Skip to main content

End User Connections to Their Entitled Desktops and Remote Applications Provisioned by Horizon Cloud Pods in Microsoft Azure

These topics provide information about areas related to your end users' connections to their entitled desktops and remote applications that are provisioned by Horizon Cloud pods. Such pods are the pod-manager-based ones that are deployed by Horizon Cloud in Microsoft Azure using the console's pod deployment wizard.

When Using PCOIP URLs and a Pod with an Internal Gateway Configuration

As described in Your Horizon Cloud on Microsoft Azure Deployments, a Horizon Cloud pod in Microsoft Azure can be configured with an internal gateway configuration, using Unified Access Gateway instances. For the internal gateway type, even though Horizon Web Client (Blast protocol) configures its external URL to be your provided FQDN, the PCOIP URL uses IP addresses instead. This behavior makes for a difference between the external gateway and internal gateway types with respect to PCOIP:

  • External gateway type: the PCOIP URL is set to the public IP of the external gateway configuration's load balancer resource.
  • Internal gateway type: the PCOIP URL first attempts to resolve your provided FQDN using DNS to an IP address, and then uses that as the PCOIP URL. If the PCOIP URL cannot resolve your provided FQDN, the PCOIP URL instead uses the private IP address of the internal gateway configuration's internal load balancer resource.

Now, your network environment might be such that the internal gateway configuration's load balancer is not the first endpoint in an end-user connection attempt. As an example, you might have an additional endpoint or load balancer that you have set up to redirect to the internal gateway configuration's load balancer. In the certificate you uploaded to the internal Unified Access Gateway gateway configuration when you deployed or edited the pod, you likely have made that certificate match the FQDN or IP addresses of that first endpoint in your networking setup. You likely did that because you expect your end-user clients to access your network environment starting with that first endpoint. If your network environment matches this description, where your end-user clients first access an endpoint that is not the internal gateway configuration's load balancer as their first endpoint, you must ensure your DNS mapping provides for the PCOIP URL to match for your end-user clients to properly authenticate against your provided certificate.

Enable Time Zone Redirection for RDS Desktop and RDS-Based Application Sessions

If a farm's RDSH VM is in one time zone and the end user is in another time zone, by default, when the user connects to their RDS session-based desktop, the desktop displays time that is in the time zone of the farm's RDSH VM. You can enable the Time Zone Redirection group policy setting to make the session-based desktop display time in the local time zone. This policy setting applies to remote application sessions as well.

Prerequisites

  • Verify that the Group Policy Management feature is available on your Active Directory server.

    The steps for opening the Group Policy Management Console differ in the Windows 2012, Windows 2008, and Windows 2003 Active Directory versions. See the Windows online help for your operating system version.

  • Verify that the Horizon RDS ADMX files are added to your Active Directory. For an example of these steps, refer to the content about adding the ADMX template files to Active Directory located within the Horizon Remote Desktop Features and GPOs guide at Horizon 8 Documentation.

  • Familiarize yourself with the RDS device and resource redirection group policy settings described in the Horizon Remote Desktop Features and GPOs guide at Horizon Documentation.

Procedure

  1. On the Active Directory server, open the Group Policy Management Console.

  2. Expand your domain and Group Policy Objects.

  3. Right-click the GPO that you created for the group policy settings and select Edit.

  4. In the Group Policy Management Editor, navigate to Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection.

  5. Enable the setting Allow time zone redirection.

Multiple-Monitor Support for Desktops and Remote Applications Provided By a Horizon Cloud Pod in Microsoft Azure

This topic describes specific support for using multiple monitors with the end-user entitled resources provisioned by a Horizon Cloud pod in Microsoft Azure.

For general and extensive details about using monitors and screen resolution in the Horizon Client used by end users, see Monitors and Screen Resolution.

Note: Due to the number of variables in your end users' environments that can affect their graphical user experience — such as network conditions, bandwidth consumption, workload intensity, and so on — testing is recommended so that you can identify the usability, cost, and performance mix which best meet your specific business requirements.

The configurations in the following table are for a typical knowledge worker workload, such as a combination of office productivity applications, streaming media in a browser, and Internet use. Your experience might vary due to VM size, display protocol you are using, screen resolution, workload, and other factors.

