Skip to main content

8 de octubre de 2026

Requirements Checklist for Deploying a Horizon Cloud on Google Cloud Platform Edge

The purpose of this checklist is to inform you of the required elements for creating a Horizon Cloud on Google Cloud Platform Edge deployment using GCP as your capacity provider and using the Horizon Control Plane.

Note: Horizon Cloud on Google Cloud Platform is currently available in Limited Availability (LA) mode only.

This checklist is for Horizon Cloud customer accounts that have never had a Horizon Cloud on Google Cloud Platform deployment in their tenant environment. Such tenants might be referred to as clean-slate environments or greenfield environments.

You must perform some items that follow before you deploy Horizon Cloud. You can defer some items until after the deployment is finished and running.

Ports and Protocols Requirements

Specific ports and protocols are required for deployment and ongoing operations of your Horizon Cloud environment. For details, see Port and Protocol Requirements for Horizon Cloud on Google Cloud Platform Edge.

Licensing for the Microsoft Windows Operating Systems

Horizon Cloud does not provide any guest operating system licensing required for use of Microsoft Windows operating systems. You must have valid and eligible Microsoft licenses that entitle you to create, perform workflows on, and operate the Windows-based desktop VMs and RDSH VMs that you choose to use in your Horizon Cloud environment. Windows 11 VMs must run on GCP Sole Tenant Nodes due to Microsoft licensing requirements.

GCP Account and IAM Requirements

To ensure Horizon Cloud has the correct permissions to provision resources in your GCP project, choose one of the following options.

Option A: Create a service account with the Compute Admin and IAP-secured Tunnel User roles.

Option B: Create a custom role with the required permissions. After creating the service account, download the JSON key file and note the following values — you will need them when configuring the GCP provider in Horizon Cloud:

ValueJSON Field Name
Project IDproject_id
Client IDclient_id
Client Emailclient_email
Private Key IDprivate_key_id
Private Keyprivate_key

For the full list of required custom role permissions, see the Custom Role Permissions section below.

Custom Role Permissions

If you choose Option B, the following IAM permissions are required on the custom role.

Instance Permissions

PermissionDescription
compute.instances.getGet instance details
compute.instances.createCreate instance VM
compute.instances.deleteDelete instance VM
compute.instances.useUse of instance in instance group
compute.instances.setMetadataSet metadata for VM
compute.instances.setLabelsSet labels for VM
compute.instances.listList instances in a project/zone
compute.instances.startStart instance VM
compute.instances.stopStop instance VM
compute.instances.resetReset instance VM
compute.instances.setTagsSet tags on VM instance
compute.disks.createCreate disk for VM instance

Compute Permissions

PermissionDescription
compute.zones.listList available zones
compute.machineTypes.getGet machine type details
compute.machineTypes.listList available machine types
compute.diskTypes.listList available disk types
compute.regions.getGet region details for quota validation
compute.images.listList available images
compute.images.useReadOnlyUse of image in instance creation
compute.regionOperations.getGet region operation details for async operations
compute.zoneOperations.getGet zone operation details for async operations

Network Permissions

PermissionDescription
compute.networks.listList available VPCs
compute.networks.getValidate VPC
compute.subnetworks.listList available subnets
compute.subnetworks.useUse of subnet in instance creation
compute.subnetworks.getFetch the subnet details

Instance Group Permissions

PermissionDescription
compute.instanceGroups.createCreate instance group
compute.instanceGroups.getGet instance group details
compute.instanceGroups.deleteDelete instance group
compute.instanceGroups.updateUpdate instance group to attach/detach instances
compute.instanceGroups.useUse of instance group in backend service

