Skip to main content

2 settembre 2026

Create a Pool

You can add pools to your environment from the Horizon Universal Console. After you have at least one image added in the Horizon Universal Console, you can create a pool based on that image.

From the console, select Pools from the left menu. Your list of Pools is shown in a table format. The menu button options are: Add, Edit, Delete, Provisioning and an Ellipsis (...) button that shows more options. When you select a specific Pools checkbox, these menu buttons will show up or gray out as needed. If you scroll to the bottom of the table, there is a button to Manage Columns that allows you to select what columns you want to be shown or hidden in the table.

Before selecting the Add button to create a pool, make sure the following prerequisites have been made.

Prerequisites

Before creating a pool, ensure that the following requirements are in place:

  • End-user identity provider: Verify that you have configured an identity provider to use for end-user identity. If using Microsoft Entra ID as the identity provider for user identity, verify that Microsoft Entra ID Connect configuration is complete. For related information, refer to Identity and Access Management in Horizon Cloud.

  • Machine identity provider: Verify that you have the configuration in place for a machine identity provider. This provider establishes the machine identity of virtual machines that provide remote desktops and applications. When you are using Microsoft Entra ID for end-user identity, machine identity for Linux pools must be provided by a customer-managed Active Directory domain. Linux virtual machines do not support Microsoft Entra ID as a machine identity provider.

    Note: When using Microsoft Entra ID for machine identity, be mindful that when deleting a Microsoft Entra ID joined pool or VM, the pool's specified provider requires specific permissions to delete the device entry from Microsoft Entra ID when the pool or VM is deleted.

  • Required permissions are:

    • Scope: Microsoft Graph (https://graph.microsoft.com)
    • Permission: Device.ReadWrite.All Read and Write devices
    • Admin Consent Required: Yes
  • To use the Microsoft Azure portal to add the application permissions to the provider's service principal, navigate to App Registrations, select the service principal's app registration, and use the Azure Portal's API permissions to add Microsoft Graph application permission Device.ReadWrite.All.

  • If you use your Active Directory domain for machine identity, ensure that you have configured the Active Directory domain. For more information refer to Setting up Your Active Directory Domain.

  • When using Workspace ONE Access for end-user identity, you must configure an Active Directory domain to use for the machine identity.

  • Ensure the Horizon Edge is created successfully and the Horizon Edge Gateway and UAG deployments are displaying healthy (green) states in the Horizon Universal Console at Capacity > Horizon Edges.

  • Ensure that the VDI or multi-session image which you will use in this pool is published successfully. You can check the image state in the Horizon Universal Console at Images.

  • UEM Requirement: Horizon Cloud and Workspace ONE UEM must be configured to use the same Active Directory domain.

  • Workspace ONE Intelligent Hub must be installed in the VM Image before creating a dedicated single-session pool managed by Workspace ONE UEM.

  • Workspace ONE Intelligent Hub version 25.06.1 or later.

  • Horizon Agent version 25.2.0 or later.

  • The enrolment OG setting must be configured for Intelligent Hub Managed Mode.

Microsoft Azure Dedicated Host Prerequisites

Before attempting to create a Microsoft Azure pool, you must complete the following steps in Azure to use the Azure dedicated host feature.

  • Create a Host Group, select the Availability Zone if required (which can only be managed through Azure) and enable the Automatic placement option.

  • Create/add one or more Hosts to the Host Group.

After these steps are completed, you can enable the toggle Use Azure dedicated hosts when creating a pool. Once activated, a list of available associated Host Groups is visible. For more information refer to Microsoft's site: Azure Dedicated Hosts.

Support for Microsoft Entra ID Hybrid Joined Desktops

For information about Entra ID hybrid join support for desktop pools, see Support for Microsoft Entra ID Hybrid Joined Desktops.

Procedure

  1. From the Horizon Universal Console, select Pools in the left menu.

  2. Click Add and then select your preferred provider type.

  3. Enter a unique Pool name and add a Description.

  4. For Microsoft Azure pools, select either Windows or Linux as your Operating System. The selected operating system determines the available pool types, image options, and licensing requirements in subsequent steps.

  5. Select a Pool type.

    • Dedicated single-session for the persistent VDI desktop experience where each desktop is mapped to a single user.

    • Floating single-session for the non-persistent VDI desktop experience where multiple users can use the desktop at different times and the desktop resets after each user session.

    • Multi-session for session-based published desktops and applications.

