.
-
Add an App Volumes application by importing an existing application package.
If you have an application package that was previously created with App Volumes, you can import it with the Import Application option. This means you can reuse application packages from on-premises deployments without having to repackage the applications. See Add an App Volumes Application by Importing an Existing Application Package Using Horizon Cloud.
-
-
Create an App Volumes entitlement to entitle the App Volumes application to users. See Create an Entitlement for an App Volumes Application using Horizon Cloud.
Prerequisites for Using App Volumes with Horizon Cloud on Edge deployments
App Volumes can be used with Microsoft Azure, Amazon Workspaces Core, and vSphere Provider Edge deployments.
Storage Account Access Key Rotation for Azure
You can rotate the storage account access keys for an App Volumes application storage account in the Microsoft Azure portal and update the rotated key for the storage account in the Horizon Universal Console.
Note: Ensure that you follow all the best practices and recommendations by Microsoft Azure when rotating the storage account access keys.
After rotating an access key in the Microsoft Azure portal for an App Volumes application storage account, the access key for that storage account is no longer valid. As a result, the pool VM loses access to the storage account and the end user who has logged into that pool VM can no longer use the applications. To prevent affecting the end user, you must update the secondary (key2) access key for the App Volumes application storage in the Horizon Universal Console even before rotating the primary key (key1).
To update an access key for an App Volumes application storage, use the Update Access Key functionality in the Horizon Universal Console > Capacity > Edge > App Volumes Application Storage grid section. To view this functionality, in the grid, you must click the ellipsis icon for that storage account. The Access Key Status in the storage grid indicates whether the status of the updated key is Valid or Invalid. After successfully updating the access key for the storage account, the status of the key becomes Valid. The pool VMs are able to access the storage account and the user can continue using the applications.
Important: There might be active attachments on the pool VM accessing the storage account whose access key you intend to update. Hence, after updating the storage account with the secondary (key2) access key, restart the pool VM. This restart ensures that the pool VM continues to access the storage account and the attachments remain active. As a result, the end user can continue using the applications on that pool VM. Following this action, the intended key can be rotated.
If you want to use the rotated access key to update for the storage account, ensure that no attachments are using this key before rotating the intended access key.
Update the Domain Join Service Account Details for App Volumes
Amazon Workspaces Core Edge Deployment
If you change the domain join service account credentials in the AWS console, then you must ensure that the changed service account details are updated in the Horizon Universal console. This update ensures that the Horizon Edge continues to access the Amazon FSx file shares through the service account and administrator operations continue normally.
Note:
-
The service account details must be updated in every Horizon Edge which uses the same service account.
-
In the AWS console, service account details must be updated for all FSx file shares which are used by the App Volumes Application storage account in a specific Horizon Edge.
-
If there is a change in the DNS Server IP address of the Active Directory domain for App Volumes, then the changed IP address must also be updated in the Horizon Universal console.
Procedure
-
Change the domain join service account credentials.
a. Go to the Horizon Universal console, navigate to the Capacity page, select the desired Horizon Edge, and click Edit.
b. Navigate to the App Volumes Storage section and make note of all the File Share Names.
c. Go to the AWS Console, navigate to File systems (File Share Names), and update the service account details (username and password) in all the required File systems.
If necessary, update the DNS IP addresses for all the required File systems.
-
Go to the Horizon Universal console, navigate to the Capacity page, select the desired Horizon Edge, and click Edit.
-
Navigate to the App Volumes Application Storage section.
-
Beside the Service Account details table title, click Edit.
-
Update the Service Account username and password with the same values that were used to update in the AWS console.
If you have changed the DNS IP address in the AWS console, then you must update the DNS IP address on this page too.
vSphere Provider Edge Deployment
If the domain join service account credentials change, then you must ensure that the changed service account details are updated in the Horizon Universal console. This update ensures that the Horizon Edge continues to access the file shares through the service account and administrator operations continue normally.
Note:
-
The service account details must be updated in every Horizon Edge which uses the same service account.
-
To access the file shares, ensure that this service account has both read and write permissions.
Procedure
-
Go to the Horizon Universal console, navigate to the Capacity page, select the desired Horizon Edge, and click Edit.
