This cloud- and web-based console is the user interface for your single point of control for managing and monitoring your first-gen Horizon Cloud environment and your cloud-connected pods.
Attention: This information applies solely when you have access to a first-gen tenant environment in the first-gen control plane. As described in KB-92424, the first-gen control plane has reached end of availability (EOA). See that article for details.
As of August 2022, Horizon Cloud is generally available and has its own guide, Using Horizon Control Plane Horizon Cloud.
An indication of which environment you have, Horizon Cloud or first-gen, is the pattern that appears in the browser's URL field after you log in to your environment and see the Horizon Universal Console label. For a Horizon Cloud environment, the console's URL address contains a portion like /hcsadmin/. The first-gen console's URL has a different section (/horizonadmin/).
Remember: The Horizon Universal Console is dynamic and reflects features that are appropriate for the up-to-the minute configuration of your tenant environment. Access to features described in this documentation can depend on factors including, and not limited to:
- Whether the feature depends on system code available only in the latest Horizon Cloud pod manifest, Horizon pod version, or Horizon Cloud Connector version.
- Whether access to the feature in Limited Availability, as stated in the Release Notes at the feature's debut.
- Whether the feature requires specific licensing or SKUs.
When you see mention of a feature in this documentation and you do not see that feature in the console, first check the Release Notes to see if the feature's access is limited and the way you can request enablement in your tenant. Alternatively, when you believe you are entitled to use a feature that is described in this documentation and you do not see it in the console, you can open an informational (non-technical) service request (SR) using your Customer Connect account at https://customerconnect.omnissa.com.
Browser Experience
The console is compatible with recent versions of Google Chrome, Mozilla Firefox, and Microsoft Edge. Use of the console in Microsoft Internet Explorer 11 is deprecated and will give a sub-optimal experience. The console is not supported for use in Apple Safari, although you can try using the console in Apple Safari. If you attempt to access the console using a non-modern browser such as Microsoft Internet Explorer 11, the console displays an information message to use an up-to-date browser. For the best user experience, use the most recent versions of Google Chrome, Mozilla Firefox, and Microsoft Edge.
Navigation and Functional Areas
On the left side of the interface is the Navigation bar, providing a hierarchy for navigating to the main areas of the user interface. The following table describes each area starting with at the top of the bar.
| Category | Functional Areas |
|---|---|
| Monitor | The Monitor category provides access to the unified dashboard, activity monitoring, reports, and notifications. For an overview of the pages in this category, see About the Monitor Menu in the Horizon Universal Console and topics First-Gen Tenants - Horizon Cloud Dashboard - Health Visibility and Insights into Your Pod Fleet and Tenant Environment, Activity Page, Reports Page, and Notifications Page. |
| Assignments | The Assignments category provides access to assignments and assignment-related actions and workflow. For an overview of the pages in this category and links to the various assignment-related workflows you can do with assignments, see About the Assignments Menu in the Horizon Universal Console. |
| Inventory | The Inventory category provides access to desktop-as-a-service artifacts from your pods, such as imported base VMs, sealed images, farms, and applications. For an overview of the pages in this category and tasks you can do in them, see Viewing Assets in Your Horizon Cloud Tenant's Inventory. Note: Many of this category's pages are only applicable to pods in Microsoft Azure. |
| Settings | The Settings category provides access to pages that involve settings and configurations in your environment. For an overview of the pages in this category and the tasks you can do in them, see Settings Menu. |
For example, in this release, some areas of the console are applicable only for Horizon Cloud pods deployed in Microsoft Azure. Horizon Cloud pods are those deployed into Microsoft Azure by the console's automated pod deployment wizard and which run the pod-manager software technology. When your cloud-connected pod fleet consists of only Horizon pods — pods that are running the Horizon Connection Server software — those areas that are applicable only for the pod-manager-based pods display a graphic and message. The following screenshot is a portion of what is displayed.

When your cloud-connected pod fleet includes both Horizon Cloud pods and Horizon pods, you might see an explanatory banner on various pages.
Upper Toolbar
In addition to the Logout action under the logged-in user name, the upper part of the console provides:
- The console's search feature to search users or VMs (
). For more information, see Using the Console's Search Feature. - Notifications (
). For more information, see Notifications Page. - Support-related information (
) such as what's new in the current service level, Web-based documentation, build information, and requesting support. - Language selector, to display the console in its supported languages.
About the First-Gen Horizon Universal Console's Navigation Menus and Using the Filter Fields
This documentation page describes how to use the first-gen console's navigation menus and filter fields.
Left-Hand Navigation Menus
The first-gen console's menus provide a quick way to navigate to monitor activity and perform various functions in your Horizon Cloud environment. These menus are located along the left side of the console.
| Menu | Description |
|---|---|
| Upper left icon | If you set the Getting Started page as your default landing page, clicking this icon displays the Getting Started page. See Getting Started Page - Overview. Otherwise, clicking this icon displays the Dashboard page. |
| Monitor | Provides access to:
|
| Assignments | Provides access to the console's assignments-related area from which you can work with assignments that entitle end-user access to those assignable items that are in your environment's inventory. Tip: The console is dynamic and reflects the workflows and settings that are appropriate for the up-to-the-moment situation in your Horizon Cloud tenant environment. The labels displayed for the console's assignment-related pages will vary depending on factors such as the tenant's configured brokering setting, the types of cloud-connected pods in your fleet, the tenant's regional cloud plane, and features that are based on specific licensing. |
| Inventory |
When your environment has pods deployed in Microsoft Azure, this console area provides access to work with assets such as:
|
| Settings | Provides access to screens from which you can work with system-wide settings and configurations for various system areas such as:
|
About the Monitor Menu in the Horizon Universal Console
Use Monitor to navigate to various dashboards, displays, and reports. You can explore details about usage of your environment, the administrator and user activity in the environment, see system notifications, and view various reports.