Load Balancer Permissions

PermissionDescription
compute.regionBackendServices.getGet Load Balancer Regional backend service details
compute.regionBackendServices.createCreate Load Balancer Regional backend service
compute.regionBackendServices.deleteDelete Load Balancer Regional backend service
compute.regionBackendServices.useUse of LB Regional backend service in forwarding rule
compute.regionBackendServices.updateUpdate Load Balancer Regional backend service
compute.regionHealthChecks.getGet Load Balancer Regional health check details
compute.regionHealthChecks.createCreate Load Balancer Regional health check
compute.regionHealthChecks.deleteDelete Load Balancer Regional health check
compute.regionHealthChecks.useReadOnlyUse of LB Regional health check in backend service
compute.forwardingRules.getGet Load Balancer forwarding rule details
compute.forwardingRules.createCreate Load Balancer forwarding rule
compute.forwardingRules.deleteDelete Load Balancer forwarding rule
compute.forwardingRules.setLabelsSet labels for Load Balancer forwarding rule

IP Address Permissions

PermissionDescription
compute.addresses.getGet details of reserved IP address
compute.addresses.createReserve external IP address
compute.addresses.createInternalReserve internal address
compute.addresses.useInternalUse reserved internal IP address
compute.addresses.deleteInternalDelete reserved internal IP address
compute.addresses.deleteDelete external IP address
compute.addresses.useUse reserved external IP address
compute.addresses.setLabelsSet labels for IP address

Sole Tenant Node Permissions

These permissions are not validated during provider creation but are required for Sole Tenant Node operations.

PermissionDescription
compute.nodeTemplates.getGet sole tenant node template details
compute.nodeTemplates.listList available sole tenant node templates
compute.nodeTemplates.createCreate sole tenant node template
compute.nodeTemplates.deleteDelete sole tenant node template
compute.nodeGroups.getGet sole tenant node group details
compute.nodeGroups.listList available sole tenant node groups
compute.nodeGroups.createCreate sole tenant node group
compute.nodeGroups.deleteDelete sole tenant node group
compute.nodeGroups.updateUpdate sole tenant node group to attach/detach nodes
compute.nodeGroups.addNodesAdd nodes to sole tenant node group
compute.nodeGroups.deleteNodesDelete nodes from sole tenant node group
compute.nodeTypes.listList available sole tenant node types
compute.nodeTypes.getGet sole tenant node type details
compute.acceleratorTypes.listList available accelerator types
compute.acceleratorTypes.getGet accelerator type details

IAP Tunnel Permissions

Required for Horizon Ops to debug Edge/UAG issues via SSH and IAP tunnel.

PermissionDescription
iap.tunnelInstances.accessViaIAPSecure access to VM via SSH + IAP tunnel

Firewall Management Permissions

Optional: If not provided, the required firewall rules must be managed by the customer admin.

PermissionDescription
compute.firewalls.createCreate firewall rules
compute.firewalls.deleteDelete firewall rules
compute.firewalls.getGet firewall rule details
compute.firewalls.listList firewall rules
compute.firewalls.updateUpdate firewall rules
compute.networks.updatePolicyUpdate network policy

Shared VPC Permissions

Service Project

PermissionDescription
compute.projects.getGet project details for Shared VPC operations

Host Project

PermissionDescription
compute.networks.listList available VPCs in the host project
compute.networks.getGet VPC details in the host project
compute.networks.useUse VPC in the host project for instance creation
compute.subnetworks.listList available subnets in the host project (region-wide)
compute.subnetworks.getGet subnet details in the host project
compute.subnetworks.useAttach edge/UAG/desktop NICs to a shared subnet in the host project

Shared VPC Host Project Firewall Permissions (Optional)

Optional: If not provided, the required firewall rules must be managed by the customer admin.

PermissionDescription
compute.firewalls.listList firewall rules in the host project
compute.firewalls.getGet firewall rule details in the host project
compute.firewalls.createCreate firewall rules in the host project
compute.firewalls.deleteDelete firewall rules in the host project
compute.firewalls.updateUpdate firewall rules in the host project
compute.networks.updatePolicyUpdate network policy in the host project

GCP APIs and Services

The following APIs must be enabled on your GCP project:

  • Compute Engine API

  • Cloud Identity-Aware Proxy API (iap.googleapis.com)

Unified Access Gateway Requirements

A Unified Access Gateway (UAG) deployment is associated with your Horizon Edge and enables secure client connections to desktops and applications. You use the Horizon Universal Console to configure Horizon Cloud with the Unified Access Gateway.