-
Navigate to the App Volumes Application Storage section.
-
Beside the Service Account details table title, click Edit.
-
Update the Service Account username and password with the same values that were used to update in the vCenter console.
Horizon Edge-related requirements
Before you can add App Volumes applications into your inventory, confirm that your environment meets the following prerequisites.
-
The deployment must have a gateway configuration (Unified Access Gateway instances), and you have completed the Unified Access Gateway’s FQDN-mapping steps, as it is required for Horizon Cloud on Microsoft Azure or Horizon Cloud on Amazon Workspaces Core deployments that are configured with Unified Access Gateway instances.
-
Depending on the type of Edge deployment, file shares are generated by the service or you can bring your own file shares.
To view the file shares, in the Horizon Universal Console, navigate to the Capacity page, click the Horizon Edge, and scroll to the App Volumes Application Storage section.The two types of file shares are as follows:
-
Staging file share
The staging file share is a single file share which is used to stage new application packages for discovery and import into the application inventory. The application packages can be copied from an existing App Volumes 4.x deployment. The file share is also used for application packaging.
Edge Deployment Staging file share Microsoft Azure A single Azure file share is automatically provisioned when the Horizon Edge is deployed.
For information about deploying a Microsoft Azure Edge, see Add and Deploy a Microsoft Azure Edge.Amazon Workspaces Core A single Amazon FSx for Windows file server is automatically provisioned when the Horizon Edge is deployed.
For information about deploying an Amazon Workspaces Core Edge, see Add and Deploy an Amazon WorkSpaces Core Edge.vSphere Provider You can bring your own domain-joined SMB file share and register the file share when deploying the Edge. You can also register the file share after Edge deployment by editing the deployed Edge.
For more information about deploying a vSphere Edge, see Add and Deploy a Horizon Edge for vSphere. Only a single file share is registered as a staging file share.
For information about editing the deployed Edge, see Editing a Horizon Edge Deployment. -
Delivery file share
The delivery file share is used to deliver existing application packages that are entitled to users or groups. The desktop pool VMs mount the application package disks from this file share. Within a Horizon Edge, Horizon Cloud automatically replicates the application packages from the staging file share to the delivery file shares.
Edge Deployment Delivery file share Microsoft Azure Six delivery Azure file shares are automatically provisioned when the first pool is created for every provider.
For example: For a Microsoft Azure edge with one primary provider and four secondary providers, App Volumes provisions one staging file share and six delivery file shares for every secondary provider. As a result, a total of 24 delivery file shares are provisioned.Amazon Workspaces Core A single Amazon FSx for Windows file server is automatically provisioned when the first pool is created for every provider. vSphere Provider You can bring your own domain-joined SMB file shares and register these file shares when deploying the Edge. You can also register the file shares after Edge deployment by editing the deployed Edge. You can register any number of delivery file shares.
For information about editing the deployed Edge, see Editing a Horizon Edge Deployment.
For more information about deploying a vSphere Edge, see Add and Deploy a Horizon Edge for vSphere.Note:
-
If you intend to use the primary provider to create your pools, then App Volumes provisions one staging file share and six delivery Azure file shares.
-
In a vSphere Edge deployment, the registered file share must be in the same region as the deployed Edge.
-
When deploying an Amazon Workspaces Core Edge, you can configure the sizing for an Amazon FSx for Windows file server. The sizing options provided are Basic and Advanced. The Amazon FSx for Windows file server is provisioned as per the configured sizing option. For information about adding and deploying an Edge, see Add and Deploy an Amazon WorkSpaces Core Edge.
Sizing option Description Basic The provisioned Amazon FSx for Windows file server has the following sizing features: - 1500 IOPS
- 500 GB storage capacity
- 32 MB/s throughput
Advanced The provisioned Amazon FSx for Windows file server has the following sizing features: - 10000 IOPS
- 500 GB storage capacity
- 256 MB/s throughput
Note:
For new deployments, you can select the sizing option as either Basic or Advanced. After the initial configuration, the sizing options cannot be changed from the Horizon Universal Console. However, the sizing options can be customized using the AWS Management Console. For more information, see FSx for Windows File Server performance.
For existing deployments, the sizing option is Basic.