Click Monitor to navigate to these pages.
| Option | Description |
|---|---|
| Dashboard | Displays information about your overall environment: pod health status, capacity and utilization levels, end-user activity, and more. |
| Activity | Provides activity details for administrators and end users, and audit logs. |
| Reports | Provides access to various pre-defined reports, including how users are mapped to desktops. |
| Notifications | Lists notifications, which provide information about the system, such as important events. |
Activity Page
Use the Activity page to access data regarding current and past events in the system.
The Activity page is available from the Monitor icon. The page contains tabs for administrator events, user events, and audit logs for events initiated on your pods.
Available Actions
Each of the Activity page's tabs provides for the following actions:
- Filter the events displayed using the filter tools available on each tab.
- Refresh the list.
- Export the displayed information as a report file with the Export Report feature. Different from the other tabs, the Audit Logs tab uses an Export button for exporting its data.
The Admins tab also provides for cancelling some administrator-related events. See the following Administrator Events section for more information.
Exporting Reports from the Activity page's Tabs
Each tab provides an action for exporting a report that contains the tab's associated data.
For most of the tabs, when you export a report, it appears on the Exported Reports tab of the Reports page, where you can download the report. See Reports Page for more information.
The Audit Logs tab uses a slightly different exporting mechanism than the other tabs. For the Audit Logs tab, clicking that tab's Export downloads the CSV file instead of using the exported reports feature.
Important: On the tabs that use the Export Report button, if you select All Pods in the pod filter, the Export Report button is deactivated. You can export data for all of your pods by performing an export for each pod.
When you begin the export, you can choose whether you want to export all data or only the data as currently filtered.
Then a message appears at the top of the page indicating that the report is being generated.
Depending on the number of records, the preparation time can take several minutes. For example, a report with 50,000 records takes approximately 10 minutes.
You can see the progress of the report and download it when complete on the Exported Reports tab of the Reports page. On that Exported Reports tab, select Horizon Cloud from the list to see that report
For administrator or user events, the exported report file is a CSV file contained in a ZIP file. The data in the generated CSV file is not sorted by date. You can correct that in one of the following ways:
- Open the CSV file in Excel and set the date format for the cells that contain dates to mm/dd/yy hh:mm AM/PM.
- In Excel, create a new blank workbook and use Excel's Data Import wizard to import the downloaded CSV file.
Administrator Events
The Admins tab displays information about administrator events. Expand an event to view details and subtasks for that event. Click an event to view details and progress for that event. Click the event description to view further information.
| Column | Description |
|---|---|
| Description | Details regarding the event. |
| Status | Successful indicates that an event was performed in its entirety. Failed indicates that an event was either partially performed or not performed at all. |
| % Completion | Current percentage of event completed. |
| Time | Time that the event was logged. |
These filtering options are available on the Admins tab:
- Display events for only a certain time period, a specific pod, or a certain status, using the filters at the top of the tab.
- Filter events shown in the table using the filter tool in each column.
From the Admins tab, you can cancel assignment-related tasks before they complete by selecting the task in the list and clicking Cancel Tasks.
- Before attempting to select a task for cancellation, refresh the view to update the status for the tasks displayed.
- If a task is currently in a state where the system allows you to cancel it, you can select the check box corresponding to that cancellable task. If all tasks in the list are cancellable, you also have the option of selecting the 'select all' check box at the top of the list to cancel all tasks. If not, you must select tasks individually.
The following table shows the tasks that you can cancel.
| Task | Cancel When Task is in Queued State | Cancel When Task is in Running State |
|---|---|---|
| Farm Expansion | Supported Note: When the system has automatically created an expansion task for an RDSH farm, the farm must be offline before you can cancel that task. | Supported
Note the following:
|
| Assignment Expansion | Supported Note: When the system has automatically created an expansion task for a VDI desktop assignment, the assignment must be offline before you can cancel that task. | Supported
Note the following:
|
| Convert VM to Image | Supported Note: If you cancel this task, and want to retry it, first confirm that the VM is in a state where it can be converted. If you are not sure, power off and then power on the VM. | Supported Note: If you cancel this task, and want to retry it, first confirm that the VM is in a state where it can be converted. If you are not sure, power off and then power on the VM. |
User Events
Depending on the pod types in the tenant's fleet, the console displays the Users (Azure) tab, the Users (SDDC) tab, or both tabs.
Use these tabs to access descriptions and times logged for end-user events, categorized by the pod type that is associated with those events.
For example, use the Users (SDDC) tab to access data logged for end-user events related to the tenant's Horizon deployments.
These filtering options are available on these tabs:
- Display events for only a certain time period or a specific pod, using the filters at the top of the tab.
- Filter events shown in the table using the filter tool in each column.
Audit Logs
The Audit Logs tab displays the time, status, description, and user information logged for events that have occurred from administrator-initiated actions on your pods. For more information, see Working with Audit Logs.
You can filter events displayed using the Filters tool at the top of the tab.
Reports
Use the console's Reports page to access various reports related to end users' desktop and application sessions that are provided by your first-generation Horizon Cloud tenant.
Attention: This Reports documentation page is updated to match with the changes to the first-generation console as described in KB article 91183.
