Overview
When deploying Horizon Cloud managed desktops, you have several options for how machines are identified and joined to directory services:
- Active Directory Domain Services (AD DS) - traditional on-premises Active Directory.
- Microsoft Entra ID (formerly Azure AD) - cloud-based identity and directory service.
- Entra ID Hybrid Join - a combination of both, allowing desktops to connect to on-premises Active Directory and cloud-based Entra ID resources simultaneously.
This topic describes the Entra ID hybrid-join option and applies to all supported capacity provider types when creating or editing desktop pools in the Horizon Universal Console.
What Is Entra ID Hybrid Join?
Entra ID hybrid join enables your Horizon Cloud managed desktop VMs to be registered in both your on-premises Active Directory domain and Microsoft Entra ID. This gives end users seamless access to both on-premises and cloud-based resources from a single desktop session, without requiring separate identity configurations for each environment.
This option is particularly useful for organizations that are transitioning from on-premises infrastructure to cloud identity services, or that require concurrent access to resources in both environments.
Supported Capacity Providers
Entra ID hybrid join is supported for Microsoft Azure, vSphere, and OpenStack capacity provider types.
Configuring Hybrid Join During Pool Creation or Editing
When creating or editing a desktop pool in the Horizon Universal Console, the Machine Identity (Domain) section includes a toggle labeled Defer VM availability until hybrid join.
When this option appears
This toggle is available when:
- You are creating or editing a pool for any supported capacity provider (Microsoft Azure, vSphere, or OpenStack).
- The specified Machine Identity provider is an on-premises Active Directory server.
What the toggle does
When Defer VM availability until hybrid join is enabled, VMs in the pool are not made available to end users until the hybrid join process completes successfully. This ensures that users always connect to a fully registered desktop - joined to both on-premises Active Directory and Microsoft Entra ID - before a session is established.
Enabling this option allows the pool to access both on-premises and cloud-based resources. Refer to the on-screen help for the prerequisites required before using this option.
Important Considerations
Reuse VM ID and Hybrid Join Conflict
Important: Do not enable both Reuse VM ID and hybrid join for the same desktop pool template simultaneously.
When floating pool VMs are recreated, enabling Reuse VM ID causes the VM to reuse its existing computer account in Active Directory. However, the corresponding device entry in Microsoft Entra ID may not update correctly, which can result in authentication or registration problems with those recreated VMs. To avoid this issue:
- Enable hybrid join without enabling Reuse VM ID, or
- Consult your Active Directory and Entra ID administrator before combining these settings.
Related Topics
Was this page helpful?