Skip to main content

November 20, 2025

Omnissa Horizon 8 Release Notes

Horizon 8 2503 | 15 APR 2025

With Horizon 8, IT departments can run remote desktops and applications in the data center and deliver these desktops and applications to employees. End users gain a familiar, personalized environment accessible from any number of devices, anywhere within the enterprise or home. Administrators gain control, efficiency and security by centralizing data in the data center.

Upgrading Changes

For upgrades to Horizon 8 2503, review these important considerations:

  • If you are running 2312.2 or a later version of 2312.x, please do not upgrade to 2503. Your upgrade path will be the follow-on maintenance version of 2503, i.e. 2503.1.

  • Beginning with the Horizon 8 2412 release, there is a new licensing module for term and perpetual licenses. Review the License Activation section in these release notes for details.

  • It is very important for you to thoroughly review KB 6000681 before starting your Connection Server upgrade. To ensure compatibility with existing system components, third-party integrations, and automated workflows, follow the recommendations outlined in that KB 6000681, and in Upgrading to Omnissa Horizon 8 2412 and Later.

  • Omnissa recommends that you validate the upgrade in a UAT environment before deploying it to your production environment.

Important Notes

  • Horizon 8 2503 is not supported with vSphere 6.5 or vSphere 6.7, which are both past the end of General Support. Horizon 8 2503 Instant Clones are incompatible with vSphere 6.5 and vSphere 6.7 so you must upgrade to vSphere 7.0 or later before upgrading to Horizon 8 2503 if you are using Instant Clones.

  • Microsoft security update (KB 5014754) will impact customers using certificate-based authentication to Horizon 8, such as smartcard authentication. Horizon 8 True SSO is not impacted by this security update. If you have applied this update to your Windows Domain Controllers but have not mapped certificates to one of the strong mapping types described in the Microsoft KB, then users will be denied authentication after Full Enforcement mode is activated by Microsoft in a future Windows Update. See the above KB for further details, including the expected Full Enforcement mode date. To address this issue, Horizon 8 2309 introduced the ability for administrators to configure strong certificate mappings from the Horizon console. If you are using certificate-based authentication, upgrade to Horizon 8 2309 or later in order to configure certificate mappings. See KB 91595 for details.

  • Horizon Agent no longer supports Windows Server 2012 R2 within a guest OS whether it be for new or existing deployments. Also starting with Horizon 8 2312, the use of Windows Server 2012 R2 is no longer supported for Horizon Connection Server and Horizon Enrollment Server deployments. Please use Windows Server 2016 or later. See https://learn.microsoft.com/en-us/lifecycle/announcements/windows-server-2012-r2-end-of-support for details.

  • Microsoft released security updates KB5008383 and KB5020276. While Omnissa has determined that KB5008383 does not impact Horizon Full Clones and Instant Clones, KB 5020276 does if you have selected “Allow Reuse of Existing Computer Accounts”. See KB 92214 for details.

What's New

Horizon 8 version 2503 is an Extended Service Branch (ESB). It includes the following new features and enhancements.

License Activation

A new licensing module for term and perpetual licenses was introduced in the 2412 release. While existing license keys remain supported, we strongly recommend activating Horizon 8 2503 with a new Omnissa license if you are using a term or perpetual license.

  • The new Omnissa Horizon license key is available through the Customer Connect portal. A banner notification will prompt you to upgrade to the new Omnissa license, and you will have 60 days to complete this transition. Failure to update the license keys within this period will result in Horizon Console entering restricted mode. See Enabling Horizon 8 for Subscription Licenses and Horizon Control Plane Services in the Horizon 8 Installation and Upgrade guide.

  • Additionally, starting with this release, the 15-day grace period for subscription licenses has been removed. If you activate a subscription license in Horizon 8 without Horizon Edge, you must reactivate it every 90 days to maintain full functionality. However, licenses will be automatically activated if you are using Horizon Edge.

  • The Licensing and Usage screen in Horizon Console includes a field for the Subscription End Date. When data becomes available from the Horizon Control Plane, this field will display the end date of the subscription license. Otherwise, this field will display "N/A".

Horizon Connection Server

  • The ADAM instance application partition name has been updated with “horizon” to ensure consistency for brownfield customers. For greenfield or new customers, the partition name will default to “horizon.”

    New Partition Name:

    • Local LDAP: dc=vdi,dc=horizon,dc=internal
    • Global LDAP: dc=vdiglobal,dc=horizon,dc=internal

    To maintain compatibility, the Connection Server installer allows selecting the old or new partition in Horizon 2412 or lower. From Horizon 2503, both partition types are supported.

  • To assist brownfield customers with the transition to the updated application partition names, Omnissa provides a migration script that updates the partition names while ensuring data integrity. After upgrading all pods to Horizon 2503, customers can run the script to permanently update their deployments to the new application partition naming convention, ensuring a seamless migration without data loss. See KB 6000797 for details and for the migration script.

  • Unmanaged Mode Support and new rebranded 2503 ADAM DB Partition - The 2503 Server supports both old ADAM DB and new ADAM partitions. Due to the "Failed to update LDAP..." error encountered when registering the Old Horizon 8 Agent with a new Server, unmanaged Horizon 8 Agents (versions 2412 and earlier) will not work with the 2503 Server having the new ADAM DB partition. For more information on this and other backward compatibility considerations, see KB 6000681.

    • Workarounds: To use the 2412 Agent (or earlier versions) with a 2503 (or later) Horizon Server, ensure the server is installed with the old Horizon Directory Services partition. If you wish to use a 2503 (or later) Horizon Server with the newer Directory Services partition, make sure the Agent is first upgraded to 2503 (or later) before connecting it to the Connection Server. Note: These considerations only apply if the Agent is installed in Unmanaged mode. In regular mode, older Horizon Agents will work with the 2503 Server that has the new ADAM DB partition.
  • Horizon 8 now supports Horizon Connection Server on Microsoft Windows Server 2025 for greenfield deployments. Enhancements include Enrollment Server support, True SSO with Microsoft CA, Active Directory (2025 domain functional level), and Event Database support with a compatible Microsoft SQL version. For operating system support details, see KB 78652.

  • The Agent Auto-Update feature is now available under the Horizon Term license.

  • The Horizon Lifecycle Management APIs now support SMB file shares for registering Horizon Connection Server packages, removing the requirement for creating and maintaining a valid web server.

  • You can monitor Connection Server health, utilization, session details, and errors/warnings for a specific POD from the Horizon Console. Navigate to Monitor/Infrastructure to view details and ensure VM uptime by addressing issues promptly.

  • Horizon Server now includes ChaCha cipher suites in the default configuration for non-FIPS mode to enhance security and performance, especially on devices without AES hardware acceleration. Added cipher suites are:

    • TLS 1.3: TLS_CHACHA20_POLY1305_SHA256
    • TLS 1.2 & TLS 1.3: TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
    These cipher suites offer strong encryption and improved efficiency. No action is required unless using a custom TLS configuration. FIPS mode remains unaffected.

Horizon Console

  • The Horizon 2503 CS server now supports IDP (Identity Provider) authentication for users, enhancing security and access control. Administrators can enable the IDP Should Authenticate User Every Time setting to require IDP re-authentication, even if an active SAML session exists. By default, users will not need to re-authenticate if a session is already active. Enabling this option ensures stricter authentication policies, reducing unauthorized access risks. This feature improves compliance and security for organizations requiring frequent user verification. Configure this setting in the Authentication preferences to tailor IDP behavior to your security needs.

Virtual Desktops and Applications

  • Network Access Policy is now configurable at the pool level, providing enhanced flexibility to secure access based on user location and the sensitivity of the application. Administrators can set specific network access policies (External, Internal, or Both) for critical applications. For instance, a doctor may have full access to all business-critical applications while on the hospital network, but access to sensitive apps like VDI or RDSH may be restricted when outside the corporate network.

  • The session recording feature now has the same lifetime as the Blast remoting session it is recording. Previously, recording was terminated early if the primary Blast session had a brief network outage, even if the Horizon Client succeeded to automatically reconnect to the Horizon Agent within the two-minute network recovery period.

  • Horizon Agent simplifies authentication for Horizon Physical PCs by removing the requirement for Remote Desktop Users group membership. To enable this feature and for more information, see Manual Pool of Registered Physical Machines.

Horizon Agent for Windows

  • A new TCP bandwidth estimator now further reduces the bandwidth consumed by the Blast protocol. Available for the Windows Agent and Client starting with version 2412, this feature is now available in 2503 for these clients: Horizon Client for Linux, Horizon Client for Mac, Horizon Client for Android and Horizon Client for iOS.