As described in the KB article, Intelligence for Horizon is available for first-generation Horizon Cloud tenants that have subscription licenses Horizon Universal, Horizon Apps Universal, and Horizon Apps Standard. With this availability, the KB article states:
- The historical dashboards and reports that the first-gen console provided will now be available through Intelligence.
- As of June 30, 2023, those historical dashboards and reports are no longer available in the first-gen console.
- The following reports that were previously on the console's Reports page are now only available in the Intelligence console: Azure Concurrency, Sessions, User Usage, VDI Applications Usage, Utilization.
- With these changes, because the Reports page's Schedules tab and related features were applicable only for the Sessions, User Usage, and VDI Applications Usage reports, that tab and features are removed from the console.
- Please note that if your first-gen tenant has deactivated monitoring user session data, the reports associated with utilization, trending, and historical analysis are deactivated and then unavailable in Intelligence. When the monitoring is deactivated, the system collects such user session information for a limited period of time and hashes the user name to enable real time administration while deactivating historical and aggregated viewing of that user information. As a result, the reports that would display historical and aggregated viewing of that data, such as the Sessions report, will be unavailable. For the way to check if your tenant has this monitoring deactivated, navigate to the console settings in Settings > General Settings > Monitoring.
For further information, see the following pages in the Intelligence documentation: Horizon Cloud First-Gen Integration and Access Horizon Cloud Data in Intelligence Reports.
Navigating the Reports Page
Select Monitor > Reports to open the Reports page, where you can view detailed information for a variety of report types. When you create a report, it displays in the console with options to filter the results, manually refresh the page, and export the report.
The Reports page has these tabs:
- The Create Report tab shows the types of reports available for you to create. You can click the report type to create the report in the console. See Report Types below for descriptions of report types.
- The Exported Reports tab lists exported reports that are ready for download. This includes reports from the Reports page's Create Reports tab and reports created from data that you exported from other locations in the console, such as the Activity page.
- Use the drop-down menu at the top of the tab to select which type of report you want to view. The number of choices depend on the pod types in your tenant's pod fleet.
- Select a report and click the Download button to download a ZIP file containing the report file in XLSX format.
Exporting Report Data
When you display a report in the console, you will see either a labeled button for exporting or an icon button for exporting. That icon depicts a page with an arrow pointing to the right.
The system's behavior that occurs after you click the button to initiate the export will vary depending on the type of report.
-
For most reports
After you initiate the export by clicking the relevant button, the system displays the progress of creating the report. Follow the on-screen prompts.
Attention: If you have pods in Microsoft Azure and any of those pods are at manifests earlier than 2552, the system's process for larger reports is as follows:
- When you begin the export, a message appears stating that the report is being compiled and it can take some time. Depending on the number of records, the preparation time can take several minutes. For example, a report with 50,000 records takes approximately 10 minutes.
- When the preparation is done, another dialog box appears with the message
Report Generated Successfullyand a Download button. After clicking the Download button, you must wait for the download to complete before closing this dialog box. Closing it before the download is complete cancels the download. Because you cannot perform any other actions in the console until this process is finished, if you have a large number of activity records you should plan to export the information when you can wait up to 10 minutes before performing other tasks in the console.
Report Types
When the Horizon Agent is installed, the Horizon Monitoring Service Agent option is installed by default. If you do not install this option, activity-related data from user sessions in the desktop instance or farm multi-sessions instances based on this image is not reported. As a result, data from end-user activity and other types of desktop activity will not be displayed in reports. Also, for the RDP protocol, that agent option provides only a subset of metrics that it provides for other protocols.
CAUTION:
If you have cloud-connected Horizon pods that are sending desktop data to vRealize Operations Manager, enabling the first-generation cloud-monitoring toggles causes data to be sent to the Cloud Monitoring Service (CMS) instead. To continue using vRealize Operations Manager to collect that desktop session data, deactivate CMS in the console settings at Settings > General Settings > Monitoring.
| Report Type | Details |
|---|---|
| User Mapping | View details and sort by various categories, such as User name, Domain, Desktop Name, Desktop Model, Farm, and Mapping Type (User or Group). Note: This report is populated only for users that have at least one direct assignment to a desktop. In the console, you can select individual users or user groups when making a desktop assignment. If a user has at least one assignment done as an individual user and zero or more assignments done as being part of the assigned group, this report reports all of that user's desktop assignments. However, if all the user's desktop assignments are done using groups, that user's assignments are not reported in this report. If the user is mapped to a desktop as an individual user, the Group Name column is blank. If the user is mapped to a desktop from being a member of a group that is entitled to the desktop assignment, the Group Name column displays the entitled group's name. |
| Desktop Mapping | View details and sort by various categories, such as Desktop Name, Model, Assignment Name, Type, Farm, Active User, Mapped Users, and Mapped User Groups. Note: In this report, the Mapped Users column is populated only for dedicated VDI desktop assignments, because for such assignments, each user gets mapped to a specific VDI desktop and returns to that same desktop at each login. That mapped user is the user assigned to that desktop. However, for floating VDI desktop assignments and session desktop assignments that are served by farms, users do not get mapped to specific desktop VMs. As a result, there is not data in the Mapped Users column for those desktop assignment types. |
| URL Configurations | View information for currently configured URL redirects. For more information, see Single-Pod Broker - Horizon Cloud Pods - Create a URL Redirection Customization and Assign it to Users. |
| Agent Versions | View current versions of agents for each VM. For a pod in Microsoft Azure, this tab also displays the pod's manifest version to help you determine if the agent version must be updated or not. Select a pod in the Pod drop-down at the top left of the page to show information for that pod. You can also sort data on all columns, including Assignment Name. |
Notifications Page
Horizon Cloud uses notifications to inform you of certain types of system activity, such as events and service registrations.
