The Horizon Universal Broker is a cloud-based service that brokers desktops across multiple sites, regardless of the underlying infrastructure. The service makes intelligent brokering decisions based on the geographic locations of users and resources.
By enabling the Horizon Universal Broker for Horizon 8 Edges, you connect your Horizon 8 environments to a single, unified brokering service. This allows users to seamlessly access desktops and applications across both on-premises and cloud environments.
Note: The Horizon Universal Broker supports Virtual Delivery Agent (VDA) and Remote Desktop Session Host (RDSH) Virtual Delivery Agent.
Understanding RDS Farms vs RDSH Pools
When configuring multi-session environments, it is helpful to understand the distinction between the infrastructure and the delivery mechanism:
-
RDS Farm (The Infrastructure): A collection of virtual machines (RDSH servers) running the Windows Remote Desktop Services role. This is the underlying compute capacity where the sessions actually run.
-
RDSH Pool (The Entitlement): In Horizon, this is also known as a published desktop or application pool — the component that delivers resources from the farm to the user. When used with the Universal Broker, only published desktop pools are currently supported. RDSH published application pools are not currently supported with Universal Broker.
Understanding Cloud-Managed Pools
When you configure a Horizon 8 pool as Cloud-managed, you are granting the Horizon Cloud Control Plane permission to manage and broker user connections to that specific pool via the Universal Broker. This setting bridges your Horizon 8 environment with your Horizon Cloud service.
For single-session VDI pools, only pool-level Cloud-managed configuration is required. For RDSH environments, the Cloud-managed configuration operates at two levels:
-
Farm level: Before configuring individual RDSH pools as Cloud-managed, you must first synchronize the Horizon 8 RDSH farm with the Horizon Control Plane. This registers the underlying session host infrastructure — the RDS Farm described in the section above — with Horizon Cloud and makes farm resources available for pool-level configuration.
-
Pool level: Once the farm is synchronized, you configure individual RDSH pools within that farm as cloud-managed, granting the Universal Broker permission to broker user connections to those specific pools.
Once you enable the Cloud-managed flag in your Horizon 8 Connection Server, the pool data synchronizes with the cloud. Shortly after configuration, these pools and their associated resources will automatically appear in the Horizon Universal Console. For RDSH farm pools, this includes both session desktops, which become available for grouping and management alongside resources from cloud-native pools. You can view, monitor, and add them to pool groups by navigating to Pools in the left-hand menu of the console.
For detailed instructions on configuring Cloud-managed pools, see Create a Hybrid Pool with the Horizon Universal Broker.
Integration with Horizon 8
You can connect Horizon 8 pods to the Horizon Universal Broker to streamline the management of single-session VDI, multi-session Remote Desktop Services (RDS) pools, and RDSH farms.
Unlike traditional VDI, RDS and Remote Desktop Session Host (RDSH) pools allow multiple users to share a single Windows Server virtual machine to access published applications or session-based desktops. This provides higher user density and lower infrastructure costs.
In addition to individual pool management, administrators can configure Horizon 8 RDSH farms to synchronize with the Horizon Control Plane. As defined in the Understanding RDS Farms vs. RDSH Pools section above, an RDSH farm is the underlying infrastructure group that contains one or more session host virtual machines. Synchronizing a farm with the Horizon Control Plane makes the farm's session desktops available for centralized management through the Horizon Universal Console — without requiring each resource to be configured individually.
This feature supports hybrid pool groups, allowing you to combine Horizon 8 pools with cloud-provider pools within the same pool group, or manage them separately. You can create hybrid pool groups for multiple resource types:
-
Single-session (VDI) Pool Groups: Combine Horizon 8 floating or dedicated desktop pools with Microsoft Azure or AWS provider-type pools for scalable virtual desktop delivery.
Note: Hybrid pool groups with Horizon 8 automated desktop pools are available for vSphere only. Supported on the Horizon Client for Windows, Linux, Mac, and Web.
-
Multi-session / RDSH Pool Groups: Combine Horizon 8 RDSH farm pools with cloud-native multi-session pools. This allows administrators to manage session desktops across on-premises RDSH farms and cloud-native session hosts from a single unified Pool Group in the Universal Console.
Port and Protocol Requirements for Universal Broker with Horizon 8
For the Universal Broker use-case, the Unified Access Gateway instances must maintain connectivity to the Horizon Cloud Service Gateway endpoints to fetch the JSON Web Key (JWK) set used for JWT (JSON Web Token) authentication. This connectivity is critical for session brokering and client protocol redirection to function correctly across pods.
Ensure that your network configuration and firewalls allow the Unified Access Gateway instances to communicate with the destinations as shown below:
- Source: Unified Access Gateway
- Target:
cloud-sg.horizon.omnissa.com - Port: 443
- Source Network: DMZ network
- Protocols: TCP, UDP
- Purpose: Because the Unified Access Gateway fetches the JWK set from
cloud-sg.horizon.omnissa.com, Unified Access Gateway must be able to resolve these addresses at any time or the user will not be able to launch the session.