Remote Desktop Features

  • Screen Sharing Support for Chrome and Edge C on Linux Browser Content Redirection: Browser Content Redirection (BCR) now supports screen-sharing capabilities on Linux (CentOS, RHEL, and Ubuntu) clients using Chrome and Edge C. This enhancement allows you to seamlessly share your screen during web conferencing sessions on UC applications like Microsoft Teams, Zoom, and Cisco Webex, providing a smoother experience for media-intensive applications.

  • New ViewClient_Broker_AuthMethod registry value: Specifies the authentication method used to connect to the broker.
    Possible values include:

    • Windows-password
    • Cert-auth
    • GSSAPI (LACU and WHFB)
    • SecurID
    • Unauthenticated
    • SAML
    • JWT
    • RADIUS

Horizon 8 and Amazon WorkSpaces Core

  • Omnissa Access is now supported with Horizon 8 on Amazon WorkSpaces Core. This requires Omnissa Access connector 24.12 or later.

  • Horizon 8 automated pools now support Amazon WorkSpaces Core graphics G4DN (NVIDIA T4) instances. Graphics.g4dn is ideal for customers seeking low-cost GPU-enabled virtual desktops and the GraphicsPro.g4dn enables high-end media production, or GIS data processing. See more at the Amazon page EC2 G4dn family.

Windows OS Optimization Tool for Omnissa Horizon

Horizon 8 SDKs

  • WebRTC SDK:
  • The WebRTC SDK now supports scenarios where multiple calls can be taken on each headset without putting one call on hold.
  • Web based Unified Communications applications can now develop optimized plugins for Horizon that would allow media offload using the WebRTC SDK

Please note that the WebRTC SDK is intended for unified communications application providers through the Omnissa Partner Program.

Horizon 8 API

For the latest set of Horizon 8 APIs, see Omnissa Developer Portal and navigate to the current release in the drop down. Click on the Documentation tab for more details and examples on how to use the API.

Horizon Edge and Horizon Cloud Connector

Applicable to customers with Horizon Universal Subscription, Horizon Enterprise Plus Subscription, Horizon Standard Plus Subscription, Horizon Apps Universal Subscription, or Horizon Apps Standard Subscription.

The Horizon Edge is a required component for connecting Horizon 8 to Horizon Control Plane next-gen for subscription licensing enablement and additional control plane SaaS services.

The Horizon Cloud Connector virtual appliance is a required component for connecting Horizon 8 to the first-gen Horizon Control Plane for subscription licensing enablement and additional control plane services.

Horizon 8 Deployed on Public Cloud SDDCs

For a list of Horizon 8 features supported on Azure Omnissa Solution (AVS), see KB 80850.

For a list of Horizon 8 features supported on VMware Cloud on AWS, see KB 58539.

For a list of Horizon 8 features supported on Google Cloud VMware Engine (GCVE), see KB 81922.

For a list of Horizon 8 features supported on Oracle Cloud Omnissa Solution, see KB 88202.

For a list of Horizon 8 features supported on Alibaba Cloud Omnissa Service (ACVS), see KB 92140.

Before You Begin

  • You cannot mix IPv4 and IPv6 pods in a single CPA federation. They have to all be IPv4 or IPv6.

  • Microsoft Internet Explorer is no longer supported for Omnissa Horizon Console from Horizon 2111 onward. As Horizon Console is migrating to clarity widgets which do not support Internet Explorer, we have removed Internet Explorer from the list of supported browsers for Horizon Console.

  • The Horizon Virtualization Pack for Skype for Business is no longer supported in this release. When using this release of Horizon Client with Horizon Agent 2212 or earlier, the Virtualization Pack for Skype for Business will continue to run in fallback mode.

  • Important note about installing VMware Tools: If you plan to install a version of VMware Tools downloaded from the product downloads page, rather than the default version provided with vSphere, make sure that the VMware Tools version is supported. To determine which VMware Tools versions are supported, go to the Omnissa Product Interoperability Matrix. (Supported versions: 11.1.0, 11.0.6, 10.3.22, 10.3.21). There are also performance issues with the 11.x versions of VMware Tools. For more information, see KB 78434.

  • Downgrading Connection Server instances is not supported. To revert to a previous version after an upgrade, restore from backup. For more information, see Create a Replicated Group After Reverting Connection Server to a Snapshot.

  • It is possible that the ordering of cipher suites can be enforced by Connection Server. For more information, see Horizon Security.

  • Connection Server must be able to communicate on port 32111 with other Connection Servers in the same pod. If this traffic is blocked during installation or upgrade, installation will not succeed.

  • TLS handshakes on port 443 must complete within 10 seconds, or within 100 seconds if smart card authentication is enabled. In previous releases of Horizon, TLS handshakes on port 443 were allowed 100 seconds to complete in all situations. You can adjust the time for TLS handshakes on port 443 by setting the configuration property handshakeLifetime. Optionally, the client that is responsible for an over-running TLS handshake can be automatically added to a blacklist. New connections from blacklisted clients are delayed for a configurable period before being processed so that connections from other clients take priority. You can enable this feature by setting the configuration property secureHandshakeDelay. For more information about setting configuration properties, see Horizon Security.

  • When you deploy an instant clone as a RDS host, do not reboot the RDS host directly from within the Windows Server OS. Instead, refresh the instant clone VM using the push image workflow.

  • In Horizon 8, internal validation checks determine if the instant clone and internal template have valid IP addresses and a network connection. If a virtual machine has a NIC that cannot be assigned an IP address during provisioning, instant-clone provisioning fails.

    The forwarding rules for HTTP requests received by Connection Server instances have changed at this release. If you have defined custom frontMapping entries in locked.properties , you should remove them before upgrading. If you wish to disallow administrator connections to certain Connection Server instances, then instead of defining custom frontMapping entries, add this entry to locked.properties :

    frontServiceWhitelist = tunnel|ajp:broker|ajp:portal|ajp:misc|moved:*|file:docroot

  • In Horizon 8, the HorizonDbChk tool will not have access to vCenter credentials and will prompt for this information when needed.

  • Microsoft Windows Server requires a dynamic range of ports to be open between all Connection Servers in the Horizon 8 environment. These ports are required by Microsoft Windows for the normal operation of Remote Procedure Call (RPC) and Active Directory replication. For more information about the dynamic range of ports, see the Microsoft Windows Server documentation.

  • Screen DMA is disabled by default in virtual machines that are created in vSphere 6.0 and later. Horizon 8 requires screen DMA to be enabled. If screen DMA is disabled, users see a black screen when they connect to the remote desktop. When Horizon 8 provisions a desktop pool, it automatically enables screen DMA for all vCenter Server-managed virtual machines in the pool. However, if Horizon Agent is installed in a virtual machine in unmanaged mode (VDM_VC_MANAGED_AGENT=0), screen DMA is not enabled. For information about manually enabling screen DMA, see KB 2144475.

  • To use View Storage Accelerator in a vSphere environment, a desktop virtual machine must be 512GB or smaller. View Storage Accelerator is disabled on virtual machines that are larger than 512GB. Virtual machine size is defined by the total VMDK capacity. For example, one VMDK file might be 512GB or a set of VMDK files might total 512GB. This requirement also applies to virtual machines that were created in an earlier vSphere release and upgraded to vSphere 5.5.

  • The Global Policy, Multimedia redirection (MMR), defaults to Deny. To use MMR, you must open Horizon Console, edit Global Policies, and explicitly set this value to Allow. To control access to MMR, you can enable or disable the Multimedia redirection (MMR) policy globally or for an individual pool or user. Multimedia Redirection (MMR) data is sent across the network without application-based encryption and might contain sensitive data, depending on the content being redirected. To ensure that this data cannot be monitored on the network, use MMR only on a secure network.

  • The USB Redirection setup option in the Horizon Agent installer is deselected by default. You must select this option to install the USB redirection feature. For guidance on using USB redirection securely, see Deploying USB Devices in a Secure Horizon Environment.

  • For information on security considerations and disallowing inter-virtual machine transparent page sharing, see KB 2080735.

  • If a PCoIP Secure Gateway (PSG) has been deployed for PCoIP connections, zero client firmware must be version 4.0 or later.

  • RC4, SSLv3, TLSv1.0 and TLSv1.1 are disabled by default in Horizon 8 components, in accordance with RFC 7465, "Prohibiting RC4 Cipher Suites," RFC 7568, "Deprecating Secure Sockets Layer Version 3.0," PCI-DSS 3.1, "Payment Card Industry (PCI) Data Security Standard", and SP800-52r1, "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations." If you need to re-enable RC4, SSLv3, TLSv1.0 or TLSv1.1 on a Connection Server or Horizon Agent machine, see Older Protocols and Ciphers Deactivated in Horizon.

