Skip to main content

Requirements Checklist for Deploying an Amazon Workspaces Core Edge

The purpose of this checklist is to inform you of the required elements for doing a native Amazon WorkSpaces Core deployment using the Horizon Control Plane in Horizon Cloud.

Checklist Audience

This checklist is for Horizon Cloud customer accounts that have never had a Horizon Cloud on Amazon WorkSpaces Core deployment in their tenant environment. You might hear such tenants referred to as clean-slate environments or greenfield environments.

You must perform some items that follow before you deploy Horizon Cloud. You can defer some items until after the deployment is finished and running.

AWS Account Requirements

For configuration limits, see Sizing Your Horizon Cloud Deployment, which includes information about using the Configuration Maximums tool. Starting on the Configuration Maximums page, select View Limits, Horizon Cloud, the most recent version, and the categories you want to view.

Amazon Elastic Compute Cloud (Amazon EC2) Requirements

Valid Amazon Web Services account in a supported AWS region. See related AWS documentation.

Note: Horizon Cloud supports most Amazon WorkSpaces Core Supported Regions.

Valid AWS Identity and Access Management (IAM) roles in each Amazon Web Services account. See the AWS documentation for creating an AWS Account.

The roles are a requirement to perform the Amazon WorkSpaces Core Edge deployment. See Amazon WorkSpaces Core Edge Deployments.
Ensure that no AWS IAM policy or resource locks are in place that would prevent Horizon Edge deployment resources from being created.
Perform the IAM requirements
Amazon EC2 capacity for the core Horizon Edge resources to deploy into that account.

Edge Gateway (VM) – enough quota for a single virtual machine.

Below is the list of supported VM SKU sizes for an Edge Gateway (VM) deployment in descending order of priority. If your Amazon WorkSpaces Core account has capacity for at least one of the following VM SKU sizes, the Edge deployment is accepted. Otherwise, the Edge deployment is rejected.

  • M5.xlarge

  • Run commands to check for the availability of the Amazon WorkSpaces Core model and to check the regional CPU output. See Check the Availability of the Amazon WorkSpaces Core Model.
  • Unified Access Gateway instances – Minimum of 2 x of the supported sizes that follow. The default and recommended size is C4.2xlarge.
    • C3.2xlarge and above
    • C4.2xlarge and above
    • C5.2xlarge and above
    • C5a.2xlarge and above
    • C5ad.2xlarge and above
    • C5d.2xlarge and above
    • C5n.2xlarge and above
    • C6a.xlarge and above
    • C6g.2xlarge and above
    • C6gd.2xlarge and above
    • C6gn.2xlarge and above
    • C6i.2xlarge and above
    • C6in.2xlarge and above
    • C7a.2xlarge and above
    • C7g.2xlarge and above
    When your Horizon Edge instance is ready to use, your capacity in Amazon WorkSpaces Core also must accommodate the imported VMs, images, pool VMs, and App Volumes app-capture VMs that you create in that Horizon Edge instance. See the Image Management System Requirements section.
  • The following Amazon WorkSpaces Core deployment option is available:
    Edge Gateway (VM) = Edge Gateway Virtual Machine Edge Gateway (VM) is for smaller deployments without high availability.

    Amazon WorkSpaces Core Capacity Requirements

    Where the following table refers to Amazon WorkSpaces Core capacity, no manual installation is necessary. As long as the stated capacities are available in the subscription, the deployer automatically instantiates the described VMs.

    Bring-Your-Own-License (BYOL) Prerequisite Configured.

    See the AWS documentation for bringing your own Windows desktop licenses in WorkSpaces.
    Availability Zones for WorkSpaces Personal Configured.

    See the AWS documentation for information about Availability Zones for WorkSpaces Personal.

    Network Requirements

    The following network requirements include the details necessary to successfully deploy and operate a Horizon Edge. See the AWS documentation for networking in Amazon EC2. for more information.

    Use the following table for an Edge Gateway deployment.