Session Routing in Hybrid RDSH Pool Groups
When a Pool Group contains both Horizon 8 RDSH farm pools and cloud-native multi-session pools, the Universal Broker uses the brokering policies configured for that Pool Group to determine where each user session is routed.
The broker evaluates the following factors when routing sessions in a hybrid RDSH Pool Group:
-
Resource availability: The broker checks the available capacity across all pool members — both on-premises RDSH session hosts and cloud-native session hosts — and routes sessions to pools that have capacity to serve the request.
-
Geographic proximity: Where applicable, the broker favors pool members that are geographically closer to the user to minimize latency.
-
Load-balancing rules: Any load-balancing or weighting rules you define in the Pool Group policy are applied consistently across all member pools, including Horizon 8 RDSH farm pools.
-
Session desktop routing: The broker applies the same policies used for cloud-native multi-session pools to on-premises RDSH farm pools within the same group, routing users to the pool with the best available capacity.
No additional brokering configuration is required beyond what you would configure for a standard hybrid Pool Group. Existing brokering policies apply to Horizon 8 RDSH farm pools in the same way they apply to cloud-native pools in the group.
For more information about creating a Pool Group that includes Horizon 8 RDSH farms, see Create a Hybrid Pool with the Horizon Universal Broker.
Prerequisites
Before using the Horizon Universal Broker with your Horizon 8 environment, ensure the following prerequisites are met.
Supported Minimum Versions
The minimum versions of the following components are required:
| Component | Minimum Version |
|---|---|
| Horizon 8 Connection Server | 2506 |
| Horizon Client for Windows | 2506 |
| Horizon Client for Linux, Mac, and Horizon Web Client | 2512 |
Horizon Control Plane Connection
Your Horizon 8 Edges must be connected to the Horizon Control Plane via the Horizon Edge Gateway. For details, refer to Connecting the Horizon Deployment to the Horizon Control Plane.
JWT Authenticator
Horizon 8 Edges require a configured Horizon JWT Authenticator. You manage this using the Connection Server - Horizon JWT Authenticator setting in the Horizon Universal Console when enabling the Universal Broker option for a new or existing Horizon 8 Edge. You have two configuration options:
-
Automated JWT: Horizon Cloud automatically provisions and configures the JWT trust between the cloud and your Connection Server. No additional configuration steps are required.
-
Manual JWT: You must manually configure the JWT authenticator in Horizon 8. For instructions, refer to Configure a JWT Authenticator in Horizon Console.
Note: For information about configuring the JWT in the Horizon Unified Access Gateway (UAG), see Configure JWT Settings in the Horizon Unified Access Gateway below.
If using Unified Access Gateway, refer to: JSON web token (JWT) settings.
Troubleshooting: If JWT configuration fails after a few minutes with no error message, verify:
- The
locked.propertiesfile has been updated and Connection Server services restarted on all Connection Servers. - The
portalHostlist includes all relevant FQDNs. - The Issuer field is set to
portal(not blank). - The JWT Consumer authenticator has been assigned under General Settings > Edge Service Settings > Edit Horizon Settings > More > JWT Consumer.
- If the problem persists, open a Support Request and reference UAG and Connection Server logs.
Deployment Prerequisites
Ensure your domain, identity, and access settings are properly configured. Refer to Requirements Checklist for Deploying a Horizon 8 Edge.
Network Requirements
Verify that minimum network requirements are met. Refer to Port and Protocol Requirements for Deploying Horizon 8 Edge.
Connection Server Properties
Add these properties to the locked.properties file on every Horizon Connection Server in the pod. File location: C:\Program Files\Omnissa\Horizon\Server\sslgateway\conf\locked.properties
Important: After saving changes, restart the Horizon Connection Server services on each server for the settings to take effect.
The following properties must be configured on the Horizon Connection Server:
-
enableCORS = trueMandatory (Web Client only): Enables CORS on the server to prevent cross-origin requests from being blocked. This setting is not required if users are connecting via native Horizon Clients. -
allowPreflight = trueMandatory: Allows OPTIONS preflight requests. Browsers send OPTIONS before actual requests to check permissions. -
checkOrigin = trueOptional: Server validates that incoming requests are from allowed origins. Only origins in theportalHostlist are accepted. -
checkOrigin-misc = falseOptional: Disables origin checking for miscellaneous/non-portal endpoints. Uses less strict validation for certain paths. -
allowMethod.1 = GET, allowMethod.2 = HEAD, allowMethod.3 = POSTMandatory: Used to fetch specifications and launch items. -
portalHost.1 = <customOriginPortalHost1>, portalHost.2 = <customOriginPortalHost2>, portalHost.3 = ...Mandatory: When using different origins, you must list all origins.
Example configuration:
enableCORS = true
allowPreflight = true
checkOrigin = true
checkOrigin-misc = false
allowMethod.1 = GET
allowMethod.2 = HEAD
allowMethod.3 = POST
allowMethod.4 = PUT
portalHost.1 = ub-uag.mclab.horizoneuc.com
portalHost.2 = devlb-westus2-cp103.azcp.horizon.omnissa.com
portalHost.3 = titan-portal.local
portalHost.4 = ubcs.mclab.horizoneuc.com
Note: For on-premises Connection Servers and UAGs, list the individual server FQDNs — do not use the load balancer FQDN. The cloud-side Universal Broker FQDN (as configured in the Horizon Universal Console) should also be included. Cloud load balancer FQDNs may be included for cloud-hosted components.