  • Horizon 8 uses version m86 of Microsoft WebRTC source code.

  • For best practices on using Carbon Black with Horizon 8, see KB 95512.

  • Horizon 8 supports vSAN 8 Express Storage Architecture (ESA) for both full and instant clones. For more information on vSAN 8 ESA, see https://techzone.omnissa.com.

  • Horizon 8 supports a maximum of 500 virtual machines per ESXi host when using vSAN 8 ESA datastore. The achievable maximum depends on the workload and specifics of the hardware. For information on all Horizon configuration maximums, see VMware Configuration Maximums.

  • Cross-origin resource sharing is enabled by default. If you experience connection issues from Horizon Web Client, you might need to add the connection URL to the known origins list. For more information, see KB 85801.

Upgrade

Check the Omnissa Product Interoperability Matrix before upgrading your Horizon deployment. Note the following guidance:

  • You can only upgrade to a version with a release date later than your current deployment.

  • When upgrading from a non-ESB version to an ESB version, the target ESB version must be later that your current non-ESB release. For example, you cannot upgrade from Horizon 8 2203 (non-ESB) to Horizon 8 2111.1 (ESB) even though 2111.1 was released after 2203 (or you will lose features). You can only upgrade to Horizon 8 2212 or later versions.

  • Important: Please allow for extra time and preparation when you upgrade from a VMware-branded Horizon version to an Omnissa-branded Horizon version. For more details, see KB 6000681 and Upgrading to Omnissa Horizon 8 2412 and Later.

Compatibility Notes

The table below contains specific compatibility information as well as links to information located elsewhere.

TopicCompatibility Information or Link
Horizon Client
Horizon Client with Windows 10 and 11https://kb.omnissa.com/s/article/58096
Horizon Agent
Horizon Agent with Windows 10 and 11 - guest operating systems on single-user machines and RDS hostshttps://kb.omnissa.com/s/article/78714
Horizon Agent with OSs other than Windows 10 and 11 - guest operating systems on single-user machines and RDS hostshttps://kb.omnissa.com/s/article/78715
Horizon with Windows 10 - update or upgrade requirementshttps://kb.omnissa.com/s/article/2148176
Horizon Agent with Linux guest operating systemsSystem Requirements for Horizon Agent for Linux

https://kb.omnissa.com/s/article/87277
Horizon Server
Horizon with Operating Systems, MSFT Active Directory Domain Functional Levels, and Events Databaseshttps://kb.omnissa.com/s/article/78652
Horizon Software Interoperability
Horizon 8 2503 interoperability with Omnissa productsOmnissa Product Interoperability Matrix - Horizon 8 2503
Horizon 8 2503 with third-party productsOmnissa Product Interoperability Matrix - Horizon 8 2503 - 3rd Party
Horizon Hardware Compatibility
Horizon with third-party peripheralsOmnissa Validated Peripherals
Horizon with NVIDIA GPU cardshttps://docs.nvidia.com/grid/15.0/product-support-matrix/index.html

Resolved Issues

The list below indicates major issues resolved in this release. The number provided before each resolved issue refers to the Omnissa internal issues tracking system.

  • HZN-2469, HZN-4504, HZN-4070, HZN-2468 (and inter-related issues): Unable to remove local entitlements when user session is active and displays error "entity not found" ("unable to find entity").

  • HZN-2543: For any entitled user who is already deleted from Active Directory: When their entitlement is removed, a success message is displayed, but the entitlement remains intact

  • HZN-2654: A warning icon was incorrectly displayed next to entitled pools in the Users and Groups > User details > Desktop Entitlements datagrid

  • HZN-2865: Logging of events to the syslog server is delayed and the delay worsens with increased load on the CS

  • HZN-3272: Running the PowerShell script “Get-Horizon_Pool_Used_VM_Policy_RestAPI” fails while invoking Get REST API for desktop pool V8

  • HZN-3363: SAML metadata containing non-ASCII characters causes instability in the CS tracker JMS communication leading to connection server outage and UTFDataFormatException is seen in logs

  • HZN-3371: Horizon client shows generic 'published app' icons instead of the correct ones

  • HZN-3419: Customers were getting an LDAP exception when trying to run any of the viewdbchk commands i.e., horizondbchk command now after rebranding

  • HZN-3423: Network label information is not shown for manual pool and logs show ”Could not get network label for target VM"

  • HZN-3511: Instant clone VMs are sometimes stuck in MAINTENANCE state during the resync operation after user session logoff

  • HZN-3888: Attempts to modify published application icons in Horizon Console result in the error "Requested Icon with requested ID was not found," blocking icon updates

  • HZN-3911: Users were getting “An internal server error occurred" when trying to unassign users to VDI's

  • HZN-3948: Full clone rebuild fails when initiated simultaneously from two CS and logs shows message -”Pending operations as no additional pool managers found"

  • HZN-4162: The options to add new desktop pools and perform maintenance operations on existing pools were incorrectly disabled, despite a valid subscription license being in use.

  • HZN-4163: The options to add new desktop pools and perform maintenance operations on existing pools were incorrectly disabled, despite a valid subscription license being in use

Known Issues

The numbers included before the known issues refer to the issues logged in the Omnissa internal issue tracking system.

Before upgrading to this release, please review the information in KB 6000681 and Upgrading to Omnissa Horizon 8 2412 and Later.

Horizon Connection Server

  • VCART-2725: Users' default network printer set with DEM sometimes does not persist between sessions

    Workaround: Upgrade to 2503.1.

  • VCART-6058: Intermittent printing issues may occur due to hangs in the spoolsv.exe process on RDSH servers, requiring a restart of the Print Spooler service

    Workaround: Upgrade to 2503.1.

  • VCART-6721: Login to the Linux VDI desktop may face unexpected delays after upgrading from Horizon Linux Agent 2212 due to SSO misconfiguration

    Workaround: Upgrade to 2503.1.

  • VCART-6976: Microsoft Edge, Chrome, and some internal apps in the customer's environment do not launch with HAI (25.1.0) when Scanner and Serial Port Redirection is enabled

    Workaround: Upgrade to 2503.1.

  • HZN-6390: Helpdesk Admins are currently unable to perform the "End Process" and "End Application" actions for user sessions within the Horizon Admin Console

    Workaround: Submit a request for a hot patch or upgrade to Horizon version 2506 or later, where this issue has been resolved.

  • HZN-4309: Users are experiencing VDPCONNECT_CONN_TIMEDOUT errors when connecting to VDI machines, disrupting their development workflows

    Workaround: Upgrade to 2503.1.

  • HZN-4315: Clicking the local pools tab in global entitlements now results in an error, preventing users from managing pools

    Workaround: Upgrade to 2503.1.

  • HZN-4455: Users with the “Inventory Administrators” role receive a warning about degraded mode in the Horizon admin console, preventing them from accessing certain features

    Workaround: Upgrade to 2503.1.

  • HZN-4476: Horizon View Java component service is consuming excessive memory, leading to frequent server reboots required by Prudential Financial

    Workaround: Upgrade to 2503.1.

  • HZN-4535: DCT output from Support.bat may fail to generate the ADAM.ldif file, preventing expected directory synchronization

    Workaround: Upgrade to 2503.1.

  • HZN-4550: API authentication may fail for users with specific passwords containing open curly braces and a hyphen

    Workaround: Upgrade to 2503.1.

  • HZN-4560: Unable to save Connection Server settings after upgrading to Horizon 2503 due to GSS Authenticator Configuration error

    Workaround: Upgrade to 2503.1.

  • HZN-4588: Unable to launch VDIs through the Access catalog portal

    Workaround: Upgrade to 2503.1.

  • HZN-4597: UAG client sessions remain active despite being logged as disconnected, creating a potential security concern for the customer

    Workaround: Upgrade to 2503.1.

  • HZN-4605: Automatic backups are failing when CPA is enabled

    Workaround: Upgrade to 2503.1.

  • HZN-4710: CPA does not select RDSH farms in remote pods that already have active user sessions when launching new applications

    Workaround: Upgrade to 2503.1.

  • HZN-4888: Import of ADAM DB fails during migration to 2503 partition if a non admin user is configured with redundant roles

    Workaround: Upgrade to 2503.1.

  • HZN-5070: Unable to view events in the Horizon admin console

    Workaround: Upgrade to 2503.1.

  • HZN-5078: The Administrator Console is displaying an inflated session count, making it difficult to accurately track active sessions

    Workaround: Upgrade to 2503.1.

  • HZN-5117: Unable to unassign user from assigned pool when pae-SIDString values are in lower case

    Workaround: Upgrade to 2503.1.