    Network Requirements for an Edge Gateway (VM)

    For each Horizon Edge Gateway, an Amazon Virtual Private Cloud (VPC) created in your target Amazon EC2 region with applicable address space to cover required subnets.
    The following subnet requirements are minimum. For larger environments, larger subnets might be required.
    • Management subnet — /26 minimum
    • Desktop (tenant) subnet - Primary — /27 minimum, but sized appropriately based on the number of desktops and RDS servers. You can add more subnets as required.
    • DMZ subnet — /27 minimum for the cluster of Unified Access Gateway instances (not required for Internal Unified Access Gateway Access Type). The DMZ subnet must be public.
    You must create subnets manually on the VPC as a prerequisite. See Configure network settings for an Amazon WorkSpaces Core Region. As a best practice, do not attach other resources to the subnets.

    For Unified Access Gateway, configure the Virtual Private Cloud (VPC) DNS server to point to a valid DNS server that can resolve both internal machine names and external names. See Configure Required DNS Records After Deploying Horizon Edge Gateway and Unified Access Gateway

    • For internal endpoints, Active Directory is an example.
    • For external endpoints, outbound internet access on the Virtual Private Cloud (VPC) you are using for the gateway deployment must resolve and reach specific DNS names using specific ports and protocols. This configuration is required for deployment and ongoing operations.
    Outbound Internet access on the VPC you are using for the Horizon Edge deployment must resolve and reach specific DNS names using specific ports and protocols. This is required for deployment and ongoing operations. For the list of DNS names and ports, see Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in an Amazon WorkSpaces Core Environment.
    Optional. Proxy server information if required for outbound internet access on the Virtual Private Cloud (VPC that is used during deployment and ongoing operations of the Horizon Cloud environment.
    Optional. AWS VPN configured, when you want networking between the Virtual Private Cloud (VPC) and your on-premises corporate network.
    Proxy - Add all configured proxy settings on workspaces core images at a system level.

    Ports and Protocols Requirements

    Specific ports and protocols are required for deployment and ongoing operations of your Horizon Cloud environment. See Port and Protocol Requirements for Your Horizon Cloud Deployment in Amazon Workspaces Core.

    Unified Access Gateway Requirements

    A cluster of Unified Access Gateway VMs is associated to a pool, which enables clients to have trusted Horizon Web Client connections to the VMs in that pool.

    You use the Horizon Universal Console to configure Horizon Cloud with the Unified Access Gateway. The items below are required for that type of configuration.

    For all configuration types, outbound Internet access to the following endpoint name is required:
    *.horizon.omnissa.com

    When Allow Internal Access Over a Corporate Network is the Unified Access Gateway Access Type, either user defined routing or NAT Gateway can be applied to the Management subnet to allow outbound traffic.

    When the Unified Access Gateway Access Type is configured externally with a DMZ network, external access to the following endpoint name must be configured on the DMZ network:
    *.horizon.omnissa.com

    For external as well as both external and internal Unified Access Gateway types, an internet gateway must be present in the VPC and the traffic from the DMZ subnet must be routed to the internet gateway.

    An internal FQDN, external FQDN, or both are required depending on the access type you select during the Unified Access Gateway configuration.
    • If you provide end users solely with internal access, a single FQDN is required.
    • If you provide end users solely with external access, a single FQDN is required.
    • If you provide end users with both internal and external access, you can configure either a single common FQDN or two separate FQDNs. If you want to isolate both internal and external access, configure separate URLs. Otherwise, the same FQDN can be configured for both internal and external access.
    Certificate or certificates for the Unified Access Gateway in PEM or PFX format matching the FQDN.

    Note: If the certificate or certificates that you supply for this purpose use CRLs (Certificate Revocation Lists) or OCSP (Online Certificate Status Protocol) settings that refer to specific DNS names, then you must ensure outbound Internet access on the Virtual Private Cloud (VPC) to those DNS names is resolvable and reachable. During configuration of your supplied certificate in the Unified Access Gateway configuration, the Unified Access Gateway software reaches out to those DNS names to check the certificate's revocation status. If those DNS names are not reachable, deployment fails. These names are highly dependent on the CA that you used to obtain the certificates.
    Follow the appropriate subnet guidelines depending on your Unified Access deployment mode:

    Basic Mode:
    • Management subnet — /26 minimum. You can use the same management subnet used for the Horizon Edge
    • Desktop (tenant) subnet - Primary — /27 minimum, but size appropriately based on the number of desktops and RDS servers. You can add more subnets as required.
    • DMZ subnet — /27 minimum for the cluster of Unified Access Gateway instances (not required for an internal Unified Access Gateway Access type).