Supported Configurations for RDSH VMs
VM TypeGraphics ByWorkloadMonitor Options
Non-GPU-backed RDSH VMMicrosoft Hyper-V display adapterBasic, not requiring advanced graphics features or HD video playbackSingle 4K display
GPU-backed NV-Series RDSH VMNVIDIA GRID GPU For driver details, see: Graphics intensive or requiring advanced graphics featuresSingle 4K display
GPU-backed NVv4-Series RDSH VMAMD GPU For driver details, see:Primarily for application rendering, such as for 3D apps.Single 4K display
Supported Configurations for VDI Desktop VMs
VM TypeGraphics ByWorkloadMonitor Options
Non-GPU-backed VDI desktop VMDisplay Adapter (installed by VMware Tools) Note: With this driver, Microsoft software rendering is used for advanced graphics features. This driver is a different driver than the ESX display driver. Basic, not requiring advanced graphics features or HD video playback Single 2560x1440 display Two 1920x1080 displays
GPU-backed NV-Series VDI desktop VMNVIDIA GRID GPU For driver details, see: Graphics intensive or requiring advanced graphics features Up to four 4K displays Note: Microsoft NV-series VMs allow use of up to four 4K displays for VDI desktops. Please see the NVIDIA GRID documentation for the specific GPU you are using to get supported resolutions and workload recommendations.
GPU-backed NVv4-Series VDI desktop VMAMD GPU For driver details, see:Primarily for application rendering, such as for 3D apps.Single 4K display Note: Based on our validation testing and the AMD Radeon MI25 specifications, a single 4K display is recommended here. Please see the AMD Radeon Instinct MI25 documentation for the specific GPU you are using to get supported resolutions and workload recommendations.

Horizon Cloud on Microsoft Azure — Support of Media Optimization for Microsoft Teams

You can use the Horizon remote experience feature for Media Optimization for Microsoft Teams with the virtual desktops and remote apps provisioned from your Horizon Cloud on Microsoft Azure deployments. As described in the Horizon Remote Desktop Features and GPOs guide, this feature provides for Teams media processing to take place on the client machine instead of in the virtual desktop.

For Horizon Cloud on Microsoft Azure deployments, use of this feature requires pod manifest 2298.0 or later and Horizon Agents Installer (HAI) version of 20.2 or later. As of August 11, 2020, you can use Horizon Clients version 2006 and later to obtain use of this feature with virtual desktops provisioned from those pods. Refer to the information in the Horizon Remote Desktop Features and GPOs guide located at Horizon 8 Documentation.

Access Desktops and Applications

After you create desktop and application assignments, end users can access desktops and applications using the Horizon Client or a browser using Horizon Web Client capabilities. If you have integrated your environment with your Omnissa Access environment, you can optionally enforce end-user access to go through that environment.

Log In to Desktops or RDS-Based Remote Applications Using the Horizon Client

When your end users connect to Horizon Cloud using the Horizon Client, they can work with their assigned desktops or remote applications.

These steps describe using Horizon Client for the first time to connect to a desktop provided by a Horizon Cloud pod.

Important: If you are assigning URL redirection to your end users, they must install their Horizon Client with the URL Content Redirection feature enabled for them to take advantage of that feature. The client must be installed using the command line to enable URL Content Redirection in the client. As a starting point to learn about this area, see these topics in the Horizon Client documentation:

Prerequisites

  • Familiarize yourself with the most up-to-date information regarding Horizon Clients. For example, compare Horizon Client interoperability with Horizon Cloud on Microsoft Azure using the Omnissa Product Interoperability Matrix. Also see the Horizon Client documentation.

  • From your organization's DNS information, obtain the fully qualified domain name (FQDN) that your organization has associated in its domain name system (DNS) for end-user connections to this pod, such as desktops.mycorp.example.com.

    For example, when the Horizon Cloud pod in Microsoft Azure is configured to use Unified Access Gateway for end-user connections, your organization has a DNS CNAME or A record that maps the FQDN that you provided in the deployment wizard to the auto-generated public FQDN of the pod's deployed load balancer. See How to Obtain the Horizon Cloud Pod Gateway's Load Balancer Information to Map in Your DNS Server for a description of this auto-generated public FQDN.