  • HZN-5139: Customers are unable to access the connection server administration interface after applying the Microsoft KB5060531 patch

    Workaround: Upgrade to 2503.1.

  • HZN-5148: Unable to access the Horizon Connection Server admin interface when clients connect in FIPS mode configuration

    Workaround: Upgrade to 2503.1.

  • HZN-5151: Unable to deploy dedicated instant clone pool with Persistent disks

    Workaround: Upgrade to 2503.1.

  • HZN-5186: In the Horizon Admin Console, when an administrator attempts to schedule an auto-upgrade for an RDS Host, an error message appears stating: 'An internal server error occurred. Please refresh the browser page and try again.'

    Workaround: Upgrade to 2503.1.

  • HZN-5418: Users may observe that Horizon recordings now display machine assignments using GUIDs instead of usernames

    Workaround: Upgrade to 2503.1.

  • HZN-5532: Pool operations are halted when the manual pool and the IC automated pool use the same common resource folder

    Workaround: Upgrade to 2503.1.

  • When there are more than ten global dedicated entitlements available to a user, the machine host name will sometimes not be visible in global entitlements if the "Show assigned host name" option is enabled.

  • Scheduling an upgrade for an RDS host may complete successfully, but the upgrade itself can fail when the scheduled time is reached.

    Workaround: See KB article 6000992.

  • If Horizon Events Database is hosted by an instance of Microsoft SQL Server (any version), do not disable TLS 1.2. This connection cannot be made over TLS 1.3.

  • HZN-4597: Connecting to a desktop via UAG keeps the session idle until UAG times out the client resulting in a “Tunnel Error: logout request by system” message

    Workaround: DO NOT click OK and simply move the box to the corner of the screen. The session stays active and you can keep working until you click on the ‘OK’ button.

  • HZN-4315: Internal error message is seen when clicking local pools tab under a Global Entitlement

    Workaround: None.

  • HZN-4309: BSG Connection Attempt Fails With VDPCONNECT_CONN_TIMEDOUT Error

    Workaround: None.

  • HZN-4605: Global LDAP configuration backup fails after upgrading to Horizon 8 version 2503

    Workaround 1: Use the Unencrypted Backup Command. You can take an unencrypted global LDAP backup using the following vdmexport command:

    vdmexport -g -v -f :\filename.ldif

    Workaround 2: Use the Ldifde utility. As an alternative, you can use the Windows LDIFDE utility to export directory data. For detailed instructions, please refer to the official Microsoft documentation here: Import or Export Directory Objects Using Ldifde.

  • HZN-4560: After upgrading to Horizon 2503 Connection Server settings cannot be saved due to the error "Failed to fetch GSS Authenticator Configuration"

    Workaround: See Omnissa Internal KB 6000870.

  • HZN-4535: DCT output from Support.bat of Horizon 2503 does not update adam.ldif and adam-global.ldif files and file size is 0 kb

    Workaround: Navigate to the Connection Server installed DCT folder location: C:\Program Files\Omnissa\Horizon\Server\DCT and replace the vdm-datacollect.ps1 with the attached ps file vdm-datacollect.ps1. Then invoke the DCT collection.

  • HZN-4455: Users with Inventory Administrator role see warning “You have {0} day(s) remaining to migrate to the Omnissa license. Failure to do so will result in the admin console entering degraded mode"

    Workaround: None.

  • HZN- 4552: When using Cloud Pod Architecture (CPA) with any one or more POD running version 8.14 or later, application session affinity is not maintained correctly. Launching a second application (with session already active on POD-A) from POD-B results in launching a new session from local RDSH instead of sending request to remote pod POD-A.

    Workaround: None.

  • HZN-3627: In a fresh install of Horizon Connection Server 2412 and in an upgrade from a previous version to version 2412, the LDAPServerIntegrity and LDAPEnforceChannelBinding registry keys are added to the wrong path. The entries are added to the parent ADAM_OmnissaHzeDS folder instead of its child Parameters folder. Note: This issue only occurs for version 2412 fresh installs and upgrades to 2412. This issue doesn't exist in version 2503 fresh installs or upgrades to version 2503.

    Workaround: Manually create new keys at the correct path and set their value. The entries incorrectly added at the parent folder can be deleted safely. The correct path is:

    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ADAM_OmnissaHzeDS\Parameters folder
    • [REG_DWORD] LDAPServerIntegrity = 2
    • [REG_DWORD] LDAPEnforceChannelBinding = 2
  • HZN-2030: Subsequent global entitlement launch with WS1 with/without True SSO enabled fails after locking the first global entitlement when CPA backhaul feature is enabled.

    Workaround: None.

  • HZN 2542: When changing the browser locale and refreshing the Horizon Console UI, error alerts fail to display for the newly selected language.

    Workaround: Log in to Horizon Console in a new browser tab.

  • HZN-2307: Adding a newly signed certificate to the certificate store and setting the rekey to the netbios name in LDAP parameter 'pae-clustercredparams' occasionally results in the certificate not being marked as current.

    Workaround: Restart the Connection Server.

  • HZN 2355: Restarting/Shutting down a desktop from a machine with an active session results in this error message: "The operation could not be completed as there is an outstanding session on the machine."

    Workaround: Machines with existing active sessions are not allowed to restart/shutdown to prevent any accidental data loss. Log off and disconnect the active sessions on the desktop then proceed with a safe restart/shutdown.

  • HZN-2390: When Home sites is in use with ANY global entitlement scope, the default CPA load goes to one of the pods in that site leading to high resource utilization.

    Workaround: Choose “Load Index“ or “Session load“ distribution policy in all the global entitlements to mitigate this issue.

  • HZN-1744: Admin UI is not operational if all of the Connection Servers in the POD are not upgraded to Horizon 8.12.1 from Horizon 8.12.

    Workaround: Upgrade all Connection Servers in the POD to 8.12.1.

  • HZN-722: When users authenticate using a smartcard with Horizon Client, an event is logged that says "User null failed to authenticate". This event is harmless and can be ignored. This occurs only when Smart card authentication for users is set to Required.

    Workaround: None.

  • HZN-717: Smartcard certificate SSO to desktop fails when subject DN has non-English or special characters and the certificate does not contain the UPN of the user.

    Workaround: At the failed SSO screen, manually select the smartcard and input the PIN to log in.

  • 3073725: Number of issues reported for ESXi Hosts in the dashboard summary may not match with number of issues reported in the dedicated ESXi Host issues section in the dashboard.

    If NVIDIA GRID vGPU support detects a mismatch with the supported vGPUs for the given host, the issue count should be incremented but the count may not display in the UI.

    Workaround: View the warnings in Dashboard > System Health > View > vSphere > ESX Hosts.

  • 3117780: The Edit vCenter model cannot be closed using the OK button when no changes are made.

    Workaround: Use the Cancel button to close the model.

  • 3076811: Admin console doesn’t open with localhost(loopback address) in IPv6.

    Workaround: Use the fully Qualified domain name instead of localhost in the URL to open the admin console. For example, if the fully qualified domain name is (test-machine-1.hzeipv6.local) then the URL to open the admin console would be: https://test-machine-1.hzeipv6.local/admin/

  • 2712612: Substituting cluster certificates causes True SSO configuration to fail.

    Workaround: Contact your Omnissa representative for assistance with this. The issue will be fixed in an upcoming release.

  • 3020358: Horizon Connection Server fails to validate the server certificate of a vCenter instance, preventing a successful connection. This can happen even if an older version of Horizon can connect successfully using the same certificate. In the Connection Server debug log, you will see an exception similar to this:

    2022-08-14T08:59:19.762-04:00 DEBUG (207C-17B4) <ajp-nio-127.0.0.1-8009-exec-2> [Connection4] [EXCEPTION] Connection to the vCenter Server https://SITE-VCENTER.DOMAIN.FOREST:443/sdk failed.: javax.xml.ws.WebServiceException: Could not send Message. com.xxxxxx.vdi.logger.Logger.debug(Logger.java:44)

    javax.xml.ws.WebServiceException: Could not send Message.....

    This is caused by javax.net.ssl.SSLHandshakeException: SSLHandshakeException invoking https://SITE-VCENTER.DOMAIN.FOREST:443/sdk : Certificates do not conform to algorithm constraints

    Workaround: Follow the steps in KB 89331.

  • 3004222: View API consumers like the MP4H Adapter invoke MachineDetailsView. This API fails intermittently with user data not found error.

    Workaround: None

  • 1778303: When you restart or reset a virtual machine for which an end user session exists in a desktop pool from vCenter Server or from the Windows Operating System menu, the virtual machine restarts but the status of the virtual machine might appear in the “Already Used” state in Horizon Console. This problem can occur for the following pool types:

    • Instant-clone desktop pools.