    Advanced Mode:

    • Management subnet — /28 only. Use Management subnet — /28 only and use a different management subnet than the Management subnet used for the Horizon Edge.
    • Desktop (tenant) subnet - Primary — /27 minimum, but size appropriately based on the number of desktops and RDS servers. You can add more subnets as required.
    • DMZ subnet — /27 minimum for the cluster of Unified Access Gateway instances (not required for an internal Unified Access Gateway Access type).

    Understanding User Identity and Machine Identity

    Horizon Cloud differs from other environments in how it handles identity. In Horizon Cloud, the service makes a distinction between user identity and machine identity, and it relies on both types of identity when establishing a secure connection between a client and a remote desktop or application.

    Note: You might be new to this distinction between user identity and machine identity if you are more familiar with environments that use a single identity provider to authenticate both user and machine identity, such as the first-generation Horizon Cloud environment or a Horizon 8 on-premises environment.

    In Horizon Cloud, you must set up an identity configuration consisting of an identity provider to authenticate the user identity and an identity provider to authenticate the machine identity.

    • User identity

      Horizon Cloud requires you to register a user identity provider. The service uses this identity provider to authenticate client users attempting to access remote desktops and applications.

    • Machine identity

      Horizon Cloud also requires you to register a machine identity provider. The service uses this identity provider to establish the machine identity of virtual machines that provide remote desktops and applications.

      Through the machine identity provider, the service joins remote desktops and the virtual machine sources for remote applications to the trusted network domain that client users are entitled to access.

    Supported Identity Configurations

    Horizon Cloud requires you to register an identity configuration that consists of a user identity provider and a machine identity provider. Feature capabilities might vary depending on the particular identity providers included in the configuration.

    Horizon Cloud supports the following identity configurations.

    Supported Identity Configurations for Horizon Cloud

    Identity ConfigurationUser Identity ProviderMachine Identity ProviderFeature Considerations
    AMicrosoft Entra ID Commercial or Microsoft Entra ID GovernmentActive Directory
    • Supports SSO to remote desktops and applications.
    BMicrosoft Entra ID Commercial or Microsoft Entra ID GovernmentMicrosoft Entra ID
    • Does not support single sign-on (SSO) to remote desktops and applications.
    CWorkspace ONE Access Cloud or Workspace ONE Access On PremisesActive Directory
    • Supports SSO to remote desktops and applications.
    • Supports integration with Workspace ONE.
    • Just-in-Time directories are not supported.
    DOmnissa Identity ServiceActive Directory
    • Supports SSO to remote desktops and applications.
    • Windows 365 is not currently supported with this configuration.

    The following sections describe requirements for each supported user identity provider and machine identity provider.

    User Identity Requirements

    This section describes the requirements for the user identity provider that you choose to use in your identity configuration. Horizon Cloud supports Microsoft Entra ID and Workspace ONE Access as providers of user identity.

    In addition to the requirements described in this section, see the Supported Identity Configurations section for information about feature considerations and the machine identity providers that you can use with each user identity provider. For an overview of how Horizon Cloud manages identity, see the Understanding User Identity and Machine Identity section.

    • Microsoft Entra ID

      When Microsoft Entra ID Commercial or Microsoft Entra ID Government is your user identity provider, a user with Microsoft Entra ID Global Administrator privileges must do the following.
      • Approve the requested permissions.
      • Provide consent for the entire organization.
    • Workspace ONE Access

      When Workspace ONE Access Cloud or Workspace ONE Access On Premises is your user identity provider, a user with Administrator privileges must do the following.
      • Integrate the identity provider.
      • Configure required pre-requisites for Horizon Cloud integration.
    • Omnissa Identity Service

      When Omnissa Identity Service is your user identity provider, a user with Administrator privileges must do the following.
      • Integrate the identity provider.
      • Select Horizon Cloud to be used with Omnissa Identity Service.