You can view recent notifications in the administrative console by clicking the bell icon located in the upper right corner of any page (
) Open the Notifications page to view all notifications. These notifications include both active and dismissed notifications, by clicking Monitor > Notifications.
You can also show the notifications for different periods of time up to 30 days, refresh the page, and filter your search.
| Notification Type | Description |
|---|---|
| Service Registration | Service registration notifications are issued during the configuration of your environment. The system issues this type of notification when one of its packaged services is registered successfully. |
| Pod related | Pod-related notifications are issued when the system detects a change in the status of the deployed pod in Microsoft Azure. These notifications include ones for when a pod has lost connectivity with the Horizon Cloud cloud plane and when subnets are full. When subnets are full, then system operations involving cloning VMs raise notifications. |
| Pod API related | These notifications arise from conditions detected by the cloud plane's API requests that are made to the pod resources in Microsoft Azure, such as API slow downs or timeouts. |
| Primary bind account locked | These notifications are issued when the system detects the primary domain-bind account is in a failed or inactive state. For more information, see section 'Notifications When the Primary Domain-Bind Account is Locked Out' within Troubleshooting. |
| Domain Bind Account used for emergency access | This notification is issued when the primary domain bind account or auxiliary domain bind account is used to log in to the console. As described in section 'Assign Roles to Active Directory Groups that Control Which Areas of the Horizon Universal Console are Activated for Individuals' within Troubleshooting, the primary and auxiliary domain bind accounts are always assigned the Super Administrator role, which grants all the permissions to perform management actions in the console. |
| New Horizon Agent Installer (HAI) Available Update | This notification is issued when a newer version of the agent associated with a pod software version is available. By default, the system checks for updates every seven days. |
Working with Audit Logs
The Audit Logs tab displays the time, status, description, and user information logged for events that have occurred from administrator-initiated actions on your pods. The amount and types of event data reported on the Audit Logs tab might vary by pod type. The Horizon Cloud control plane retains event data for one year.

Audit Logs
-
To display the audit logs, do one of the following:
- Select Monitor > Activity. On the Activity page, click the Audit Logs tab.
- Select Settings > Capacity. On the Capacity page, click the name of the pod for which you want to view logs, and then click the Audit Logs tab. By default, the Audit Logs tab displays the logs for every pod-related event that transpired in the past 24 hours, in descending order of time with the most recent events listed first.
-
To sort the logs by ascending order of time, click the Time column header. To toggle back to descending order, click the header again.

-
To refresh the display of audit logs with the most recently reported events, click the Refresh button
.
Filtering Audit Logs
To customize the display of audit logs, you can adjust the settings for the Time Period filter. You can also apply additional filters to refine further the selection of logs that are displayed. Each filter has drop-down menus that let you define the operations and values used to narrow the selection of logs.
-
To customize the Time Period filter, select an operation and time value from the drop-down menus, and click Apply.
-
To specify an additional filter, click the plus sign (+) button. Using the drop-down menus, select the filter type, operation, and value for the filter. Then click Apply.
The options available from the operation and value menus vary depending on the filter type. For example, if you select Severity for the filter type, Greater Than or Equal To for the operation, and Success for the value, the filter displays all the logs with the status "Success" or "Info."
You can also apply more than one filter of the same type. For example, you can apply a Severity filter that shows logs with status Equal To the value Success. Then you can apply an additional Severity filter that shows logs with status Equal To the value Failure.
Downloading Audit Logs
Note: The download feature is only available to users who have Horizon Cloud Super Administrator privileges.
To download the current, filtered list of audit logs, click the Download button
button.
The downloaded logs reside in a CSV file and have the following properties:
-
The download file includes all the logs that fulfill the current filtering criteria, regardless of whether they are visible on the Audit Logs tab.
For example, the current filter might return a total of 1000 logs spanning multiple pages of the Audit Logs tab. However, each page can only display 10 logs. The download file contains all 1000 logs from all the Audit Logs pages, not just the currently viewed page.
-
The download file always lists logs in descending order of time, regardless of the sort order specified on the Audit Logs tab. The sort order only applies to the display on the Audit Logs tab.
-
By default, the download file uses the name format AuditReport-<YYYY-MM-DDTHH_MIN_SEC.millisZ> (for example, "AuditEventReport-2019-08-14T11_16_32.096Z").
About the Assignments Menu in the Horizon Universal Console
The console's navigation bar's Assignments are provides access to the assignment-related workflows you can perform in your Horizon Cloud environment.
Tip: The console is dynamic and reflects the workflows and settings that are appropriate for the up-to-the-moment situation in your Horizon Cloud tenant environment. The labels displayed for the console's assignment-related pages will vary depending on factors such as the tenant's configured brokering setting, the types of cloud-connected pods in your fleet, the tenant's regional cloud plane, and features that are based on specific licensing.
When You Have Mixed Pod Types
When you have both Horizon pods and pods in Microsoft Azure, clicking Assignments displays different choices depending on your tenant's configured brokering settings and whether your tenant is enabled for use of App Volumes.
When All of Your Pods are Horizon Pods
When all of your pods are Horizon pods, clicking Assignments displays a page from which you can initiate actions to create new desktop assignments and work with your existing assignments. For each listed assignment, you can click its name see more information about that assignment, such as which users it is assigned to and other details. For more information about desktop assignments for cloud-connected Horizon pods, see Creating and Managing Assignments in Your Universal Broker Environment and its subtopics, and also Horizon Pods - Create a Multi-Cloud Assignment of VDI Desktops.