    • Full-clone floating desktop pools with "Delete on log Off" enabled.

    Workaround: Use Horizon Client to restart or reset the virtual machine in the instant-clone desktop pool. If the virtual machine is already in the “Already Used” state, remove the virtual machine. This action automatically creates a new virtual machine based on the pool provisioning settings.

  • 1817536: If you provision instant clones on local datastores, the corresponding hosts cannot be put into maintenance mode. This occurs because the internal VMs and the instant clones are stored on local datastores so they cannot be migrated.

    Workaround: Delete the instant-clone desktop pool. This will delete the related VMs and enable the corresponding hosts to enter maintenance mode.

  • 1548405: Universal Windows Platform (UWP) applications are not supported as published applications on Windows Server 2016 and Windows Server 2019 RDS hosts.

  • 1605667: For True SSO, the connectivity status between the Connection Server instance and the enrollment server is displayed only on the System Health Status dashboard for the connection server that you are using to access Horizon Console. For example, if you are using https://server1.example.com/admin for Horizon Console, the connectivity status to the enrollment server is collected only for the server1.example.com connection server. You might see one or both of the following messages:

    • The primary enrollment server cannot be contacted to manage sessions on this connection server.

    • The secondary enrollment server cannot be contacted to manage sessions on this connection server.

    It is mandatory to configure one enrollment server as primary. Configuring a secondary enrollment server is optional. If you have only one enrollment server, you will see only the first message (on error). If you have both a primary and a secondary enrollment server and both have connectivity issues, you will see both messages.

  • 1850273: When you set up True SSO in an environment with CAs and SubCAs with different templates set up on each of them, you are allowed to configure True SSO with a combination of templates from a CA or SubCA with another CA or SubCA. As a result, the dashboard might display the status of True SSO as green. However, it fails when you try to use True SSO.

  • 1864310: In Horizon Help Desk Tool, the pod name does not appear if the session is a local session or a session running in the local pod.

    Workaround: Set up the Cloud Pod Architecture environment to view pod names in Horizon Help Desk Tool.

  • 1880134: The Workspace ONE mode setting is not reflected in the replica server from Workspace ONE.

    Workaround: Configure the Workspace ONE mode in Connection Server.

  • 1880355: In a Cloud Pod Architecture environment, pre-launched application sessions from global application entitlements are not shown in Inventory > Search Sessions in Horizon Console.

    Workaround: Log in to the Horizon Console user interface for a Connection Server instance in the hosting pod and select Monitoring > Events to view pre-launched session information.

  • 1569435: For Intel vDGA, only the Haswell and Broadwell series of Intel integrated GPUs are supported. Broadwell integrated GPUs are supported only on vSphere 6 Update 1b and later. Haswell integrated GPUs are supported on vSphere 5.5 and later. The GPU must be enabled in the BIOS before it can be recognized by ESXi. For more information, see the documentation for your specific ESXi host. Intel recommends leaving the graphics memory settings in the BIOS set to their default values. If you choose to change the settings, keep the aperture setting at its default (256M).

  • 1946086, 1936954: For vCenter Server 6.0 U3 or later, including vCenter Server 6.5, internal parent VMs migrate to another host during failure. This migration causes an issue because unnecessary parent VMs reside on the destination host.

    Workaround: Manually remove these parent VMs. For more information, see the Desktops and Applications in Horizon 8 guide.

  • 1951074, 1936743: To reduce the possibility of memory exhaustion, vGPU profiles with 512 MB or less of frame buffer support only one virtual display head on a Windows 10 guest operating system. The following vGPU profiles have 512 Mbytes or less of frame buffer:

    • Tesla M6-0B, M6-0Q

    • Tesla M10-0B, M10-0Q

    • Tesla M60-0B, M60-0Q

    • GRID K100, K120Q

    • GRID K200, K220Q

    Workaround: Use a profile that supports more than one virtual display head and has at least one GB of frame buffer.

  • 1952105, 1928484: Virtual desktops and published desktops and application pools fail to launch if they have the client restriction feature enabled and are entitled to a domain that is configured with a one-way AD trust.

    Workaround: None.

  • 1961900: After an upgrade, the bookmarks do not appear in Workspace ONE.

    Workaround: Add the bookmarks from the catalog in Workspace ONE again.

  • 2020365, 2018588: After you disconnect and reconnect the network cable and click "Disconnect and Log Off" on the client machine, the remote desktop does not disconnect and log off.

    Workaround: Manually close the window of the remote desktop and disconnect from the remote session.

  • 2024833: When you create full clones with the Sysprep customization method, customization and domain joining sometimes fails on Windows 10 guest operating systems.

    Workaround: This occurs because of a Microsoft Windows issue. To resolve this issue, follow the steps in this Microsoft help article: Sysprep fails after you remove or update Microsoft Store apps that include built-in Windows images.

  • 2085284, 2001591: When you use Safari version 10.1.1 as the Web browser to log in to Horizon Console with a Fully Qualified Domain Name, user interface issues such as the bottom panels appearing blank can occur.

    Workaround: Safari version 10.1.1 is not a supported Web browser version for Horizon Console. Use a Safari version earlier than version 10.1.1 or version 11.0.2 and later to log in to Horizon Console.

  • 2074958, 2067873: The following user interface issues occur in Horizon Help Desk Tool for global Linux sessions in a Cloud Pod Architecture deployment:

    • An internal error occurred message appears, the Skype for Business status is not displayed, and the operating system version displays as “-” when you click the session details on the Details tab.

    • A “failed to get Remote Assistance ticket” message appears when you click Remote Assistance.

    • An internal error occurred message appears when you click the Applications tab.

    Workaround: None. Horizon Help Desk does not support the following user interface features for Linux desktops: Skype for Business status, Remote Assistance, Applications tab, and the session idle status.

  • 2104955, 2104953: Horizon Console does not update the space reclamation information for a vCenter Server on vSphere version 6.7 that uses the VMFS6 with the automatic UNMAP feature.

    Workaround: None.

  • 2085281, 2000267: Login to Horizon Console fails if you use the IP address to login to Horizon Console on a Firefox, Google Chrome, Microsoft Edge, Firefox, or Safari Web browser.

    Workaround: Use the Fully Qualified Domain Name (FQDN) to login to Horizon Console. For more information on using FQDN to log in to Web applications, see the Horizon Security document.

  • 2091333: After an upgrade to vSphere 6.7, you cannot use the custom specification created with a vSphere version earlier than 6.7.

    Workaround: After an upgrade to vSphere 6.7, create a new custom specification and use this specification for pool provisioning.

  • 2093129, 2069708: Horizon Help Desk Tool displays the logon time for both the brokering pod and the hosting pod but does not display the logon time for a pod that is neither the brokering pod nor the hosting pod. Horizon Help Desk Tool displays the logon time after a few minutes for the hosting pod if the brokering pod is a remote pod.

    Workaround: If Horizon Help Desk Tool does not display the logon time for the hosting pod, close the page that displays session details, wait 7-8 minutes and navigate to the Details tab to view the session details again.

  • 2111978, 2073141: Omnissa Access sometimes fails to launch desktops. When you save SAML configuration details for the first time Omnissa Access with SAML enabled on Connection Server, desktops do not start.

    Workaround: Save the profile again and perform a sync operation on the new profile. The sync operation can occur every hour or day, as set by the administrator.

  • 2126853: Horizon Single Sign On fails when the scope of the trust authentication setting is set to “Selective Authentication".

    Workaround: Use one of the following workarounds to resolve this issue.

    • Use domain-wide authentication.

    • Continue to use the “Selective Authentication” security setting, but explicitly grant each Horizon Connection Server host (local system) accounts the "Allowed to Authenticate" permission on all the domain controllers of the computer objects (resource computers) that reside in the trusting domain or forest. For information on how to grant the "Allowed to Authenticate" permission, see the Microsoft article "Grant the Allowed to Authenticate permission on computers in the trusting domain or forest."

  • 2146919: With the Cloud Pod Architecture feature, in certain circumstances RDS licensing servers issue multiple permanent licenses to the same client in a mixed-mode licensing environment.

    Workaround: None. This problem is a third-party issue and is in line with the way Microsoft RDS license servers issue licenses.

  • 1629622: Attempts to connect to the Horizon Web Client portal or one of the administration consoles using an IP address or CNAME fails for most browsers without additional configuration. In the majority of these cases, an error is reported but sometimes a blank error message is displayed.

    Workaround: To resolve this issue, see “Origin Checking” in the Horizon 8 Security document.