    Machine Identity Requirements

    This section describes the requirements for the machine identity provider that you choose to use in your identity configuration. Horizon Cloud supports Microsoft Entra ID and Active Directory as providers of machine identity.

    In addition to the requirements described in this section, see the Supported Identity Configurations section for information about feature considerations and the user identity providers that you can use with each machine identity provider. For an overview of how Horizon Cloud manages identity, see the Understanding User Identity and Machine Identity section.

    • Active Directory
      Active Directory server with line-of-sight to the Horizon Edge Gateway instances and desktop subnets. For example:
      If you plan to connect your Active Directory using LDAPS, gather PEM-encoded root and intermediate CA certificates for your Active Directory domain. When you use the Horizon Universal Console to set up your Active Directory Domain, you are prompted at that time to upload the PEM-encoded root and intermediate CA certificates.
      Supported Microsoft Windows Active Directory Domain Services (AD DS) domain functional levels.
      • Windows Server 2016
      • Windows Server 2012 R2
      • Windows Server 2012
      Supported Microsoft Windows Active Directory Domain Services (AD DS) OS Versions.
      • Windows Server 2022
      • Windows Server 2019
      • Windows Server 2016
      • Windows Server 2012 R
      • Domain Bind Account

        Active Directory domain bind account (a standard user with read access) that has the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >.

        The account must have the following permissions:

        • List Contents
        • Read All Properties
        • Read Permissions
        • Read tokenGroupsGlobalAndUniversal (implied by Read All Properties)

        Set the account password to Never Expire to ensure continued access to log in to your Horizon Cloud environment.

        • If you are familiar with the Horizon on-premises offering, the above permissions are the same set that are required for the Horizon on-premises offering's secondary credential accounts.
        • Domain bind accounts are granted the default out-of-the-box read-access-related permissions typically granted to authenticated users in a Microsoft Active Directory deployment. However, if your organization's AD administrators have chosen to lock down read-access-related permissions for regular users, you must request those AD administrators preserve the authenticated users standard defaults for the domain bind accounts you will use for Horizon Cloud.
      Reference: Creating Active Directory Domain Bind and Domain Join Accounts
      • Auxiliary Domain Bind Account

        Must be separate from the main domain bind account. The UI will prevent re-using the same account in both fields. Active Directory domain bind account (a standard user with read access) that has the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >. The account must have the following permissions:
        • List Contents
        • Read All Properties
        • Read Permissions
        • Read tokenGroupsGlobalAndUniversal (implied by Read All Properties)
        Set the account password to Never Expire to ensure continued access to log in to your Horizon Cloud environment.
        • If you are familiar with the Horizon on-premises offering, the above permissions are the same set that are required for the Horizon on-premises offering's secondary credential accounts.
        • Domain bind accounts are granted the default out-of-the-box read-access-related permissions typically granted to authenticated users in a Microsoft Active Directory deployment. However, if your organization's AD administrators have chosen to lock down read-access-related permissions for regular users, you must request those AD administrators preserve the authenticated users standard defaults for the domain bind accounts you will use for Horizon Cloud.
      • Domain Join Account

        Active Directory domain join account which can be used by the system to perform Sysprep operations and join the virtual computers to the domain. Typically a new account that you create for this express purpose. (A domain join user account) The account must have the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >. The use of white spaces in the account's user name is currently unsupported. Set the account password to Never Expire to ensure continued ability for Horizon Cloud to perform the Sysprep operations and join the virtual computers to the domain. This account requires the following Active Directory permissions, applied to the Computers OU, or to the OU that you will enter into the console's Domain Join UI.
        • Read All Properties - this object only
        • Create Computer Objects - this object and all descendant objects
        • Delete Computer Objects - this object and all descendant objects
        • Write All Properties - Descendant Computer objects
        • Reset Password - Descendant Computer objects
        Regarding the target Organizational Unit (OU) that you plan to use for pools, this account also requires the Active Directory permission named Write All Properties on all descendant objects of that target Organizational Unit (OU).