  6. Under the Desktops section, you will see many subsections. Under the Destination subsection, select your options to complete the Site, Horizon Edge, and Provider drop downs.

    • For a Microsoft Azure Pool, if you have dedicated host groups configured, enable the toggle to Use dedicated host. Then select the Host Group.

    • If you are using a dedicated host the option to enable Use availability zones will be disabled as they are configured directly by the cloud provider.

    • When you enable Use Azure Availability Zones, the VMs for a pool are distributed across all the availability zones to prevent downtime of all the VMs in the pool if a failure occurs in a given availability zone. Note: Amazon availability zones are specified in the Networks section below. For more information, refer to: Azure services that support availability zones.

    • Enable Hibernate toggle to active for Microsoft Azure and/or Amazon WorkSpaces Core Dedicated Single-Session Pools. Important: Once the pool is enabled for hibernation, you will not be able to remove that ability from VMs as well. Refer to Hibernate Pools and Virtual Machines for more information.

  7. In the Image subsection, set the Generation type and then select the Image from the drop down.

    For a Microsoft Azure Pool, both generation 1 and 2 image VMs are supported. If you select V1, only images with a Microsoft Azure generation 1 VM and models that support generation 1 can be selected. Your selection for the Generation type acts as a filter to determine which images are listed in the Image and Model drop-down menus.

    Note: For Microsoft Azure pools, when Linux is selected as the operating system, only Generation V2 images are supported. When Linux is selected, the Image list is automatically filtered to display only Linux images.

  8. Select the Marker of the image selected.

    For a Microsoft Azure Pool, you must use one or more markers or tags to later edit the pools of an image version. For more information refer to Add Version to an Existing Microsoft Azure Compute Gallery Image, also Using Azure Resource Tags and Using Amazon Resource Tags.

    Note: If a marker associated with an older agent version is selected, a warning message is displayed. As a best practice, select a marker with the latest agent version.

  9. Specify the operating system license details.

    • For Windows pools, enable Do you have a valid license for this Windows OS and confirm that you have an eligible license.

    • For Linux pools, enable Do you have a valid license for this Linux OS and select one of the following license options:

      • Pay as you go (PAYG)
      • Bring your own subscription (BYOS) Note: BYOS is supported only by RHEL-based Linux operating systems. Ubuntu supports both PAYG and BYOS licensing options.
    • After selecting the License type, select the required confirmation check boxes to confirm that you have an eligible license and that the required Horizon Agent version is used.

  10. In the VM details subsection, specify the VM details information. Content differs depending on your selected provider type. Some options, such as hibernate, depend on your selected pool type.

    For Amazon WorkSpaces Core Pools specify the following options:

    • Hardware

    • Show only hibernate enabled hardware toggle

    • Power Management (Always On) toggle

    • User Volume in GBs

    • User Volume Encryptions Disks toggle

    • Root Volume in GBs

    • Root Volume Encryption Disks toggle

    • Enabling the Always On Power Management toggle ensures that all VMs in the desktop pool remain powered on continuously. A fixed monthly fee is applied to each VM upon provisioning and is charged at the beginning of each month. This option is recommended for pools with VMs that are used for over 80 hours per month, as it can result in cost savings during periods of high usage.

    • Disabling the Always On Power Management toggle activates Horizon Power Management, allowing power management policies and schedules configured in the pool group to take effect. The fixed monthly fee will still apply for the current month but starting from the first day of the following month, VMs will be billed at an hourly rate.

    For Microsoft Azure Pools

    • Select a Microsoft Azure VM Model type to use for the pool or accept the default. The Model setting refers to the compatibility of different Microsoft Azure VM types and sizes with Horizon Cloud. To select a different model, click the X, then click the drop-down menu, and select a model. Refer to: Microsoft Azure VM Types and Sizes for Horizon Cloud (89090) for more information.

    • If you are using the Azure dedicated host option, VM models will be filtered based on the models available to the selected Azure Host Group.

    • Use the Filter Model settings to reduce the number of Microsoft Azure VM model options listed when you configure the Model setting, if not the list of models is very long. You can filter the Microsoft Azure VM model list by Tag, CPU, RAM, Series, GPU Type, and Disk Type. Click + to add other filters. The reduced list includes a subset of models based on your specific requirements.