  • 2217199: If the same user exists in both Connection Server pods that need to be paired in a Cloud Pod Architecture environment, Horizon Console displays the value for “Source Pods” as 2 and sources the user from both pods. An administrator can edit the user from both pods, which might cause inconsistencies in user configuration during hybrid logon. Additionally, hybrid logon for the user cannot be disabled.

    Workaround: You must delete the user from both pods and then recreate the user and configure the user for hybrid logon.

  • 2222221: Core-dump error messages are generated while adding Virtual Volumes datastores on nested ESXi or nested virtual ESXi.

    Workaround: None.

  • 2356156: When a Universal Windows Platform (UWP) application is upgraded, the path containing the version changes, and the application is unreachable by the original path. The app status is Unavailable in Horizon Console and a user cannot launch the app.

    Workaround: Update the app path in Horizon Console after an upgrade and verify the app status is Available. Alternatively, do not upgrade the app.

  • 2330942: When device filtering is configured for the client drive redirection feature and a user uses the RDP display protocol to connect, device filtering does not work.

    Workaround: When device filtering is configured for client drive redirection, configure Connection Server so that RDP connections are not allowed.

  • 2300801: The True SSO desktop unlock feature is supported in PCoIP and Blast protocols, but not in Remote Desktop Protocol (RDP).

  • 2358355, 2353567: In Horizon Console, the user or group summary fails to load due to domain trust issues in the following cases:

    • When users and groups belong to a one-way trust domain and the logged in administrator has the necessary permissions from a one-way trust domain.

    • When users and groups belong to a two-way trust domain and the logged in administrator has the necessary permissions from a two-way trust domain.

    • When users and groups belong to a one-way or two-way trust domain and the logged in administrator is from the child domain and has the necessary permissions.

    Workaround: None.

  • 2363188, 2354034: In Horizon Console, some events might not be listed because the Connection Server time is set incorrectly with respect to the Connection Server time zone.

    Workaround: None.

  • 2366007, 2339388: You can recover an instant-clone virtual machine with an active session in Horizon Console.

    Workaround: None.

  • 2516216, 2514333: The Pre-launch and Use Home Site options do not work well together for global application entitlements. When you create a global application entitlement, if you enable both the Pre-launch and Use Home Site options, the pre-launched session might not be created from the home site. This problem occurs because the same session is used to start subsequent applications, and those sessions are not started from the home site.

    Workaround: None.

  • 2510477, 2500272: The following error message can appear while installing or uninstalling Connection Server:

    "Error opening installation log file. Verify that the specified location exists and is writable."

    This error occurs due to a third-party Microsoft error. For details see this Microsoft help article.

    Workaround: Restart the virtual machine on which the Connection Server is installed.

  • 2686004, 2672069: The CSRF feature for Horizon Web Client introduced in Horizon 2006 does not support the combination of a pre-login message configured on Connection Server with SAML authentication through Unified Access Gateway.

    Workaround: If you use this combination of features and Horizon version, disable this pre-login message on Connection Server. A pre-login message should instead be configured on the SAML IdP, so that it is presented to the user before the user enters their credentials.

  • 2986303: Certificates signed using SHA-1 are no longer supported in FIPS mode.

    Workaround: See Older Protocols and Ciphers Deactivated in Horizon.

Horizon Cloud Connector

  • 2295015: When you use the HTML5-based vSphere Web client to deploy the Horizon Cloud Connector virtual appliance OVA file, the following error occurs: “Invalid value 'false' specified for property proxySsl. Failed to deploy OVF package.”

    Workaround: Use the vSphere Web Client to deploy the Horizon Cloud Connector virtual appliance OVA file.

  • 2360709, 2360707: When starting Horizon Cloud Connector, you encounter the message "[FAILED] Failed to start Wait for Network to be Configured. See 'systemctl status systemd-networkd-wait-online.service' for details."

    Workaround: This message is displayed incorrectly and does not indicate an actual problem with the network. You can disregard the message and continue to use Horizon Cloud Connector as usual.

Horizon Recording

  • HZN-3928: Conflict issues will occur when you upgrade from Horizon Recording Agent RPM 1.12 to 1.13.

    Workaround: Instead of upgrading, uninstall Horizon Recording Agent RPM 1.12 and install Horizon Recording Agent RPM 1.13.

Horizon Agent for Linux

This section describes issues that might occur with Horizon Agent for Linux or when you configure a Linux desktop.

  • VCART-3894: Installation of Horizon Recording Agent fails when using the RPM installer on a RHEL 8.10 machine.

    Workaround: Before running the RPM installer for Horizon Recording Agent on a RHEL 8.10 machine, downgrade the rpm-plugin-selinux package with this command: yum downgrade rpm-plugin-selinux-4.14.3-26.el8.x86_64
    For more information, see Red Hat Knowledge Base article 3739361.

  • VCART-3920: After logging into an Ubuntu 24.04 desktop, a black screen sometimes appears.

    Workaround: Enter the Ctrl+Alt+D shortcut to fix this problem. If the problem persists, enter Ctrl+Alt+T several times, and then enter Ctrl+Alt+D again.

  • VCART-2404: After creating a full-clone or instant-clone desktop pool from an Ubuntu 24.04 machine, desktops are unavailable and the base machine appears to have no IP address and a disconnected network adapter.

    Workaround: This issue is related to the hardware clock setting on the machine. Apply the workaround documented in Knowledge Base article 95091.

  • HIX-374: When a user opens a remote session to a physical Linux machine, the local monitors for the machine go blank and the local console cannot be accessed.

    Workaround: To restore access to the local monitors and console, disconnect from the remote session. If the remote session cannot be disconnected, unplug the network cable from the physical machine. After about 5 minutes, the agent will return control to the physical machine and allow logins to the console.

  • VCART-1502: The Session Collaboration icon disappears from the system tray after resizing a Debian 12.x desktop.

    Workaround: Disconnect from and reconnect to the desktop. The Session Collaboration icon usually appears after reconnection to the desktop. Alternatively, you can try restarting GNOME Shell with the following steps:

    1. Press Alt+F2 to display the Run a Command dialog box.

    2. Type "r" in the dialog box.

    3. Press Enter.

  • VCART-438: Pressing Ctrl+Alt+F1 or Ctrl+Alt+F2 does not display the graphical desktop on a physical host machine after Horizon Agent is installed. Since TTY1 is reserved for the Gnome Display Manager, Horizon Agent uses TTY7 instead.

    Workaround: To display the graphical desktop on a physical host machine, press Ctrl+Alt+F7.

  • 2969881: NVIDIA GRID 14.0 GPU with P100 vGPU profile is not supported for Linux desktops.

    Workaround: Use NVIDIA GRID 14.1 GPU instead.

  • 2213769: Sometimes the Collaboration window might not appear after you connect to a remote desktop and click the Collaboration UI icon.

    Workaround: Resize the desktop window or reconnect to the remote desktop.

  • 1823753: The Linux agent's keyboard layout and locale do not synchronize with the client if the Keyboard Input Method System is set to fcitx.

    Workaround: Set the Keyboard Input Method System to iBus.

  • 1850274: If you configure two monitors with different resolutions, and the resolution of the primary screen is lower than that of the secondary screen, you might not be able to move the mouse or drag application windows to certain areas of the screen.

    Workaround: Make sure that the primary monitor's resolution is at least as large as the secondary monitor's.

  • 2398096: If a client user minimizes the window of a Linux published application using the Minimize command and then selects the Maximize command, the window is restored to its previous size instead of changing to full-screen mode as expected.

    Workaround: To change to full-screen mode, select the Maximize command again.

  • 2483646: Linux published applications do not support using the window taskbar to divide the work area in a multiple-monitor display. For example, suppose a client user has two monitors arranged side by side. If the user moves the taskbar to the right side of the left monitor's screen or the left side of the right monitor's screen, the work area is divided into two parts. However, if the user then maximizes the application window, the window is displayed incorrectly in relation to the taskbar.

  • 2502364: When connecting to a Linux published application from Horizon Client for Mac, the application window is displayed with square corners instead of rounded corners.

  • 2536164: If a client user leaves a nonmodal dialog box open in a Linux published application and then makes active a native application on the client system, part of the dialog box will appear to be missing when the user returns to the published application.

  • 2538998: If the client user minimizes a Linux published application window or brings another application in front of the published application window, the taskbar fails to display the thumbnail preview of the published application window. Hovering over the published application icon in the taskbar displays a blank thumbnail instead of the contents of the published application window.

  • 2539011: Linux published applications do not support the Aero Snap feature on Windows client systems. Users connecting to a Linux published application from Horizon Client for Windows do not have the capability to snap or fix windows to the edges of the computer screen using the keyboard or mouse.