        For more details on creating and reusing domain join accounts, see Creating Active Directory Domain Bind and Domain Join Accounts.

        In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.

      • Optional Auxiliary Domain Join Account

        Active Directory domain join account which can be used by the system to perform Sysprep operations and join the virtual computers to the domain. Typically, a new account that you create for this express purpose (A domain join user account).

        The account must have the sAMAccountName attribute. The sAMAccountName attribute must be 20 characters or less and cannot contain any of the following characters: "/ \ [ ] : ; | = , + * ? < >.

        The use of white spaces in the account's user name is currently unsupported.

        Set the account password to Never Expire to ensure continued ability for Horizon Cloud to perform the Sysprep operations and join the virtual computers to the domain.

        This account requires the following Active Directory permissions, applied to the Computers OU, or to the OU that you will enter into the console's Domain Join UI.
        • Read All Properties - this object only
        • Create Computer Objects - this object and all descendant objects
        • Delete Computer Objects - this object and all descendant objects
        • Write All Properties - Descendant Computer objects
        • Reset Password - Descendant Computer objects
        Regarding the target Organizational Unit (OU) that you plan to use for pools, this account also requires the Active Directory permission named Write All Properties on all descendant objects of that target Organizational Unit (OU).

        In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.
      • Active Directory organizational unit (OU) or units (OUs) for virtual desktops and RDS session-based desktops or published applications or both.

        In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Cloud console.

      Image Management System Requirements

      Your Amazon WorkSpaces Core account must accommodate the following requirements depending on the types of images you want to provision from the deployed Horizon Edge.

      Base for the image. One or more of the supported Amazon WorkSpaces Core hardware model configurations.

      Ensure that you do not exceed the quota limitations for Amazon WorkSpaces. See the AWS documentation for Amazon WorkSpaces quotas. The following model types are the default and recommended.

      Non-GPU:
      • Value – 1 vCPU, 2 GB Memory
      • Standard – 2 vCPU, 4 GB Memory
      • Performance – 2 vCPU, 8 GB Memory
      • Power – 4 vCPU, 16 GB Memory
      • PowerPro – 8 vCPU, 32 GB Memory
      • GeneralPurpose.4xlarge – 16 vCPU, 64 GB memory
      • GeneralPurpose.8xlarge – 32 vCPU, 128 GB memory
      GPU-Enabled:
      • Graphics.g4dn - 4 vCPU, 16GiB memory,1GPU, 16 GiB video memory, 125 GB local instance store
      • GraphicsPro.g4dn - 16 vCPU, 64GiB memory,1GPU, 16 GiB video memory, 225 GB local instance store
      Model types besides the Non-GPU and GPU-Enabled types listed are supported, though not necessarily verified. Ensure you have enough quota in your subscription if you select one of these models.

      Pool VM Requirements

      Your Amazon WorkSpaces Core must accommodate the following requirements depending on the types of pool VMs you want to provision from the deployed Horizon Edge.

      Model selection for the VMs in pools — any of the Amazon WorkSpaces Core hardware model configurations available in the Amazon WorkSpaces Core region, except for those not compatible with Horizon Cloud desktop operations.

      Consider the following details when selecting a VM model.
      • The decision to select between a GPU-enabled model type and Non-GPU model type depends on the VM selected during image creation.
      • To create a multi-session pool, select an image created using a multi-session operating system.
      • For production environments, scale testing recommends using models that have a minimum of 2 CPUs or larger.
      • See the AWS documentation about Amazon WorkSpaces Core Pricing to learn about the compatibility of different Amazon WorkSpaces Core hardware model types and sizes with Horizon Cloud.

      Horizon Client and Horizon Web Client Requirements

      Ensure that your end users use a supported client to access their service-provided resources. See the list at Release Notes - Client Support section

      Tip: When end users connect to Horizon Cloud using a browser, their connections automatically use the latest version of the Horizon Web Client.

    Questa pagina è stata utile?

    Invia un feedback su questo argomento

    Questo argomento è stato utile?

    Non includere informazioni personali o riservate.

    Generazione del link…