When All of Your Pods are In Microsoft Azure
When you have zero Horizon pods, clicking Assignments provides access to choices from which you initiate actions to create new assignments and work with your existing assignments. On the assignments-related pages, for each listed assignment, you can click its name see more information about that assignment, such as which users it is assigned to and other details. When you click on a VDI desktop assignment, in addition to seeing more information about the assignment, you can also navigate to the VDI desktop assignment's Desktops tab to see the list of virtual desktops that are in that VDI desktop assignment and optionally perform actions on those desktops.
For high-level information about managing assignments for your pod in Microsoft Azure and links to additional documentation topics, see Managing Assignments Provisioned By Horizon Cloud Pods in Microsoft Azure.
Viewing Assets in Your Horizon Cloud Tenant's Inventory
Your Horizon Cloud tenant's inventory contains assets such as RDSH farms, published images, applications, and imported virtual machines (VMs). The assets are building blocks from which your end users' assigned desktops and remote apps are derived. You access this inventory and the various assets using Inventory in the Horizon Universal Console.
Because of the console's dynamic nature, in your live environment, you might see entries and labels that are variations of the ones described here.
Remember: A cloud-connected pod fleet can consist of two different pod types. A Horizon pod is the pod type that is based on Horizon Connection Server and which is deployed on a vSphere-based SDDC platform. A Horizon Cloud pod is the pod type that is based on the pod-manager technology and which is deployed into Microsoft Azure by the Horizon Cloud pod deployer, as described in Horizon Cloud Pods - Using the Capacity Page to Add More Pods.
Application Assets
From Inventory, you reach workflows involving adding application-related assets into the inventory and managing those assets. Such application-related assets include App Volumes applications and farm-based remote applications. See Applications in Your Horizon Cloud Inventory.
Farm Assets
From Inventory, you reach farm-related workflows for creating and managing RDSH farms and their RDSH VMs. See Farms in Horizon Cloud and its subtopics.
Image Assets
From Inventory, you reach image-related workflows. The actual labels and pages you see in the console and the available workflows that those pages support can vary depending on the types of pods currently in your pod fleet.
-
When your pod fleet consists solely of cloud-connected Horizon pods
Cloud-connected Horizon pods support use of features of the Horizon Image Management Service and multi-pod image management. Multi-pod images are provided by the Horizon Image Management Service. The multi-pod image management workflows are covered in First-Gen Horizon Cloud - IMS Guide.
-
When your pod fleet includes at least one Horizon Cloud pod in Microsoft Azure
Horizon Cloud pods support use of per-pod images in your Horizon Cloud inventory. See the following topics that describe workflows for per-pod images:
- Creating Desktop Images and Your Horizon Cloud Pods in Microsoft Azure and its subtopics.
- Managing Published Images for Horizon Cloud Pods in Microsoft Azure and its subtopics. As of the July 2021 service release, when all of your Horizon Cloud pods are of manifest 2632 or later and your tenant is configured to use Universal Broker, the features of the Horizon Image Management Service and multi-pod image management are available to use with those pods. The multi-pod image management workflows are covered in the guide First-Gen Horizon Cloud - IMS Guide.
Imported VM Assets
From Inventory, you reach the page where you can initiate the automated creation and import of a base image VM in a single Horizon Cloud pod in Microsoft Azure as well as perform some operations on the listed VMs, such as powering them off and on. The virtual machines (VMs) listed on this page are those that have been brought into your Horizon Cloud environment in the following ways:
- The VMs that you created and imported on a per-pod basis using the Imported VMs page's Import action button, following the steps in Create a Base Virtual Machine Automatically from the Microsoft Azure Marketplace and Pair it with Horizon Cloud on a Per-Pod Basis.
- VMs that the system imported from the pods'
podID-base-vmsresource groups, when they are manually created by following the steps in Manually Build and Import a Virtual Machine from Microsoft Azure into Horizon Cloud.
Before a VM can be used in a farm or VDI desktop assignment, that VM must be converted into a published state, also known as sealing the image. Even though the Imported VMs page includes an action to convert a listed base VM to a published state, instead of using the action from this page, one typically creates a sealed, published image using the images-related pages that are described in the preceding section Image Assets. Make sure that the VM has all the applications and drivers you want installed on it before sealing it.
For a Horizon Cloud pod in Microsoft Azure, the page's Reset Agent Pairing action updates the agent state that governs the key exchange between the pod manager and the agent in the imported VM for the purposes of securing connections between the two. Because a pair of keys is used to make these secure connections, the term pairing is used to describe this exchange of keys. You typically use this workflow in the following scenarios:
-
For a VM recently imported using the automated workflow to import VMs from the Microsoft Azure Marketplace: in this scenario, this action restarts the agent software that the workflow installed in the VM, which completes the pairing.
For a VM that you manually created and installed the agent software in it, using the manual workflow to import VMs from Microsoft Azure: in this scenario, this action restarts the agent software that the workflow installed in the VM, which completes the pairing.
For a listed VM that shows an error message in its Agent Status column: in this scenario, this action restarts the agent software to repair the pairing failure and complete the pairing.
Some additional notes about the Imported VMs page:
- If the process to import an image from the Microsoft Azure Marketplace fails, the system generates a notification about the failure and displays a Failed link in the Agent Status column. Clicking that link opens the Notification page where you can read the reason for the failure.
