This checklist details the necessary requirements for registering Manual Virtual Machines (VMs) to a Manual Pool.
Purpose: This checklist is for administrators registering Manual VMs into Horizon Cloud Manual Pools: Create and Manage Manual Desktop Pools.
Prerequisites
To register your Manual VMs to a Manual Pool, ensure the following are in place:
-
Active Horizon Cloud Subscription: You must have an active subscription for any Horizon Cloud supported capacity, even if your manual VMs reside in an unsupported capacity. Supported Edge types are: Microsoft Azure, Amazon WorkSpace Core and vSphere.
-
Edge and UAG Deployments: Create your Edge and UAG deployments using Horizon Cloud supported capacities.
-
Network Line of Sight:
-
Ensure direct network access (line of sight) between:
- Edge Gateway → UAG
- UAG → Manual VMs
- Manual VMs → Edge Gateway
-
Also, ensure direct network access between:
- Edge Gateway → On-premises Active Directory (AD)
- Manual VMs → On-premises Active Directory (AD)
-
-
Inbound Network Rules: Configure manual VMs inbound network security rules to allow required Blast protocol traffic by opening the necessary ports.
-
Generate an API token in Omnissa Connect: An Omnissa Connect API token having Pool Administrator role assigned is required to execute the registration script inside each manual VM. Refer to Generate API Registration Tokens in Omnissa Connect below.
-
Outbound Internet Connectivity (for VMs):
-
Manual VMs must have outbound internet connectivity to all required URLs. In addition to the VDI Ports and Protocols Requirements mentioned in each of the Edge providers Ports and Protocol Requirements pages. The following additional URLs are to be allowed:
connect.omnissa.com*.horizon.omnissa.com
-
-
Horizon Agent: Manual VMs must have the latest available Horizon Agent installed.
-
Agent Updates: You are responsible for manually updating the Horizon Agent with the latest versions and security patches on all manual VMs.
Important Note for Dedicated Manual Pools:
After creating a dedicated manual pool using VMs that were previously assigned to and used by end-users externally, you must manually assign users to each dedicated manual pool VM after creating the pool group (and before creating the entitlement). This ensures manual pool VMs are allocated to the correct, intended users. Failure to do so will result in the system falling back to its default session assignment logic, randomly assigning any available VM to any entitled user during their first desktop launch.
Connectivity Requirements
- You have an operationally active Horizon Edge deployed.
- The Horizon Edge has direct network access to where the VMs are located.
- The VMs have outbound internet connectivity to the required URLs.
- All Horizon Cloud Service port and protocol requirements for connectivity are met.
Machine Identity
- A domain is registered within Microsoft Active Directory.
- The machine identity domain is reachable from both the Horizon Edge and the VMs.
Generate an API Token in Omnissa Connect
To register manual VMs to a manual pool using the registration script, your account will need to have an API token set up in Omnissa Connect. The API token must be generated using the least privileged role of Pool Administrator. Follow the steps below to view your account roles and/or generate API tokens.
Procedure
-
From the Horizon Cloud Console, in the top right corner, click on Your Profile Name.
-
Under User Settings, select View My Profile.
This will open your Omnissa Connect Account (CSP) page. Note: If you have access to multiple Organizations, you need to switch to the right organization to continue and the generated API token works only for the selected organization.
-
In Omnissa Connect, access the Account Settings, it will open to show the Profile tab.
-
Select the My Roles tab.
-
Under Organization Roles > Service Roles > Horizon, check to be sure that the role of Pool Administrator has been added to your account. Even if you have a higher privileged role like Administrator, you must also have the Pool Administrator role.
a. If the Pool Administrator role is not listed for you, navigate to Administrator Access > Administrator > Select Your Account Name > Select Edit Roles.
b. Next, scroll down to the Specific services section and expand Horizon. Next, select the check box to add the role of Pool Administrator. Lastly, click Save.
-
Once confirmed that your account has a Pool Administrator role, select the API tokens tab. All tokens that you have created will be listed here. Note: You can revoke an individual token or ALL tokens you created in the past on this tab, at any time.
-
Select the Generate a New API token button. There is no limit to the number of tokens you can create and/or revoke.
-
Enter a unique Name for this token.
-
Select a Token TTL (Time to Live) option. It is best to select the shortest time needed to avoid compromise. Once your current VMs are registered and paired to the manual pool, there will not be a need for this token anymore and it can be revoked. If in the future you need to add more VMs, you can generate a new token at that time.
-
Scroll down to the Service Roles section and Expand: Omnissa Connect > Horizon Cloud Service>. Then select the check box by the Pool Administrator role.
-
Click the Generate button.
-
After successfully generating the secret token, your token name and specific details are shown. Make sure to COPY the secret token code and SAVE it in a safe, secure place before proceeding.
-
Once the secret token is securely saved, click the Continue button.
-
Back on the API Tokens tab, you will now see the name and details of the token you just created.
Note: You can't view the secret token again. If it was lost or compromised, you would need to revoke it and generate another secret token.
Ports and Protocol Requirements
Depending on your Edge provider, the ports and protocols will differ. See the following topic for your specific capacity provider type:
- Horizon 8 Edge: Add and Deploy a Horizon 8 Edge
- Microsoft Azure Edge: Microsoft Azure Edge Deployments
- Amazon WorkSpaces Core Edge: Amazon WorkSpaces Core Edge Deployments
- vSphere Edge Deployments: vSphere Edge Deployments
- OpenStack Edge Deployments
- Nutanix Edge Deployments: Nutanix Edge Deployments
Was this page helpful?