  • If you want those Horizon clients that have implemented the client retry feature to automatically retry the connection when the system has to power on the underlying desktop VM or farm RDSH VM, set the Allow Client to Wait for Powered-Off VM option to Yes in the Horizon Universal Console's Broker page. The Horizon Client for Windows and Horizon Client for Mac starting with version 4.8 and later have this feature implemented.

Procedure

  1. Start the Horizon Client.

  2. In the client, select the choices to add a new server.

  3. In the new server configuration, enter the name that was added to your DNS for end-user connections, for example, desktops.mycorp.com.

  4. Enter the credentials for your Active Directory user in the authentication dialog box.

  5. If a two-factor authentication configuration is in place, enter the two-factor authentication credentials as prompted.

  6. From the displayed list of entitled desktops and remote applications, connect to the one you want to use.

    When the underlying desktop VM or farm RDSH VM is powered off, due to any power-management schedules configured in the VDI desktop assignment or farm, the system starts powering on the VM in response to the connection request. If you are running version 4.8 or later of Horizon Client for Windows or Horizon Client for Mac and you have Allow Client to Wait for Powered-Off VM option set to Yes for your tenant environment, the client displays a message describing the connection will be made when the desktop is ready and the estimated time it might take.

  7. To configure additional options that apply when you launch the selected desktop or application, right-click the icon and make your selection.

Log In to Desktops and RDS-Based Remote Applications Using a Browser

Your users can access the resources in your Horizon Cloud environment that you have entitled to them by pointing their browser to the fully qualified domain name (FQDN) that your organization has configured for end-user connections to those resources.

These steps describe using a browser to launch a desktop provided by the pod.

Note: If integration with an Access environment is configured, end users might have to access their desktops and remote applications using that environment. See Enforce Having End Users Go Through Workspace ONE Intelligent Hub Catalog

Prerequisites

  • Familiarize yourself with the most up-to-date information regarding Horizon Web Client: Omnissa Horizon Clients documentation.

  • From your organization's DNS information, obtain the fully qualified domain name (FQDN) that your organization has associated in its domain name system (DNS) for end-user connections to this Horizon Cloud pod in Microsoft Azure, such as desktops.mycorp.example.com.

    For example, when the pod is configured to use Unified Access Gateway for end-user connections, your organization's DNS has a CNAME record that maps the FQDN configured on the gateway to the Azure load balancer's auto-generated public FQDN. See How to Obtain the Horizon Cloud Pod Gateway's Load Balancer Information to Map in Your DNS Server.

  • If you want your end users' Horizon Web Clients to retry the connection automatically when the system has to power on the underlying desktop VM or RDSH VM, set the Allow Client to Wait for Powered-Off VM option to Yes. This option is located on the Horizon Universal Console's Broker page. Horizon Web Client starting with version 4.10 has this feature implemented.

  • Verify that you have the credentials for a user that has a VDI desktop, session desktop, or remote application assignment.

Procedure

  1. Point a browser to a URL of the form https://<desktops-FQDN>, where desktops-FQDN is the fully qualified domain name that was added to your DNS for end-user connections.

    For example, if your company's DNS associated an FQDN of myDesktops.example.com, point the browser to https://myDesktops.example.com.

  2. Sign in using the credentials for a user that has a desktop assignment.

Results

Icons representing the user's assignments are displayed in the browser. The user can launch a desktop or application by clicking its icon.

Accessing Local Files with Remote Applications Using File Redirection

The file redirection feature allows users to open local files in entitled remote applications that support a given file type.

The feature is enabled in the Horizon Client when the Open local files in hosted applications option is selected.

This functionality allows users to do the following:

  • Open a local file in a remote application by double-clicking the file in the client machine or by right-clicking, selecting Open with, and choosing the remote application in the menu.

  • In the remote application, browse the complete folder where the file resides.

  • Save changes made using the remote application to the local client disk.

  • Register an entitled application as a file handler for the file types that those applications can open, or chose to open with the remote application a single time.

    When an application is set as the default handler:

    • The file's preview icon matches the entitled application's icon in the application launcher page.
    • The file type description is overridden by the remote application, if any.
    • Double-clicking a file of that type launches the Horizon Client.