- The Imported VMs page does not automatically refresh itself. After you perform an action, you might have to click the refresh action to see the current status. As an example, when a VM is powered off and you choose the Power On action, the page displays In progress as the power-on process starts, and continues to show that status until you refresh the page.
- If the multi-pod image management features are available in your tenant environment, the Move to Multi-Pod Images action is available to use on VMs that are single-session VDI images. This action is primarily used on manually imported VMs to enable their use within the multi-pod image workflows.
Settings Menu
The Horizon Cloud console's navigation bar's Settings provides access to pages for working with various aspects of your Horizon Cloud environment, such as environment-wide settings, identity management, role-based access (RBAC) settings for the console, your deployed pods, and various related settings and configurations.
Click Settings to access these pages in the console.
Remember: The console dynamically reflects the current state of your tenant environment. As a result, clicking Settings might display entries and labels that are variations of the ones described below. Usually, but not always, the console hides a page from view if that page is not applicable to the up-to-the-moment situation in your tenant environment.
| User Interface Page | Description |
|---|---|
| General Settings | Displays settings that apply environment-wide for this particular Horizon Cloud tenant environment, such as those Customer Connect users who can log in to the environment, their roles, and other comparable settings, including the toggle to activate or deactivate monitoring user session information. You can edit settings from this page. See Customizable General Settings for Your Horizon Cloud Tenant Environment for details. |
| Active Directory | View and edit Active Directory (AD) details and configure the True SSO capabilities for your environment. True SSO provides the capabilities for your end users to connect to their desktops and RDS-based remote applications without having to enter AD credentials. See Horizon Cloud - True SSO - Complete Configuring True SSO for your Horizon Cloud Environment. |
| Users & Groups | Manage your end users' home site assignments. See Working with Sites in a Universal Broker Environment. |
| Roles & Permissions | Edit roles and permissions. See Assign Roles to Active Directory Groups that Control Which Areas of the Horizon Universal Console are Activated for Individuals in Those Groups After They Authenticate to Your Horizon Cloud Tenant Environment. |
| Capacity | View details about your deployed pods, such as each pod's utilization and capacity usage, and drill down to view and optionally update some of the editable properties associated with a pod, such as its specified NTP server, its associated Microsoft Azure subscription's application key, and so on. For details, see First-Gen Tenants - Managing Your Cloud-Connected Pods, for All First-Gen Horizon Cloud Supported Pod Types. |
| Identity Management | The console makes this page available only when the tenant is already configured to use single-pod brokering for the pod fleet's Horizon Cloud pods in Microsoft Azure. In that tenant scenario, this page is used to configure the tenant's integration with your Access environment. |
| Licenses | View details of current licenses for your environment, including numbers of seats and billing cycles. You can also click the SID for a license to open the subscription list page at Customer Connect (you must log in using your Customer Connect credentials). |
| VM Types & Sizes | Manage the types and sizes of VMs to be used in farms and assignments for pods in Microsoft Azure. For details, see Managing VM Types and Sizes for Farms and Assignments in the Horizon Universal Console. |
| Getting Started | Display the Getting Started wizard. See Getting Started Page - Overview for details. |
| Broker | Configure settings that apply to the system's brokering of pod-provisioned resources to your end users, such as settings that control timeouts for end-user sessions. When the tenant is configured with Universal Broker, this page includes a tab for configuring settings that apply to the tenant's integration with Omnissa Access and with Workspace ONE Intelligent Hub. For details, see First-Gen Horizon Cloud with Universal Broker - Integrate the Tenant with Access and Intelligent Hub Services. |
Customizable General Settings for Your Horizon Cloud Tenant Environment
Use the Horizon Universal Console's General Settings page to modify settings that apply to your overall Horizon Cloud tenant environment.
Note: The console dynamically reflects the current state of your tenant environment. As a result, the sections you see and settings you can change in the General Settings page are only those that are relevant and appropriate for the current state of your tenant environment. For example, when your cloud-connected pods are all Horizon pods and no pods in Microsoft Azure, only the settings relevant to Horizon pods are provided in this page. When you have at least one pod deployed in Microsoft Azure, the General Settings page makes available settings relevant to that pod type.
To change a setting, use the pencil icon next to the section that contains the setting that you want to change. An edit window displays with that section's settings. Change the settings in that window and save your changes to the system.
Note: When changing any of the following settings, it can take up to 5 minutes for the update to take effect.
- The Enable Dedicated Desktop Assignment Name setting in the Desktop Assignment Options section.
- The settings in the Domain Security Settings section, listed in Domain Security Settings on General Settings Page.
Default Domain
If you have only one Active Directory domain registered with your environment, the name of that domain appears here. If you have multiple Active Directory domains registered, this text box displays the name of that Active Directory domain that is specified as the default Active Directory domain, the one that appears first in the domain selection list in the Active Directory login page used when administrators log in to the administrative console.
This setting only governs which Active Directory domain appears first in the domain selection list on that Active Directory login page. As described in Log In to the Horizon Universal Console to Perform Management Tasks on Your Horizon Cloud Environment, when your environment has multiple Active Directory domains registered, the Active Directory login page has a domain selection list. You can use this Default Domain text box to specify one of the Active Directory domains as the default. That default Active Directory domain then appears first in the Active Directory login page's domain selection list. Click Edit to change the current setting.
Accounts
To give users the ability to log into Horizon Cloud, you add their Customer Connect accounts. After adding their account information here, then assign their Active Directory user accounts the role that is appropriate for their job or business tasks. See Assign Roles to Active Directory Groups that Control Which Areas of the Horizon Universal Console are Activated for Individuals in Those Groups After They Authenticate to Your Horizon Cloud Tenant Environment.