The items below are required to configure Horizon Cloud with the Unified Access Gateway.

  • An FQDN to specify during the Unified Access Gateway configuration.

  • Certificate or certificates for the Unified Access Gateway in PEM or PFX format, matching the FQDN. The certificate must only contain the Server Authentication EKU and must not include the Client Authentication EKU. For information about formatting your certificate in PEM format, see Format a PEM Certificate for Use with Unified Access Gateway.

Note: If the certificate uses CRLs or OCSP settings that refer to specific DNS names, ensure outbound internet access from the GCP environment to those DNS names is resolvable and reachable. The Unified Access Gateway software reaches out to those DNS names during configuration to check the certificate's revocation status. If those DNS names are not reachable, deployment fails.

  • A GCP machine type with a minimum of 4 vCPU and 16 GB memory for each UAG VM (supports up to 2000 sessions).
  • A minimum of 2 UAG VM instances for production deployments to ensure high availability.

User Identity and Machine Identity Requirements

Horizon Cloud makes a distinction between user identity and machine identity, and it relies on both types of identity when establishing a secure connection between a client and a remote desktop or application.

Supported Identity Configurations

Horizon Cloud requires you to register an identity configuration that consists of a user identity provider and a machine identity provider. Feature capabilities might vary depending on the particular identity providers included in the configuration.

Horizon Cloud supports the following identity configurations.

Identity ConfigurationUser Identity ProviderMachine Identity ProviderFeature Considerations
AMicrosoft Entra ID Commercial or Microsoft Entra ID GovernmentActive DirectorySupports SSO to remote desktops and applications.
BMicrosoft Entra ID Commercial or Microsoft Entra ID GovernmentMicrosoft Entra IDSupports single sign-on (SSO) to remote desktops and applications for Windows Horizon Clients. Entra ID SSO is not supported for Mac, Linux or Web clients.
CWorkspace ONE Access Cloud or Workspace ONE Access On PremisesActive DirectorySupports SSO to remote desktops and applications. Supports integration with Workspace ONE. Just-in-Time directories are not supported.
DOmnissa Identity ServiceActive DirectorySupports SSO to remote desktops and applications. Windows 365 is not currently supported with this configuration.

The following sections describe requirements for each supported user identity provider and machine identity provider.

User Identity Requirements

Horizon Cloud requires you to register a user identity provider. The service uses this identity provider to authenticate client users attempting to access remote desktops and applications.

Horizon Cloud currently supports Microsoft Entra ID (Azure Active Directory), Omnissa Identity Services and Omnissa Workspace ONE Access as user identity providers. For either option, you must connect an on-premises Active Directory to the external identity provider.

For more information about configuring the identity provider of your choice, see Setting Up Your Identity Provider.

Machine Identity Requirements

Horizon Cloud also requires you to register a machine identity provider. The service uses this identity provider to establish the machine identity of virtual machines that provide remote desktops and applications.

You must meet the following prerequisites:

On-premises Active Directory is supported and required for machine identity. The VDI desktops join this Active Directory domain, so domain controllers must be reachable from the Desktop VPC network where desktops are deployed.

You must create the following accounts in Active Directory for use with Horizon Cloud.

Domain Bind Account

Active Directory domain bind account (a standard user with read access) that has the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: / [ ] : ; | = , + * ? < >.

The account must have the following permissions:

  • List Contents
  • Read All Properties
  • Read Permissions
  • Read tokenGroupsGlobalAndUniversal (implied by Read All Properties)

Set the account password to Never Expire to ensure continued access to log in to your Horizon Cloud environment.