-
Configuration requirements
| Options | Description |
|---|---|
| Horizon Edge on Microsoft Azure |
|
| Horizon Edge on Amazon Workspaces Core |
|
| Horizon Edge on vSphere | Ensure that you have configured the domain joined service account details. This configuration is mandatory for using the domain-joined SMB file shares. |
How to locate the Agent Version of an image
Prerequisite: Ensure that the App Volumes agent is installed.
To locate the Agent Version of an image for a specific pool, follow these steps:
-
Navigate to the Pools page.
-
Click a pool name.
-
In the pool details page, go to the General Settings section.
-
In the Image pane, make note of the Name value.
The Name is the image name used for that particular pool. -
To view a list of images, navigate to the Images page.
-
To view the Versions table that lists the image versions and status, click the image name link.
-
Click the link of the desired image version.
-
In the image version details page, go to the Image Copies table.
-
View the Agent Version.
The Agent Version indicates the Horizon Agent Installer build installed on the image version.
Packaging requirements
- If you have configured firewall rules for access to storage account provisioned by App Volumes, ensure that you allowlist all the subnets that are associated with the provider for the Horizon Edge deployment used to package the applications.
- You must deactivate auto-update services for each application you intend to package, as an auto-update behavior is problematic.
- If the application has an auto-update service, deactivate the service, such as with Windows Services Manager, during the application-provisioning process.
- If you cannot or do not deactivate the auto-update service during the application provisioning process, after you encounter an issue, such as users receive an incomplete version of an unassigned application, modify the base image by configuring the registry. This configuration ensures that the service of interest is not started when the application package is deployed to the user VM. Specifically, configure the registry by adding the application service name to the svservice registry configuration DisableAppServicesList.
Prerequisite for Displaying App Volumes Applications in the App Catalog in Hub Services
When Horizon Cloud is integrated with Workspace ONE Intelligent Hub, end users can access and launch their assigned applications from Intelligent Hub on a Windows machine, from the Workspace ONE Intelligent Hub web portal. For information about the Horizon Cloud integration with Workspace ONE Intelligent Hub, see Integrating Workspace ONE Intelligent Hub with Horizon Cloud.
-
For App Volumes applications to be displayed in the Hub catalog (App Catalog) in a VDI desktop, ensure that the latest HAI version is installed in the end user's Windows machine.
For information about the HAI version, see the Horizon Cloud Release Notes at Omnissa Product Documentation.
If the VDI desktop has an earlier version of HAI or the App Volumes agent is not installed, then the App Volumes applications are not displayed in the Hub catalog. -
Ensure that the Intelligent Hub is able to communicate with the App Volumes agent service.
-
Ensure that the required Windows policies are configured in the end user's Windows machines which allowlist the Intelligent Hub web URL for local network access.
For more information about this requirement, see Providing Access to App Volumes Packaged Applications in the Setting up Resources in Omnissa Access guide at Omnissa Product Documentation. -
In the Hub Services console, ensure that the Show App Volumes Apps toggle is turned on.
For more information about this requirement, see Providing Access to App Volumes Packaged Applications in the Setting up Resources in Omnissa Access guide at Omnissa Product Documentation.
Best Practices for Using a Microsoft Windows Enterprise Multi-Session Image with App Volumes Applications in Horizon Edge Deployments
The following practices help provide a better user and administrator experience. Also see Setting up a Microsoft Windows Enterprise Multi-Session Image with App Volumes Applications.
-
Install hardware printers, with printer drivers, in the base image.
-
As described in the Microsoft documentation FAQ, Microsoft Windows 11 Enterprise multi-session is a Remote Desktop Session Host (RDSH) type of VM that allows multiple concurrent interactive sessions, which previously only Microsoft Windows Server operating systems provided. As Microsoft Windows 11 Enterprise multi-session is an RDSH type of operating system, the Horizon Cloud RDSH-applicable workflows apply to it instead of the VDI-related workflows. As a result, to provide session desktops to end users based on these multi-session systems, create a multi-session pool group as described in Create a Multi-Session Pool Group.
-
Inform users that when they install applications or create files that they do not intend to share among all user sessions on the same VM, they can place the file in their own profile location.
Was this page helpful?