      FilterOperatorDescription
      Tagequals- Recommended: Microsoft Azure VM models that work particularly well for pools.
      - High Performance: Azure VM models that offer premium disk support.
      - Custom: Custom tags that can be added and configured by the administrator.
      CPUequalsThe CPU filter uses a from/to range to define acceptable CPU values.
      RAMequalsMemory uses a from/to range to define acceptable RAM values.
      SeriesequalsUse the drop-down menu to view the list of Azure VM series and select the one that best fits your needs.
      GPU TypeequalsUse the GPU Type filter to select GPU-enabled Azure VM models:
      - NONE: Filters out GPU-enabled models.
      - AMD: Includes only AMD GPU-enabled models.
      - NVIDIA: Includes only NVIDIA GPU-enabled models.
      Disk TypeequalsUse the Disk Type filter to select Premium, which provides premium disk support.
    • You can change the Disk Size value based on the selected operating system. The default disk size depends on the selected operating system.

      • For Linux desktop pools, the minimum supported disk size is 30 GB.
      • For Windows desktop pools, the supported disk size range is 127 GB to 4095 GB.
    • When you create or edit a pool you have the option of increasing the OS disk size value. When that option is used, the OS disk of each VM in that pool is created with that size. However, because of default behavior of VMs in Microsoft Azure, even though the VM’s disk is expanded, the partition containing the C drive is not expanded to encompass the entire disk. That new space on the VM’s disk is unused until you take actions in the VM to expand the C drive partition to encompass the new space.

    • If you want to encrypt disks for all VMs in this pool, enable the Encrypt Disks toggle.

      • Preventing Encryption Conflicts: When Horizon disk encryption is enabled for a pool, do not centrally manage BitLocker through Group Policy, Intune, or equivalent MDM policies for those specific virtual machines. For more information on these limitations, see Microsoft's Azure Windows VM disk encryption overview.

      Note:

      • Disk encryption for managed VMs is supported using Azure Disk Encryption (ADE).
      • Other disk encryption configurations (including customer-managed key models outside of Azure Disk Encryption) or changes performed directly in Azure are not supported for VMs managed by Horizon Cloud.
      • Disk encryption is not supported by Linux desktop pools.
    • With the Auto Scale toggle enabled, you can select both the running and stopped disk type. When the VMs are powered off, the disk types are set and auto-converted. Once powered back on, the disk type returns to its original settings.

      The Auto Scale toggle can be enabled in two places. It can be toggled on in the Create a Pool page and/or from the Horizon Universal Console main left menu under the global Settings > Pool Settings > Manage. To set a global policy, use the global Settings > Pool Settings > Manage page. However, if only specific desktop pools need this feature, use the toggle on the Create a Pool page to activate or deactivate the toggle when creating a pool. The toggle specified on the Create a Pool page takes precedence over the Settings > Pool Settings > Manage page.

      Note: Changing the model used by an existing pool will only affect new VMs. Existing VMs in the pool will continue to use the previously selected model.

    • You can label a model as hidden if they do not want the model to be available for new pools however, a hidden model can continue to be used by an existing pool. A model will be marked deprecated if Microsoft Azure no longer provides the model. When editing a pool, if the currently selected model is marked as deprecated, update the model to a different one to allow the pool to create more virtual machines in the future, e.g. when expanding the pool.

  11. In the Machine Identity (Domain) subsection, select a Machine Identity provider to use for this pool.

    • The Defer VM availability until hybrid join option is available for Microsoft Azure if the specified Machine Identity provider is an on-premises Active Directory server. Enabling this option allows the pool to access both on-premises and cloud-based resources. Refer to the onscreen help for the prerequisites that are required for using this option.

    • The Active Directory domain is configured in your Horizon Cloud environment for the purpose of providing machine identity. With this selection, you can replace the default CN=Computers organization unit (OU) with a specific Computer OU into which the pool's machines will be created in that Active Directory domain. By default, the pool's machines are created in CN=Computers.

    • When you select Microsoft Entra ID, the Computer OU field is deactivated because the system doesn't use computer OUs in this case.

      When using Microsoft Entra ID for the pool's machine identity, you must configure RBAC in Microsoft Entra ID so that only the users or user groups that have Virtual Machine Administrator Login or Virtual Machine User Login role can log into their entitlements.

      Note: For Linux desktop pools, Microsoft Entra ID is not supported as a machine identity provider. Linux virtual machines must join a customer-managed Active Directory domain.