  • 2539030: Linux published applications do not support the jump list feature on Windows client systems. If a user connects to a Linux published application from Horizon Client for Windows and right-clicks the taskbar icon for the application, no jump list is displayed.

  • 2539088: Due to a limitation in the work area, Linux published application windows cannot be moved partially off the edge of the client's screen or work area. If the user attempts to move a published application window past the edge of the screen, the window will bounce back inside the screen's boundaries.

  • 2540474: If the client user opens a modal dialog box from a Linux published application, that dialog box might not appear in front of native windows.

  • 2541343: When connecting to a published application from a Windows client system, there are some differences between the context menus of the Windows taskbar and the application window's title bar. Shift + right-clicking the application icon in the Windows taskbar displays a menu with the items: Restore, Move, Size, Minimize, Maximize, Close. Right-clicking the application window's title bar displays a menu with the items: Minimize, Maximize, Move, Resize, Close.

  • 2397650: Published applications do not support the Move and Size context commands for the taskbar on Windows client systems. When a user Shift + right-clicks the published application icon in the Windows taskbar, Move and Size appear in the menu but neither command has any effect if selected.

  • 2541928: Published applications do not support the Size command from the application window's context menu. When a user right-clicks the title bar of the application window, Size appears in the menu of commands but has no effect if selected.

  • 2557790: When a user opens multiple session windows for the same published application on a Windows client system, the Cascade all windows command has no effect.

  • 2567292: If a Windows client user with a dual monitor configuration maximizes a published application in the lower-resolution monitor's work area, the Windows taskbar turns black.

  • 2568171: After publishing a LibreOffice application as an application pool, duplicate LibreOffice icons might appear in Horizon Client.

    Workaround: From the Connection Server, manually assign the icon for the LibreOffice application.

  • 2569231: Linux published applications do not support the Multi-Session Mode option in the application pool settings in Horizon Console.

  • 2536161: When connected to a Linux published application, if the user opens a dialog box related to user account controls (such as when editing firewall settings), the desktop will not show.

  • 2523872: Horizon Agent for Linux does not support session stealing between published desktops and published applications. For example, if a user has opened a published desktop session and then attempts to open an application session based on the same farm, the desktop session remains active and the application session is not established. Likewise, if the user has opened an application session and then attempts to open a published desktop session based on the same farm, the application session remains active and the desktop session is not established.

  • 2662387: If a user types an entry into the Session Collaboration invitation text box and moves the cursor away from the text box, the original entry is cleared.

  • 2684670: If a client user with a multi-monitor system opens a published application in seamless window mode, display problems might occur when moving the application window between monitors.

    Workaround: Shift + right-click the application icon in the client's task bar and select Maximize to enlarge and refresh the window display.

  • 2684687: Display problems might occur when a client user opens published applications in seamless window mode on a multi-monitor system where some monitors have portrait orientation and other monitors have landscape orientation. If the user maximizes the application windows in all the monitors, the task bar appears black in the landscape monitors.

  • 2668258, 2576341: When client users copy content containing images in rich text format and then paste the content into an application on a remote Linux desktop, the images might be missing from the pasted content. This issue is caused by a limitation in certain third-party applications such as OpenOffice or LibreOffice, not by Horizon Agent for Linux.

    Workaround: Use a clipboard manager to retrieve the missing content from the clipboard.

  • 2786998: When a user prints a document using the Printer Redirection feature from LibreOffice or Firefox, the document's headers and footers are missing from the output.

    Workaround: Use a different office application or browser to print the document.

  • 2787001: When a user prints a document in landscape orientation using the Printer Redirection feature, the print job sometimes fails.

    Workaround: None

  • 2745267: Horizon Agent for Linux only recognizes valid characters in printer names. The agent replaces invalid characters in the printer name with underscores and truncates the name if its length exceeds 128 bytes.

    Workaround: None

  • 2748100: The page margins and offsets in print jobs redirected from a remote desktop do not match the page margins and offsets in print jobs printed locally from the client system. This inconsistency is caused by different implementations of page scaling on the agent and client.

    Workaround: Turn off the page scaling option by setting it to 100% or None, on both the remote desktop and the client system.

  • 2741260: When print jobs are redirected from the remote desktop to a Windows client, N-up layouts do not print correctly. These layouts always output as left to right, and top to bottom.

    Workaround: None

  • 3051022: The Enter Ctrl + Alt + Del control in Horizon Client does not take effect when connected to a RHEL 7.9 desktop with MATE desktop environment.

    Workaround: Use the default keyboard shortcut for logging out of a MATE desktop. Or, define a custom keyboard shortcut for logging out.

  • 3158384: A small blank recording (2-3 kb) is sometimes created when a blast session running on Linux agent is being recorded by the Horizon Recording solution.

    Workaround: None. There is no adverse effect on the functionality except that a small recording can be seen in the recordings page for some of the sessions during a fresh logon.

Horizon Agent for Windows

  • VCART-7428: Scheduling an upgrade for an RDS host may complete successfully, but the upgrade itself can fail when the scheduled time is reached.

    Workaround: See KB article 6000992.

  • 2975449: When a Microsoft Teams user selects background blur image for their video call or meeting, that setting does not persist after user disconnects/logs off from the desktop or restarts the Teams service inside the desktop.

    Workaround: User needs to remember to preselect Background blur when they log in or restart Teams.

  • 2980199: Default audio device cannot be set successfully when microphone privacy is disabled for first logged in user.

    Workaround: Disconnect the remote session or change the default audio device on client side; this triggers the device to change in the remote session.

  • 1993397: If a collaborator joins a multi-monitor session and enables relative mouse mode on their client, it is possible for the mouse to move to a secondary monitor that the collaborator cannot see.

    Workaround: Move the mouse back on to the screen. Alternatively, don't use relative mouse mode in a multi-monitor session.

  • 2776478, 2708700: When the URL Content Redirection feature is configured, Horizon Client presents an alert message that asks you to change your default web browser to Horizon URL Filter for using third-party apps, not including the Chrome and Microsoft Edge (Chromium) browsers. You must click Yes to use the URL Content Redirection feature. In macOS 11 (Big Sur), even when you click Yes to the alert message, the Horizon URL Filter user interface is not shown in the default web browser of the general option, which means you cannot change the default web browser from another browser to Horizon URL Filter manually, and you must connect to the server again. In macOS 10, the user interface is shown in the default web browser of the general option. The URL Content Redirection extensions for the Chrome and Microsoft Edge (Chromium) browsers are not influenced by macOS 11.

    Workaround: None. This problem is a third-party issue.

  • 1799790: A warning message about applications in use appears when you uninstall Horizon Agent on Windows Server 2016.

    Workaround: Click “Ignore” in the dialog box that appears when you use Windows Add or Remove Programs to uninstall Horizon Agent. If you uninstall Horizon Agent from the command line, use the command msiexec /x /qn {GUID of Agent} instead of the command msiexec /x {GUID of Agent}.

  • 1874531, 1699275: When you uninstall the Horizon Agent, the mouse speed becomes slow and jerky. Uninstalling Horizon Agent also uninstalls the vmkbd.sys driver.

    Workaround: Repair VMware Tools on the Horizon Agent virtual machine.

  • 1993397: If a collaborator joins a multi-monitor session and enables relative mouse mode on their client, it is possible for the mouse to move to a secondary monitor that the collaborator cannot see.

    Workaround: Move the mouse back on to the screen. Alternatively, don't use relative mouse mode in a multi-monitor session.

  • 2003328: If you use Chrome with URL Content Redirection, and you set "..google." for the https protocol in filtering rules and you set Google as your home page in Chrome, redirection to google.com occurs each time you open a new tab.

    Workaround: Change the home page or the filtering rules.

  • 2022449, 2022448: When setting up a collaborative session, adding a collaborator by the email address from a two-way trusted domain fails.

    Workaround: Add the collaborator by using domain\user.

  • 2390130: After you connect to a remote desktop that has the Real-Time Audio-Video feature enabled, you might see the following message: "Your PC needs to be restarted to finish setting up this device: devicename (VDI)."

    Workaround: You can ignore this message as the device is usable in the remote desktop. Alternatively, you can turn off the Windows Settings notifications to prevent the message from being displayed.

  • 2417249: Users cannot use a serial printer with the serial port redirection feature when Horizon Agent is installed in an RDS host if the agent group policy setting COM Port Isolation Mode is set to Full Isolation (the default setting). This problem affects both Windows and Linux clients. This problem does not occur for virtual desktops.

    Workaround: Edit the COM Port Isolation Mode group policy setting, change the mode to Isolation Disabled , and restart Horizon Agent. For more information, see Configuring Serial Port Redirection Group Policy Settings.

