Skip to main content

September 2, 2026

Requirements Checklist for Deploying a vSphere Edge

The purpose of this checklist is to inform you of the required elements for doing a vSphere Edge deployment using the Horizon Control Plane.

Checklist Purpose

This checklist is for Horizon Cloud customer accounts that have never had a Horizon Cloud on vSphere deployment in their tenant environment. Such tenants might be referred to as clean-slate environments or greenfield environments.

You must perform some items that follow before you deploy Horizon Cloud. You can defer some items until after the deployment is finished and running.

Machine Identity Requirements

On-prem Active Directory is supported and required for machine identity. The VDI desktops join the Active Directory domain. The domain controllers must be reachable from the network where the desktops are to be deployed.

Create a primary domain join account and auxiliary domain join accounts, being aware of the following considerations:

  • The Active Directory domain join account is used by the system to perform Sysprep operations and to join computers to the domain.
  • Set the account password to Never Expire.
  • The account requires the following Active Directory permissions: Read All Properties, Reset Password, Create Computer Objects, Delete Computer Objects, and Write All Properties.

The preparatory information that follows outlines the requirements for the machine identity provider that you choose to use in your identity configuration. Horizon Cloud supports Microsoft Entra ID and Active Directory as providers of machine identity.

  • Active Directory

    When deploying vSphere Edges alone, you need an on-premises Active Directory server. However, the following points apply when you plan to use a Microsoft Azure Edge and a vSphere Edge in the same deployment:

    Active Directory server with line-of-sight to the Horizon Edge Gateway instances and desktop subnets.

    • An on-premises Active Directory server connected via VPN/Express Route
    • An Active Directory server located in Microsoft Azure
    If you plan to connect your Active Directory using LDAPS, gather PEM-encoded root and intermediate CA certificates for your Active Directory domain. When you use the Horizon Universal Console to set up your Active Directory Domain, you are prompted at that time to upload the PEM-encoded root and intermediate CA certificates.
    Supported Microsoft Windows Active Directory Domain Services (AD DS) domain functional levels.
    • Windows Server 2016
    • Windows Server 2012 R2
    • Windows Server 2012
    Supported Microsoft Windows Active Directory Domain Services (AD DS) OS Versions.
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
    • Windows Server 2012 R
    • Domain Bind Account

      Active Directory domain bind account (a standard user with read access) that has the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >.

      The account must have the following permissions:

      • List Contents
      • Read All Properties
      • Read Permissions
      • Read tokenGroupsGlobalAndUniversal (implied by Read All Properties)

      Set the account password to Never Expire to ensure continued access to log in to your Horizon Cloud environment.

      • If you are familiar with the Horizon on-premises offering, the above permissions are the same set that are required for the Horizon on-premises offering's secondary credential accounts.
      • Domain bind accounts are granted the default out-of-the-box read-access-related permissions typically granted to authenticated users in a Microsoft Active Directory deployment. However, if your organization's AD administrators have chosen to lock down read-access-related permissions for regular users, you must request those AD administrators preserve the authenticated users standard defaults for the domain bind accounts you will use for Horizon Cloud.
    • Auxiliary Domain Bind Account

      Must be separate from the main domain bind account. The UI will prevent re-using the same account in both fields. Active Directory domain bind account (a standard user with read access) that has the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >. The account must have the following permissions:
      • List Contents
      • Read All Properties
      • Read Permissions
      • Read tokenGroupsGlobalAndUniversal (implied by Read All Properties)
      Set the account password to Never Expire to ensure continued access to log in to your Horizon Cloud environment.
      • If you are familiar with the Horizon on-premises offering, the above permissions are the same set that are required for the Horizon on-premises offering's secondary credential accounts.
      • Domain bind accounts are granted the default out-of-the-box read-access-related permissions typically granted to authenticated users in a Microsoft Active Directory deployment. However, if your organization's AD administrators have chosen to lock down read-access-related permissions for regular users, you must request those AD administrators preserve the authenticated users standard defaults for the domain bind accounts you will use for Horizon Cloud.
    • Domain Join Account

      Active Directory domain join account which can be used by the system to perform Sysprep operations and join the virtual computers to the domain. Typically a new account that you create for this express purpose. (A domain join user account) The account must have the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >. The use of white spaces in the account's user name is currently unsupported. Set the account password to Never Expire to ensure continued ability for Horizon Cloud to perform the Sysprep operations and join the virtual computers to the domain. This account requires the following Active Directory permissions, applied to the Computers OU, or to the OU that you will enter into the console's Domain Join UI.
      • Read All Properties - this object only
      • Create Computer Objects - this object and all descendant objects
      • Delete Computer Objects - this object and all descendant objects
      • Write All Properties - Descendant Computer objects
      • Reset Password - Descendant Computer objects
      Regarding the target Organizational Unit (OU) that you plan to use for pools, this account also requires the Active Directory permission named Write All Properties on all descendant objects of that target Organizational Unit (OU).

      For more details on creating and reusing domain join accounts, see Creating Active Directory Domain Bind and Domain Join Accounts.


      In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.

    • Optional Auxiliary Domain Join Account

      Active Directory domain join account which can be used by the system to perform Sysprep operations and join the virtual computers to the domain. Typically, a new account that you create for this express purpose (A domain join user account).

      The account must have the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >.

      The use of white spaces in the account's user name is currently unsupported.

      Set the account password to Never Expire to ensure continued ability for Horizon Cloud to perform the Sysprep operations and join the virtual computers to the domain.

