Skip to main content

2 settembre 2026

Managing Images for Microsoft Azure Provider Deployments

As you use IMS with Horizon Edge in Microsoft Azure deployments, there are some requirements and considerations to be aware of. Your Horizon Edge in Microsoft Azure deployment must adhere to these requirements.

Microsoft Azure - Overall Horizon Edge Requirements

In addition to the details at the preceding linked pages, for IMS operations to work successfully and be supported with your deployments, those deployments must also adhere to the following requirements. If your deployments do not continue to meet these requirements, unexpected results might occur and the image management operations might fail. The publishing operation is especially sensitive to these requirements.

Microsoft Azure Quota Requirements

Your Microsoft Azure subscriptions must have enough quota for the VM models you plan to select for image management operations. For the recommended model types to use for the image base VM, refer to the Requirements Checklist for Deploying a Microsoft Azure Edge.

Service Principal Requirements

The service uses API calls to work with resources in your Microsoft Azure subscriptions. To have successful operations, for as long as the service principals are registered for use with your Horizon Edge in Microsoft Azure deployments, you must ensure that they:

  • Continue to meet the requirements described in that page.
  • Are not expired and do not reach their expiration date.
  • Remain in the Azure Portal and are not deleted.

Microsoft Azure Subscription Application Key(s)

Microsoft Azure Subscription keys (secret keys) do expire. Before the final day passes and the key expires, use the Microsoft Azure portal to create a new key for the subscription. Then immediately change the stored subscription information in the Horizon Universal Console to start using the new key. When the subscription information on both sides matches — the Microsoft Azure portal side and the Horizon Universal Console side — the subscription information stored in your Horizon Cloud environment remains viable for use with the edge already deployed in that subscription.

From the Microsoft Azure portal, you can change the Subscription Name, Application ID, and Application Key. Even though the Application Key field has the icon to view the key, the key stays hidden. To type in a new subscription name, click Edit next to the Subscription Name menu in the Manage Subscription window. Note: The Environment, Subscription ID, and Directory ID values cannot be updated.

Windows Image Publish — Sysprep Prerequisites and Considerations

When publishing a Windows image, Horizon Cloud generalizes the VM by running Sysprep inside the guest OS using Azure Run Command. The following requirements and considerations may apply.

Prerequisites

  • Prior interactive login not required: A prior interactive login to the image VM is not required before publishing for any supported Windows version.

  • Windows 11 24H2 and later - VM credentials must be valid: Horizon Cloud uses the local administrator credentials provided when the image was added to run Sysprep on Windows 11 24H2 and later images. Ensure these credentials remain valid at publish time. If the password was changed or the account was disabled after image import, use the Reset VM Password option in the Horizon Universal Console before starting the publish workflow. Reset VM Password is not available after a publish operation has started or failed.

  • Local administrator account must be enabled (Windows 11 24H2 and later): Ensure the local administrator account on the VM is active and not disabled.

  • Azure Run Command must be permitted: Azure Run Command must not be blocked by Azure policies, network rules, or security solutions on the image VM.

Considerations

  • BitLocker-encrypted drives: If the image VM has BitLocker encryption enabled on Windows 11 24H2 or later, the publish workflow automatically initiates decryption before running Sysprep. This may increase the total publish duration depending on drive size.

  • Publish duration: The overall publish time includes Sysprep execution and a generalization monitoring phase. Avoid shutting down or deallocating the VM during this period.

Troubleshooting

  • If publish fails with a Sysprep-related error, the Horizon Cloud service fetches Sysprep error logs from the image VM and displays an error message in the image version details page to surface the error cause. If the error is not visible in the HCS console, check the Sysprep error log at C:\Windows\System32\Sysprep\Panther\setuperr.log on the image VM.

  • If publish fails on Windows 11 24H2 or later with an authentication error, verify that the local administrator account used for the image is not subject to a "Deny log on as a batch job" Group Policy restriction. This policy, if explicitly applied to local administrator accounts, can prevent Sysprep from running under the image's admin credentials. This restriction does not apply to most environments — local administrator accounts have this privilege granted by default.

Horizon Cloud System-Defined Allowed AppX Packages

When importing an Azure image, Horizon Cloud retains some AppX packages (files with extension .appx) based on an internal system-defined allow list. These packages are in the system’s allow list by default and remain in the resulting base VM at the end of the import process. After Azure image import, do not delete any of the following packages.

Microsoft.DesktopAppInstaller
Microsoft.Messaging
Microsoft.MSPaint
Microsoft.OutlookForWindows
Microsoft.Windows.Photos
Microsoft.MicrosoftStickyNotes
Microsoft.WindowsCalculator
Microsoft.WindowsCommunicationsApps
Microsoft.WindowsSoundRecorder
Microsoft.WindowsStore
Microsoft.WindowsNotepad
Microsoft.ScreenSketch
Microsoft.Xbox.TCUI
Microsoft.XboxApp
Microsoft.XboxGameCallableUI
Microsoft.XboxGameOverlay
Microsoft.XboxGamingOverlay
Microsoft.XboxIdentityProvider
Microsoft.XboxSpeechToTextOverlay
MSTeams
Windows.CBSPreview
windows.immersivecontrolpanel
Windows.PrintDialog
Microsoft.Paint
Microsoft.ZuneMusic

Resetting the VM Password for Images with Microsoft Azure

As long as your image is in an imported and unpublished state, you can now reset the vm password. Log in to the Horizon Universal Console and under your image resources select the image or image version that you need to reset. Once selected the Reset VM Password button will become available.

Questa pagina è stata utile?

Invia un feedback su questo argomento

Questo argomento è stato utile?

Non includere informazioni personali o riservate.

Generazione del link…