With Horizon Client for Windows 2603, the Aggregate Entitlements feature is generally available. Aggregate Entitlements enables administrators to link two independent Horizon pods. End users can view a unified set of application and desktop entitlements within a single Omnissa Horizon Client session.
When users authenticate to the Horizon instance, the solution aggregates virtual applications and desktops from both existing and external environments into a unified catalog, providing seamless access to resources across multiple pod deployments.
For details on this feature in Client Next, supported in Tech Preview, see the KB Article 6001366.
Prerequisites
- Users should have the same Active Directory username (SID) to log in to both environments if there are multiple domains. This can also be done if there is a one-way trust between the domains.
- The service account that will be used for the external deployment configuration should have the "Manage External Keys" privilege in Horizon.
Procedure
To enable the Aggregate Entitlements feature, follow these three main steps:
- Get the cluster GUID from the source Horizon POD.
- Configure JWT on the external Connection Server Console.
- Configure the external Deployment on the source Horizon POD.
Get the Cluster GUID from the source Horizon POD
- In the existing production Horizon Console, navigate to Settings > Global Settings > Authenticators.
- On the Authenticators tab, click on METADATA SETTINGS.
- Make a note of Cluster GUID.

Configure JWT on Horizon External Connection Server Console
-
In the External Horizon Console, navigate to Settings > Global Settings > Authenticators.
-
Click ADD > Add Horizon JWT Authenticator.
-
In the Add Horizon JWT Authenticator window, enter the following:
- Method: Manual Input or Blob Input
- Manual Input: Use this for Horizon 8 Enterprise.
- Blob Input: Use this to configure Universal Broker.
- Name: JWT Authenticator Display Name.
- Issuer: Add the Connection Server cluster GUID noted earlier.
- Description: Add a description.
- Enable for all Connection Server: Enable the toggle to apply this feature to all Connection Servers in the POD. Otherwise, disable it and select individual Connection Servers after completing the configuration.
- Service Account: This is optional. Provide the credentials for an account that can establish a trust. The account must have the "Manage External Keys" privilege. This same account is used while configuring the external deployment in the existing source Horizon Console.

- Method: Manual Input or Blob Input
Configure External Deployment
-
In the source Horizon Console, navigate to Settings > Servers > External Deployment.
-
Click ADD.
-
In the Add External Deployment window, enter the following:
- Name: Provide External Deployment Server Display Name.
- Connection Server URL: Provide the External Connection Server URL. It can also be the Load balancer FQDN.
- Unified Access Gateway URL: Provide UAG URL (if any).
- Authentication Method: Credential or Certifcate.
- Credential: Enter the credential for an account that can establish trust with the External Connection Server.
- Certificate: Requirements are the same as smart-card logon. See Create Certificate Templates Used with True SSO.
- Password If the credential is used, enter the password of the service account. If the certificate is used, enter the PFX password.
-
Click ADD to complete the configuration.

Was this page helpful?