Notification Recipients
To allow specific non-administrator users or groups to receive email notifications regarding your Horizon Cloud environment, you add their email addresses to the Notification Recipients list.
The preceding accounts list can include various types of administrators. However, if you want non-administrator users or groups to receive email notifications, such as administrative and scheduled-maintenance email notifications, use the Notification Recipients section to add their email addresses.
All email notifications generated from Horizon Cloud are sent to all of the listed email addresses.
Session Timeout
These settings govern timeouts of connections to your Horizon Cloud environment:
- The Admin Portal Timeout setting governs the amount time an administrator can be continuously logged in to the console. When that time has elapsed, the administrator's authenticated session ends and the administrator must log back in.
Deletion Protection
The Deletion Protection setting controls the number of desktop VMs that can be deleted per hour in each of your dedicated desktop assignments. Select one of the following options for Mass Delete Dedicated Desktop (per hour).
- Unlimited - Unlimited desktop VMs can be deleted from dedicated desktop assignments.
- None - No desktop VMs can be deleted from any dedicated desktop assignment unless you allow them for a particular assignment using the Max Desktop Deletions (see note below).
- Custom - Number of desktop VMs that can be deleted from a dedicated desktop assignment per hour. If you select Custom, you must also enter a numerical value to the right of this drop-down menu. You can allow additional desktop VMs to be deleted from a particular assignment using the Max Desktop Deletions (see note below).
Note:
If you selected None or Custom, you can allow additional deletions for a particular assignment before this limit is invoked by editing the Max Desktop Deletions setting when you create or edit the assignment. If you have entered a value greater than 0 for the Max Desktop Deletions, then the system authorizes deletions of that number of VMs before counting them against the rate you set for Deletion Protection.
For example, you might set Max Desktop Deletions to Custom with a value of 10 and set Deletion Protection to Custom with a value of 1. In this case, after the first 10 VMs are deleted (no matter how long it takes for the count to reach 10), the system only allows 1 additional VM to be deleted per hour from that time forward.
If you select Unlimited for Deletion Protection, there is no need to use the Max Desktop Deletions setting.
For more information about the Max Desktop Deletions setting, see Create a Dedicated VDI Desktop Assignment.
To prevent all VM deletions in a dedicated desktop assignment, use the Prevent Deletions setting on the Assignments page. See Prevent Deletions or Allow Deletions for a Dedicated Desktop Assignment.
RDSH Farm
You can provide a message that Horizon Cloud displays to end users when their logged-in Windows session with their session desktop or remote application has reached the farm's configured maximum session time. The system will forcibly log out the user from their logged-in Windows session after the grace period time expires.
In the Grace Period text box, you can provide a time for which the system waits before forcibly logging out the user, after the reminder message has been sent.
Desktop Assignment Options
Use this setting to configure the displayed virtual desktops' names seen by your end users when they access their assigned virtual desktops using their end-user clients. This setting applies only to virtual desktops provisioned by a dedicated VDI desktop assignment provisioned from pods in Microsoft Azure. For information about desktop assignments in Horizon Cloud, see A Brief Introduction to Your Tenant's Desktop Assignments Based on Horizon Cloud Pods in Microsoft Azure.
Initially, when an end user logs in to their end-user client and sees a desktop newly provisioned from a dedicated VDI desktop assignment, the client displays the name of the dedicated VDI desktop assignment. At this point in time, a specific desktop virtual machine (VM) is not yet assigned to that end user as their dedicated desktop VM. When that end user takes the step to launch the virtual desktop for the first time, at that point, the system dedicates that specific desktop VM to that user as a result of that initial launch. Then for subsequent desktop launches, the name for that desktop that appears in that end user's client depends on the setting you choose here.
Important:
-
Enabling the Enable Dedicated Desktop Assignment Name setting applies to pods at pod manifest version 1900 and later. When the pod is at a manifest version lower than 1900, the legacy behavior stays in effect for virtual desktops provisioned from that pod, regardless of the toggle setting.
-
When you change the setting, it can take up to 5 minutes for the update to take effect.
-
This option does not apply to end-user connections using Access. When an end user uses Access to access a desktop entitled to them from a dedicated VDI desktop assignment, Access displays the assignment name and the user's Horizon Client or Horizon Web Client (Blast) portal displays the VM name for subsequent desktop launches.
-
When the toggle Enable Dedicated Desktop Assignment Name is deactivated, the end-users clients display the name of the virtual desktop's underlying VM. Displaying the VM name is the legacy behavior.
-
When the toggle Enable Dedicated Desktop Assignment Name is enabled, the end-user clients continue to display the name of the dedicated VDI desktop assignment that provisions the virtual desktop, even for subsequent desktop launches.
Agent Updates
The Failure Threshold setting indicates the number of VMs for which automated agent updates for dedicated desktop assignments in pods on Microsoft Azure are allowed to fail before the update process is stopped. This prevents mass failures from occurring. The default value is 30. For more information, see Updating Agent-Related Software Used by Horizon Cloud.
Image Management Settings
These settings are displayed when your tenant's pod fleet includes at least one Horizon pod. These settings apply to the Image Management Service (IMS) features for Horizon pods. Use these settings to optimize the image replication process. For all of the information about the Image Management Service, see the document First-Gen Horizon Cloud - IMS Guide and its subtopics.
Domain Security Settings
Use these settings to prevent the communication of Active Directory domain names to unauthenticated users using the various Horizon clients to connect to the pods in Microsoft Azure. These settings govern whether the Active Directory domain information is sent to the client and, if sent, how it is displayed in the end-user clients' login pages. For details, see Horizon Cloud - Domain Security Settings on General Settings Page.