Additional Resources
-
To create a hybrid pool after configuring the broker, refer to Create a Hybrid Pool with the Horizon Universal Broker.
-
For additional context and best practices, read Unlocking Simplicity: Universal Broker Support for Horizon 8 in the Omnissa Horizon Control Plane on the Omnissa Communities blog.
Identity Provider (IdP) Prerequisites for Universal Broker
Before configuring the Universal Broker, you must set up and configure a supported Identity Provider (IdP).
Currently, the Universal Broker only supports the following Identity Providers:
- Microsoft Entra ID (formerly Azure AD)
- Workspace ONE Access (Cloud)
Active Directory Synchronization and Domain Requirements
To ensure successful authentication and brokering, your environment must meet the following directory requirements:
- Directory Sync: Your configured cloud IdP must be fully synchronized with your on-premises Active Directory (AD).
- Domain Matching: The domain used in your on-premises environment must be identical to the domain used in the cloud.
- Tenant Association: This matching domain must be actively associated with your Cloud Service IdP tenant.
Verification Tip: You can verify that your directory synchronization is working correctly by searching for a specific user account in both your on-premises AD console and your cloud IdP console. The user account should appear successfully in both locations.
Workspace ONE Access Group-Level Assignments
If you are using Workspace ONE Access as your IdP and plan to use group-level assignments, you must configure a specific setting within the Workspace ONE Access console. Under the Directories menu of the Workspace ONE Access console, Select the Directory Name you need to edit. Navigate to Settings > Directory Sync and Authentication and in the External ID filed, You must map the objectGUID value to the externalId attribute.
For detailed steps on configuring your supported cloud IdP, refer to the following documentation:
- Configure Microsoft Entra ID as Your Identity Provider
- Configure Workspace ONE Access as Your Identity Provider
Configure JWT Settings in the Horizon Unified Access Gateway
To support brokering requests by the Horizon Unified Access Gateway (UAG) with Horizon Universal Broker in Horizon Cloud, configure the JWT authenticator in the UAG application. This configuration allows the UAG to retrieve the necessary JWT authenticator from the cloud and validate the JWT token.
-
Open the Horizon Unified Access Gateway application and navigate to the UAG Administrator UI.
-
Select JWT Settings.
-
Add a JWT authenticator: In the Issuer field, enter
portal. Next, select Dynamic Public key URL. -
Enter the public key URL, for example https://cloud-sg.horizon.omnissa.com/portal/.well-known/openid-configuration. Set the Public key refresh interval to
3600. -
To use the configured JWT, click General Settings > Edge Service Settings > Edit Horizon Settings.
-
Scroll to the bottom of the page, click More, and then select the JWT Consumer authenticator you configured from the JWT Consumer drop-down list.
Note: If you plan to use a different UAG FQDN, because of a load balancer, select Advanced Settings > System Configuration > Allowed Host Headers and set as described in the System configuration for the Unified Access Gateway product documentation.
Enable the Universal Broker in Horizon Cloud
You will configure prerequisites in both the Horizon 8 Admin Console and your Horizon Cloud service account. However, you must enable the feature directly in Horizon Cloud using an existing Horizon 8 provider-based Horizon Edge.
-
From the Horizon Universal Console in Horizon Cloud, click Capacity > Horizon Edges.
-
Select the name of the existing Horizon 8 provider type Edge for which to enable the Universal Broker feature to open the Details page for that Edge.
-
Click the Features tab on the resultant details page to display the Universal Broker enablement content.
-
Confirm that you meet the four listed prerequisites. If any of the listed prerequisites have not been met, follow the on-screen help before continuing.
Note: All four listed prerequisites must be met before you toggle the Brokering option.
-
Switch the Brokering toggle option from Not Enabled to Enabled.
Connect to Horizon 8 Desktops through Universal Broker
To allow end users to connect to their desktops using the Universal Broker, you must first configure the appropriate entitlements and pool settings.
Administrator Configuration Steps
-
Configure Cloud-Managed Pools: Set up your Horizon 8 pools to be managed by the cloud. For detailed instructions, refer to Create a Hybrid Pool Group to Accommodate Universal Broker Provisioning.
-
Set Up Entitlements: Ensure your users are properly entitled to the desktops they need to access.
-
Configure Client URLs (Optional): End users can connect using the standard Horizon Cloud URL (
cloud.omnissahorizon.com). If you prefer to use a custom URL, refer to Configuring Client Settings for setup instructions.
Once Pool Groups and entitlements are configured, the available desktops will appear in the user's Horizon Client. When a user launches a desktop or application, the Universal Broker automatically routes them to the appropriate pool based on your configured policies.
For instructions on how users can start their sessions, refer to Launch a Desktop with Horizon Client.
For a detailed set of use cases and additional overview enablement and workflow information, Omnissa Horizon Universal Broker: Unifying Resource Delivery for the Modern Enterprise in the Omnissa Community Forum.
Was this page helpful?