    • When you configure RBAC at the resource group level, to help identify the resource groups associated with the Microsoft Entra ID joined pools, the following tags are used on the pools' resource groups:

      • pool-name: indicates the pool name entered when creating the pool
      • add-joined: if set with true, it indicates the VMs from the pool are Microsoft Entra ID joined machines

      Note: For Microsoft Azure pools, when Linux is selected as the operating system, the following limitations apply:

      • Single sign-on (SSO) using Microsoft Conditional Access is not supported.
      • Only the default 'CN=computers' organizational unit (OU) is supported for machine identity.
      • Microsoft Entra ID is not supported as a machine identity provider for Linux desktop pools.
  12. If using the Amazon WorkSpaces Core provider type, in the Machine Identity (Domain) section, specify a Directory ID. This will be directly created in the Amazon Web Services (AWS) Console.

    • During pool creation, Omnissa automatically generates and configures a Network Security Group (NSG) that is attached to your WorkSpaces directory. This preconfigured NSG implements security controls optimized for all workspaces registered under this directory. The automatically provisioned NSG is specifically designed for WorkSpaces environments and ensures proper connectivity and security.

    • Avoid custom security groups. Attaching custom security groups to WorkSpaces directories can lead to connectivity issues and unpredictable behavior. Configure your network to allow all inbound traffic from your VPC to Active Directory rather than creating AD rules (inbound/outbound) based on security groups used in the WorkSpaces directory. These recommendations help prevent connection failures, streamline troubleshooting, and maintain consistent security across your environment.

    • If you choose to implement a custom security group despite these recommendations, ensure it includes all required inbound and outbound rules for desktop connectivity. For assistance with custom configurations, please contact our support team at Omnissa Customer Connect.

    • For Windows Server images, the workspace directory tenancy must be set as SHARED.

    • For Windows 10/11 images, the workspace directory tenancy must be set as DEDICATED. This requirement also applies to dedicated pools.

    • Administrative Unit (AUs) can also be selected to have the device ids of the Entra ID-joined pool VMs as members of the selected AU and to restrict permissions scope. This feature is optional and can be selected when creating a Microsoft Entra ID-joined pool. However, once the pool is created, the AU field’s value cannot be changed when the pool is reusing VM names.

    Note:

    • AUs are not supported for Linux desktop pools.
    • All Windows 11 and Windows 10 devices are supported, except Home editions Windows Server 2019 and newer Virtual Machines running in Azure (Server core is not supported).
  13. In the Provisioning subsection, select how your VMs are provisioned:

    • All at once: All VMs in the pool are provisioned at the time the pool is created.

    • On-Demand: VMs are provisioned as they are needed. When this option is selected, the Simplify Provisioning toggle appears.

      • When the toggle is Enabled (recommended), the pool uses the Pool Group spare capacity percentage setting. Pool-level minimum and maximum spare settings are ignored, giving you centralized, consistent control across all pools in the group.

      • When the toggle is disabled, the pool falls back to the legacy spare configuration and provisioning is managed individually at the pool level.

    • Simplify Provisioning is Enabled by default for all newly created pools and is recommended for most environments. Existing pools can be migrated at any time by enabling the toggle. Warning: Enabling Simplify provisioning may change the number of spare VMs maintained.

    • If On-Demand is selected with Simplify Provisioning disabled, you have to specify the number of Minimum spare VMs and Maximum spare VMs for this pool.

      • Note: Spare VMs are VMs not currently in use that are powered on and ready for new user sessions. The system tries to maintain spare VMs equal to (Minimum spare VMs + Maximum spare VMs) / 2. Provision and deprovision operations are triggered based on the difference between the existing spare VMs and this target.
  14. In the Properties subsection, configure as needed.

    • VM name prefix - Enter a prefix to use for the pool's VMs.

    • Reuse VM names - This setting governs how VM names are recycled. The available name range is determined by the Maximum VMs setting configured in the Provisioning section.

      • Important: You must enable this toggle during pool creation if you want to use this feature. If left OFF, it cannot be enabled or edited later.

      • When enabled, you can choose one of the following policies (you can switch between these two policies later by editing the pool):

        • Reuse VM names when possible: Reuses names from deleted VMs. If no previously used names are available, the system might generate new names outside the configured pool range. Requirement: Ensure your domain join account has the necessary permissions to reuse existing computer accounts.
        • Restrict VM names to configured range: Strictly limits VM names to the defined pool range. New VMs will only reuse names from deleted VMs, and the system will never create names outside the configured range.
    • Time zone - Select the time zone that the VMs should use. If the clock should automatically be adjusted for daylight saving time, select the check box. Note: this time zone option is not currently available for the Amazon WorkSpaces Core provider type.