  • 2512363, 2401690: sysprep fails for full clones with Windows 10 1903, Windows 10 1909 guest OS with error:

    SYSPRP Sysprep_Clean_Validate_Opk: Audit mode can't be turned on if there is an active scenario.; hr = 0x800F0975

    Workaround: Apply these instructions on the golden image and then provision the desktop.

  • 2481953: When you update the OS from Windows 1809 to 1903, you might see a black screen on Horizon Agent.

    Workaround: Apply the procedure in this KB article on the OS image. If Horizon Agent is installed on an RDS host, and the Printer Name for RDSH Agents group policy setting for the Integrated Printing feature is configured to use the client machine name as a suffix, the client machine name supports only English-language characters. If the client machine name contains characters in a non-English language, the Integrated Printing feature does not work in published desktops and published applications.

  • 2591431, 2588938: Windows 10 2004 remote desktops respond very slowly when VBS is enabled.

    Workaround: None

  • 2590496, 2588784: Updating the None guest customization to any other guest customization on a desktop pool causes existing virtual machines to go into an unreachable state after a reboot or power cycle operation.

    Workaround: In Horizon Console Desktop Pool settings, set the guest customization to None , then reboot the existing unreachable agent VMs.

  • 2593663, 2589371: With Horizon desktops using Nvidia GRID, Windows 10 build 2004, PCoIP protocol, and in multi-monitor mode, some areas of the desktop might appear black and need to be manually refreshed.

    Workaround: Use Blast protocol if available, or continue using Windows 10 build 1909.

  • 2590453, 2585527: Switching the agent desktop from window mode to multi-monitor mode with 4x4k monitors can sometimes take a few seconds.

    Workaround: None.

  • 2574035: When you run the Horizon Agent installer from a web browser download directory, the installer fails to complete installation.

    Workaround: Download the installer to a non-download directory, such as the desktop, and run it from there for a successful installation.

  • 2539025, 2357111: HTML5 Multimedia Redirection does not work with an Edge browser in an IPv6 environment.

    Workaround: None.

  • 2682571, 2672155: Remote desktops and published applications configured in Horizon 8 do not sync when using Workspace One Access Connector 19.03.0.1.

    Workaround: Revert to Workspace One version 19.03.0 and perform the sync operation again.

  • 2770035, 2744714: HTML5 Multimedia Redirection does not work with https://www.glamour.com/video.

    Workaround: None.

  • 2776478, 2708700: When the URL Content Redirection feature is configured, Horizon Client presents an alert message that asks you to change your default web browser to Horizon URL Filter for using third-party apps, not including the Chrome and Microsoft Edge (Chromium) browsers. You must click Yes to use the URL Content Redirection feature. In macOS 11 (Big Sur), even when you click Yes to the alert message, the Horizon URL Filter user interface is not shown in the default web browser of the general option, which means you cannot change the default web browser from another browser to Horizon URL Filter manually, and you must connect to the server again. In macOS 10, the user interface is shown in the default web browser of the general option. The URL Content Redirection extensions for the Chrome and Microsoft Edge (Chromium) browsers are not influenced by macOS 11.

    Workaround: None. This problem is a third-party issue.

  • 2783745: If you disable the IE browser URL Plugin, enable the Edge browser URL Content Redirection extension, and input a URL in the IE mode of the Edge address bar, Edge stops responding.

    Workaround: None.

  • 3025092: Smart Card Authentication and Redirection does not work for AWS WSP Workspaces.

    Workaround: Use AWS PCoIP Workspaces instead of WSP Workspaces.

Horizon Client

This section describes problems that end users might encounter when using Horizon Client or Horizon Web Client to connect to remote desktops and applications. For problems that occur only in a specific Horizon Client platform, see the Horizon Client release notes in the Omnissa Product Documentation portal.

  • VCART-5577: Systray icon redirection does not work for hosted apps published from Windows 11 24H2.

    Workaround: None.

  • 3235572: Horizon Client crashes with "Horizon View unrecoverable error" dialog when connecting to remote desktop.

    Workaround: None. You must upgrade the Horizon Client version to the 2306 or later release.

  • 2384662: Most keyboard shortcuts supported by the Google Chrome browser do not work on pages redirected using Browser Redirection.

    Workaround: None.

  • If you use Skype for Business inside a non-persistent desktop, you might reach the Skype for Business limit of 16 device certificates. When this limit is reached and Skype for Business attempts a new logon, a new certificate will be issued and the oldest assigned certificate will be revoked.

    Workaround: None.

  • 1996301: Sometimes an audio call does not start correctly from Skype to Skype for Business. The call status is "Connecting call..." on the Skype for Business client.

    Workaround: Set the English IME on the client device and set the non-English IME on the remote desktop.

  • 1704144: When you connect to a Linux desktop, some keyboard inputs do not work. For example, if you are using a non-English IME on both the client device and the remote desktop, some non-English keys are not displayed correctly.

    Workaround: None.

  • 1850278: Unicode keyboard input does not work correctly with Horizon Web Client when connected to Linux desktops.

    Workaround: None.

  • 1711664: When you use the Ambir Image Scan Pro 490i to perform a scan on a remote desktop or application, the dialog box always displays “Scanning…” and does not complete.

    Workaround: Perform a scan on the client. The client scan calibrates the scanner. After the calibrate operation is finished, save the calibration file and deploy it in ProgramData\AmbirTechnology\ImageScanPro490i.

  • 1865373, 1863461: If a VDI desktop is in a remote location and experiencing high network latency, then a recursive unlock using smart card authentication might not work.

    Workaround: Unlock the desktop manually.

  • 2761441, 2739372: HDR support for full screen mode is limited to a scenario where the selected monitor is the primary monitor.

    Workaround: None.

Windows OS Optimization Tool

  • When the exported analysis report is exported to the same VM where you're running the Optimization Tool EXE, the report is auto-deleted after running the tool's Generalize task. Even though you'll still be able to view the report inside the Optimization Tool user interface, the exported report is deleted after Sysprep runs (Sysprep runs as part Generalize).

    Workaround: Export the analysis report to another location on the network instead of saving the report into the current user folders on the same VM. Because those user folders get deleted as part of Sysprep, if saved in those folders on the VM, the report is deleted during the Generalize run. If you specify to redirect the report to another location on the network, the report will be retained after running Generalize.

  • In the tool's Optimize task sequence created with the MDT plugin, there's a known issue with the Windows Store Apps UI's behavior for the MSTeams check box related to the Remove store apps check box. When you want to delete all of the store apps and select that Remove store apps check box, the individual UI options to retain individual apps should all be unselectable. Due to this known issue, the MSTeams check box is an exception to the UI behavior for the other listed apps. Selecting and unselecting the MSTeams check box will have no effect.

APIs

  • HZN-3296: REST API ObjectGUIDs change after certain events, such as disaster recovery and pod rebuilding.

    Workaround: Do not rely on ObjectGUIDs as persistent identifiers. After an event such as disaster recovery and pod rebuilding, resync any third-party applications to the new ObjectGUIDs.

On-Premises Environments

  • HZN-4839: Occasionally, the health check response for /favicon.ico may be delayed.

    Workaround: This issue can occur during periods of LDAP congestion. To mitigate it, consider adjusting the timing of LDAP backups. For more information, see Horizon Configuration Backup Settings.

    A permanent fix is planned for the Horizon 2512 release.

Use of Open Source

As part of the installation process, an open_source_licenses.txt file is written to the file system. Key open-source components included in this release are:

  • Horizon Connection Server 2503 is built on the Apache Tomcat implementation of Jakarta EE, version 10.1.39.
  • Horizon Agent for Linux 2503, Horizon Agent for Windows 2503, and Horizon Connection Server 2503 all utilize the BellSoft Liberica distribution of OpenJDK, version 17.0.13.0.1 (CPU).

Use of Open Source

As part of the installation process, an open_source_licenses.txt file is written to the file system. Key open-source components included in this release are:

  • Horizon Connection Server 2503 is built on the Apache Tomcat implementation of Jakarta EE, version 10.1.39.
  • Horizon Agent for Linux 2503, Horizon Agent for Windows 2503, and Horizon Connection Server 2503 all utilize the BellSoft Liberica distribution of OpenJDK, version 17.0.13.0.1 (CPU).

Documentation

Horizon 8 documentation is in the Omnissa Product Documentation portal.

Localized Content for Omnissa Docs

For details on Omnissa's localization strategy, see Announcing Omnissa Localization Support.

Support Contact Information

To receive support and to learn more about support policies, see Omnissa Customer Connect.

For information on filing a support request in Customer Connect and via Cloud Services Portal, see KB 6000005.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…