      This account requires the following Active Directory permissions, applied to the Computers OU, or to the OU that you will enter into the console's Domain Join UI.
      • Read All Properties - this object only
      • Create Computer Objects - this object and all descendant objects
      • Delete Computer Objects - this object and all descendant objects
      • Write All Properties - Descendant Computer objects
      • Reset Password - Descendant Computer objects
      Regarding the target Organizational Unit (OU) that you plan to use for pools, this account also requires the Active Directory permission named Write All Properties on all descendant objects of that target Organizational Unit (OU).

      In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.
    • Active Directory organizational unit (OU) or units (OUs) for virtual desktops and RDS session-based desktops or published applications or both.

      In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.

    User Identity Requirements

    Horizon Cloud relies on an external identity provider and currently supports Microsoft Entra ID (Azure Active Directory) and Omnissa Workspace ONE Access. The identity provider that you configure with Horizon Cloud performs the authentication required when users attempt to access their desktops.

    For either Microsoft Entra ID or Workspace ONE Access, you must connect an on-premises Active Directory to the external identity provider.

    For needed setup information, see Setting Up Your Identity Provider.

    vCenter Requirements

    Horizon Cloud uses an All-In (single/common) SDDC model and does not require a separate vCenter for the management workload. vCenter requirements are as follows for vSphere or SDDC:

      • A vCenter instance with administrator credentials for VM CRUD operations (vSphere 8.0 or newer). You must enable all privileges under the vSphere Tagging privilege group. For the minimum permissions required for the credentials, see Configure a vCenter Server User for Horizon Cloud.
    • DRS and HA enabled on the cluster that is going to be used. You must enable the vSphere-specific feature CBRC on all hosts that are part of the cluster.

    • CBRC to be enabled on all the hosts that are part of the cluster.

    • At least one datacenter, as below:

      • At least one cluster with a minimum of 3 ESXi hosts. The cluster should be directly under the Datacenter folder and not inside a Host and Cluster folder.

      • At least one Datastore (VSAN or VMFS) identified with IOPs and having capacity for hosting a Horizon Edge, UAGs, and desktop VMs.

    • Virtual machine folders for deploying the Management VMs and Desktop VMs.

    • Create the necessary resource pools for deploying the Management VMs and Desktop VMs. A minimum of one set for each tenant organization is recommended.

    • Create the necessary virtual machine folders for deploying the Management VMs and Desktop VMs. A minimum of one set for each tenant organization is recommended.

    Network Requirements

    The following networking prerequisites are required. The three networks (DMZ, Management, and Desktop) and their port group each need static or reserved IPs on a corresponding VLAN. The minimum requirement is /30. There is a minimum of one set for each tenant organization and one set for your partner organization.

    • DMZ Network

      • Port group on which the DMZ network interface of the UAG will be attached. This must be reachable from the network that end users connect from.
      • The Static IP Range minimum requirement is 2 consecutive IPs - for example, 10.202.155.30-10.202.155.39 - is required to support UAG cluster growth to 10.
      • Advanced UAG: Must be Static IP range equal in size to the other 2 networks. Up to 10 IPs are allowed.
    • Management Network

      • Port group on which the Management network interface of the UAG is attached. This is also the port group on which the Edge VM will be deployed.
      • The Static IP range minimum requirement is 2 consecutive IPs - for example, 172.20.241.30-172.202.155.39 - is required to support UAG cluster growth to 10.
      • Advanced UAG: Must be Static IP range equal in size to the other 2 networks. Up to 10 IPs are allowed.
    • Desktop Network

      • PortGroup on which the Desktop network interface of the UAG is attached. This is the port group on which the desktop VMs are deployed. The desktop VMs require reachability to the Edge VM and the Active Directory infrastructure.
      • The Static IP range minimum requirement is 2 consecutive IPs - for example, 192.168.240.30-192.168.240.39 - is required to support UAG cluster growth to 10.
      • Advanced UAG: Must be Static IP range equal in size to the other 2 networks. Up to 10 IPs are are allowed.

    You also need to meet the following networking prerequisites:

    • A static IP from the identified Management network for the Edge VM and with a resolvable FQDN, (the A record in DNS infrastructure) so that the desktop VMs can reach the Edge VM using FQDN. You'll need a minimum of one for each tenant organization and one for your partner organization.

    • A DNS entry created for the UAG FQDN, which resolves to the load balancer VIP in the event of a multiple UAG deployment. You'll need one for each UAG deployment for each tenant organization.

    • Ensure that all required ports and protocols listed in Port and Protocol Requirements for Deploying a vSphere Edge are available in the folder that is shared with you and that they are properly allowlisted as described in the Getting Started with Horizon Cloud product documentation.

    For related information about networking requirements, see Configure Network Settings for vSphere Edge Deployments.

    Ports and Protocols Requirements

    Specific ports and protocols are required for deployment and ongoing operations of your Horizon Cloud environment. See Port and Protocol Requirements for Deploying a vSphere Edge.

    Certificate Requirements

    Certificate requirements are as follows:

    • Certificate or certificates for Unified Access Gateway (UAG) in PEM or PFX format matching the FQDN.

    • A self-signed SSL certificate. You can create a self-signed SSL certificate by using OpenSSL. Example scripts are provide below.

    Example: generate CSR and KEY

    openssl req -new -newkey rsa:2048 -nodes -keyout uag.key -out uag.csr

    Example: generate PEM and self-sign with KEY

    openssl x509 -req -sha256 -days 365 -in uag.csr -signkey uag.key -out uag.pem

    Example: combine into PEM

    cat uag.pem uag.key > uag_cert.pem

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…