    • Desktop admin username and Desktop admin password - Enter the credentials for the local admin account used to access the image's operating system, and to use during the image conversion process. You can edit the admin credentials from pools when adding additional VMs, this means that any new VMs added will have different admin credentials than the original ones had. Note: for Amazon WorkSpaces Core, these credential fields are not currently used in any pool operations.

    • Use outbound proxy - You can enable this toggle to route outbound requests to the Internet through a proxy server. The Time zone option is not present for the Amazon WorkSpaces Core provider type.

  15. (Optional) To add Resource Tags for Microsoft Azure and Amazon WorkSpaces Core, expand the Advanced subsection.

    If inherited tags exist, they will be displayed here. Click Add to add a tag that will be applied to the resource groups specific to this pool, click Done when you finish. For more information refer to Using Azure Resource Tags and Using Amazon Resource Tags.

  16. (Optional) To use a Post Customization Script, expand the Advanced subsection and provide the information needed.

    This optional feature allows admins to run a one-time script at the end of provisioning the VMs and before the machine is made available for end users to connect to.

    • Post customization script path (optional): The path to the script that will be run during VM provisioning. Example: C:\windows\system\script.exe

    • Post customization script parameters (optional): Parameters or values required for the script to run successfully. Example: parameter1 parameter2

    • Script execution time (optional): Specifies the duration the system will wait after starting the script on a VM before marking it as available for user sessions. Use this delay to allow scripts to fully execute. This delay ensures that script has enough time to complete, functioning similarly to a fixed static timer.

    • Mark VM deployment as failed if the script fails to start: When enabled, this setting will mark the deployment as failed if the script fails to start. However, if the script starts but encounters an issue during execution, the deployment will still be considered successful.

    Note: The post-customization script will run on only newly provisioned VMs with agent version 25.3.0 or higher. Existing VMs or those with earlier agent versions will not execute the script.

  17. Click Next to save your changes and move to the Networks section.

  18. The Networks section content differs depending on your selected provider type.

    • For Microsoft Azure, select the virtual networks and tenant (desktop) subnets for Microsoft Azure. Note: The Azure dual-stack option cannot be modified when you edit a pool.

    • For Amazon WorkSpaces Core, set the specified VPC options for both Availability Zone 1 and its Subnet, and Availability Zone 2 and its Subnet. Refer to Availability Zones for WorkSpaces Personal for more information.

    • Important: Amazon WorkSpaces Core prevents changing subnets for registered WorkSpaces directories. Once a WorkSpaces directory is registered with specific subnets, the subnet configuration cannot be modified without first deregistering the directory. This process requires removing all workspaces from that directory because existing pools cannot have their network configuration modified and any new pools created using the same directory will inherit identical subnet configurations. This limitation necessitates careful planning of subnet allocation during initial network configuration.

    • By default, virtual desktops use IPv4 addresses. If you want the virtual machine to use IPv4 and IPv6 addresses, activate the Enable dual-stack support option and select subnets that are configured as dual stack. Note: When you enable the dual-stack option, only subnets that are configured as dual stack are listed.

  19. (Optional) The Dynamic Environment Manager is an optional feature you can configure.

  20. In the Workspace ONE Unified Endpoint Management (UEM) section, toggle ON: Enroll in UEM to enable it.

    Note: Only newly created Dedicated and Floating desktop pools are supported. If any other pool type is selected, the option to manage desktops with UEM will not be available.

    Review the confirmation dialog indicating that Intelligent Hub must be installed in provisioning mode on the gold image/template.

    Once Enroll in UEM is enabled, enter the following required fields:

    • UEM device services server URL
    • Organization group ID
    • Staging username
    • Staging password

    Important: Any typos in the UEM parameters will cause new VMs to fail automatic enrollment into Workspace ONE UEM. The system will validate parameter formats (basic format checks).

  21. Click Save to save the newly created pool for your environment.

  22. The system will then prompt you to either add the pool you just created to a pool group or to select finish.

Results

When you see a pool listed on the main Pools page, you can perform actions on the pool such as editing the pool's definition and deleting the pool. For a pool that doesn't have an associated pool group, you can add a pool to a pool group by selecting the pool and clicking Add to Pool Group.

Note: UEM enrollment status updates in the Horizon Control Plane are processed asynchronously. Allow some time for the enrollment status to appear after enrollment actions. Upon first user logon, the device will be automatically enrolled to Workspace ONE UEM and a new device record will appear under Devices > List View in the Workspace ONE UEM console. If enrollment fails on the UEM side, the device status may remain as Pending.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…