  • If you are familiar with the Horizon on-premises offering, the above permissions are the same set that are required for the Horizon on-premises offering's secondary credential accounts.
  • Domain bind accounts are granted the default out-of-the-box read-access-related permissions typically granted to authenticated users in a Microsoft Active Directory deployment. However, if your organization's AD administrators have chosen to lock down read-access-related permissions for regular users, you must request those AD administrators preserve the authenticated users standard defaults for the domain bind accounts you will use for Horizon Cloud.

Domain Join Account

Active Directory domain join account which can be used by the system to perform Sysprep operations and join the virtual computers to the domain. Typically a new account that you create for this express purpose.

  • The account must have the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: / [ ] : ; | = , + * ? < >. The use of white spaces in the account's user name is currently unsupported.
  • Set the account password to Never Expire to ensure continued ability for Horizon Cloud to perform the Sysprep operations and join the virtual computers to the domain.
  • The account requires the following Active Directory permissions, applied to the Computers OU, or to the OU that you will enter into the console's Domain Join UI: Read All Properties, Reset Password, Create Computer Objects, Delete Computer Objects, Write All Properties.
  • Regarding the target Organizational Unit (OU) that you plan to use for pools, the account also requires the Active Directory permission named Write All Properties on all descendant objects of that target Organizational Unit (OU).
  • In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.
  • The on-premises Active Directory domain must be running a supported AD DS domain functional level. See the Microsoft documentation for the currently supported AD DS domain functional levels and required Windows Server operating system versions.

For more details on creating and reusing domain bind and domain join accounts, see Creating Active Directory Domain Bind and Domain Join Accounts.

Sole Tenant Node Requirements

  • If you plan to deploy Windows 11 VMs, verify that your target GCP region has sufficient Sole Tenant Node quota and available capacity for your intended deployment scale before beginning deployment.

Network Requirements

The following network elements must be in place before deployment.

  • Three separate VPCs created in GCP:

    • Management VPC (/26 minimum)
    • Desktop VPC (/27 minimum)
    • DMZ VPC (/27 minimum, not required for internal-only UAG)

    Note: AD can be configured on the either Management VPC or On-premises.

  • Confirm that your internal network CIDRs do not overlap 192.168.236.0/23 (Kubernetes service CIDR) or 192.168.240.0/21 (Kubernetes pod CIDR) used inside the Edge Gateway VM.

  • Cloud NAT configured on the Management, Desktop, and DMZ VPC subnets.

  • VPC peering configured between the AD Server VPC and each of the Management, Desktop, and DMZ VPCs.

  • GCP Cloud DNS forwarding zone and peering zone configured to resolve your internal Active Directory domain from the Management and Desktop VPCs.

Pool VM Requirements

Your Google Cloud Platform must accommodate the following requirements depending on the types of pool VMs you want to provision from the deployed Horizon Edge.

  • Machine type selection for the VMs in pools — any of the Google Compute Engine machine types available in your GCP region, except for those not compatible with Horizon Cloud desktop operations.

Consider the following details when selecting a machine type.

  • To create a multi-session pool, select an image created using a multi-session operating system.
  • For production environments, scale testing recommends using machine types that have a minimum of 2 vCPUs or larger.
  • See the GCP Compute Engine documentation to learn about the availability and compatibility of different Google Compute Engine machine types and sizes with Horizon Cloud for standard Windows Server VMs.
  • For Windows 11 licensing compliance, you must use GCP Sole-Tenant Nodes. Sole-Tenant Nodes ensure dedicated physical servers and help meet Microsoft licensing requirements for Windows 11 single-session desktops. The N-series node family is recommended for optimal performance and Windows 11 compatibility.

Horizon Client and Horizon Web Client Requirements

Ensure that your end users use a supported client version to access their service-provided resources. For related information, see Horizon Cloud Release Notes.

¿Le resultó útil esta página?

Enviar comentarios sobre este tema

¿Le resultó útil este tema?

No incluya información personal ni confidencial.

Generando el enlace…