Horizon Cloud Environment with Universal Broker — Enforce Having End Users Go Through Workspace ONE Intelligent Hub Catalog to Access Their Entitled Desktops and Applications <a id="enforcewsone>

These steps are applicable when your Horizon Cloud environment is configured for Universal Broker and when you have integrated your Horizon Cloud with your Access tenant. Horizon Cloud provides this feature by which you can specify that end users must go through the Workspace ONE Intelligent Hub catalog to access their pod-provisioned desktops and remote applications. Requiring end users to access their desktops through the Hub catalog prevents direct desktop access using Horizon Client or Horizon Web Client. This enforcement is useful when you want to use the two-factor authentication method that is set in your Workspace ONE tenant environment.

When your environment is configured with Universal Broker, your end users typically launch their entitled desktops using the following methods.

In the Horizon Universal Console, you can optionally configure your Horizon Cloud environment to require your end users use Workspace ONE Hub catalog only.

Prerequisites

Verify that your Horizon Cloud configured with Universal Broker and Access tenant are successfully integrated. See Horizon Cloud Environment with Universal Broker - Integrate the Tenant with Omnissa Access and Intelligent Hub Services.

Procedure

  1. In the console, navigate to Settings > Broker > Authentication.

  2. Enable the toggle Enforce Intelligent Hub and confirm your choice.

What to do next

Verify that the desktop access behaves according to your settings by trying to access a desktop using the Horizon Client or using a browser directly instead of through the Workspace ONE Hub catalog.

Horizon Cloud Environment with Single-Pod Brokering — Enforce Having End Users Go Through Omnissa Access to Access Their Entitled Desktops and Applications

These steps are applicable when your Horizon Cloud environment is configured for single-pod brokering and when you have integrated your Access environment with your pods in Microsoft Azure. Horizon Cloud provides this feature by which you can specify that end users must go through Access to access their pod-provisioned desktops and remote applications. Requiring end users to access their desktops through Access prevents direct desktop access using Horizon Client or by Horizon Web Client. This enforcement is useful when you want to use the two-factor authentication method that is set in your Access environment.

Your end users typically launch their entitled desktops using the following methods.

In the first-gen Horizon Universal Console, you can optionally configure your Horizon Cloud environment to require your end users use Access only. You can configure enforcement on users who are accessing their desktops and applications from locations outside your corporate network or on users accessing from inside your corporate network, or both. You can also configure the client to automatically redirect to Access when the enforcement is enabled.

The feature to force end-user access to Access works with the Access redirection feature in the following ways.

Force end-user access through Access settingAccess redirection settingWhat happens when the end user's client connects to Horizon Cloud to access their desktops and applications
Enabled (yes)Enabled (yes)Client is automatically redirected to Access.
Enabled (yes)Deactivated (no)Client displays a message that tells the user that they must access Horizon Cloud using Access. Automatic redirection does not occur.
Deactivated (no)Enabled (yes)Client displays the Horizon Cloud login screen for the end user to log in. Automatic redirection does not occur because forced access to Access is not enabled.
Deactivated (no)Deactivated (no)Client displays the Horizon Cloud login screen for the end user to log in. In this scenario, both forced access and the automatic redirection features are deactivated.

Prerequisites

Verify that your Horizon Cloud and Access environments are successfully integrated. See A Horizon Cloud Environment with Single-Pod Brokering — Integrating the Environment's Horizon Cloud Pods in Microsoft Azure with Omnissa Access.

Procedure

  1. In the console, navigate to Settings > Identity Management and click Configure.

  2. In the dialog box, make selections according to your organization's needs.

    OptionDescription
    Force Remote Users to AccessWhen set to Yes, users that are trying to access their desktops from locations outside of your corporate network must log in to Access and access desktops from there.
    Force Internal Users to AccessWhen set to Yes, users that are trying to access their desktops from locations within your corporate network must log in to Access and access desktops from there.
  3. Click Save to confirm the configuration to the system.

  4. Set Access redirection on the identity management configuration.

    Note: You can have Access redirection enabled for only one of the identity management URLs that are configured on the Identity Management page. If your Identity Management page lists multiple configurations with different identity management URLs, and one is associated with the toggle is set to YES, when you try to set the toggle to YES for a different identity management URL, an error message is displayed.

    1. On the Identity Management page, select the check box for the Access configuration for which you want to set redirection and click Edit to open its configuration.

    2. Set the Workspace ONE Redirection toggle to YES.

    3. Click Save.

What to do next

Verify that the desktop access behaves according to your settings by trying to access a desktop using the Horizon Client or using a browser directly instead of through Access.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…