Important:
-
These settings are applied to all of your environment's pods that are deployed in Microsoft Azure, the ones that are under the same Horizon Cloud customer account (tenant).
-
The combination of options selected here changes the user experience in the clients. Certain combinations can set requirements for how end users enter the domain information on the client login page, especially when using older clients, command-line clients, and when your environment has multiple Active Directory domains. How these settings affect the client user experience depends on the client. You might need to balance your desired end-user experience according to your organization's security policies. For more information, see Horizon Cloud - Domain Security Settings on General Settings Page.
-
The General Settings page does not display this Domain Security Settings section when your Horizon Cloud environment has any pods in Microsoft Azure that are not yet updated to pod manifest version 1273 or later. To get access to these controls, update all your pods in Microsoft Azure to this release.
-
Until all your pods are updated to pod manifest version 1273 or later, your environment is configured by default to provide the same behavior as it was in the previous Horizon Cloud release. Until all your pods are at this release level, the system sends the Active Directory domain names to the end-user clients and the clients have the legacy behavior that displays the Active Directory domain drop-down menu.
Then when all your pods' manifests are at version 1273 or later, these settings are displayed in the General Settings page. At that point, the displayed settings reflect the legacy behavior (both controls set to No), and you can change them to control the communication of domain information to the clients.
To see your pods' current manifest versions, use the Capacity page. For this release's pod manifest version, see the Release Notes page.
Monitoring
The Cloud Monitoring Service (CMS) collects and stores session, application, and desktop data from connected pods for monitoring and reporting purposes. The CMS is one of the central services provided in Horizon Cloud. For an introduction to the CMS, see First-Gen Tenants - Introducing the Cloud Monitoring Service's Unified Visibility and Insights, Health Monitoring, and Help Desk Features Provided in the Horizon Universal Console.
-
Use the Cloud Monitoring Service toggle to enable or deactivate the cloud monitoring service. It is enabled by default.
When this setting is deactivated, the Session Data setting below does not appear.
-
When the cloud monitoring service is enabled, you can use the Session Data toggle to opt in or opt out of tracking user information related to your end users' sessions. Information collected includes times they logged in, session durations, and average session length per user.
When you opt in to the collection of user data, the service collects this information and maintains it for the duration of your use of your first-gen Horizon Cloud environment. As described in KB article 91183, this data is made available in Intelligence. You can delete the collected data by turning off the Session Data toggle.
When you opt out of the collection of user data but leave the monitoring service enabled, the service collects session data for a limited period and hashes the user name to allow real-time administration while deactivating historical and aggregated viewing of information. As a result, some reports, such as the Horizon User Usage report, are not available. In this case the system also continues to collect other data related to applications and desktops in connected pods.
Pendo Analytics and Guides
The console displays this section only when you have logged in to your Horizon Cloud tenant using the Cloud Services login method. If you have logged in using the Customer Connect credentials method in the Horizon Cloud login screen, the console does not display this section.
This section indicates the current enablement state of the Pendo-related service feature. When you log in to your tenant using the Cloud Services login method, the Pendo-related features are enabled by default.
To read about these Pendo-related features and optionally change the current settings, click the edit (pencil icon). Upon clicking the icon, the console redirects you to the Cookie Usage page which provides information about these Pendo-related features and displays toggles for changing the settings.
To reflect the changes you make in the Cookie Usage page in the Horizon Universal Console General Settings page, refresh the General Settings page.
Domain Security Settings on General Settings Page
You use these settings to prevent communication of Active Directory domain names to unauthenticated users using the various Horizon clients. These settings govern whether the information about the Active Directory domains that are registered with your Horizon Cloud environment is sent to the Horizon end-user clients and, if sent, how it is displayed in end-user clients' login screens.
Configuring your environment includes registering your environment with your Active Directory domains. When your end users use a Horizon client to access their entitled desktops and remote applications, those domains are associated with their entitled access. Prior to the March 2019 quarterly service release, the system and clients had default behavior with no options to adjust that default behavior. Starting in March 2019, the defaults are changed, and you can optionally use the new Domain Security Settings controls to change from the defaults.
Important: When changing these settings, it can take up to 5 minutes for the update to take effect.
This topic has the following sections.
- Domain Security Settings
- Current Default Behavior As Compared with Past Releases
- Relationship to Your Pods' Manifest Levels
- Single Active Directory Domain Scenarios and User Login Requirements
- Multiple Active Directory Domain Scenarios and User Login Requirements
- About Pods in Microsoft Azure with Unified Access Gateway Instances Configured with Two-Factor Authentication
Domain Security Settings
Combinations of these settings determine whether domain information is sent to the client and whether a domain selection menu is available to the end user in the client.
Important: These settings apply to all of your Horizon Cloud pods in Microsoft Azure that are within the same Horizon Cloud environment. All such pods that are deployed in Microsoft Azure using the same Horizon Cloud customer account (tenant) get the same combination. All of the end users connecting to your pods will receive the behavior according to these settings, regardless of which pod is provisioning their virtual desktops and remote applications.
CAUTION:
These settings change the user experience in the clients. The behavior for end users using versions of Horizon Client prior to version 5.0 is different than for Horizon Client 5.0 and later. Certain combinations can set requirements on how your end users specify their domain information in the client login screen, especially when using older clients, command-line clients, and when your environment is configured with multiple Active Directory domains. How these settings affect the client user experience depends on the client. You might need to balance your desired end-user experience according to your organization's security policies. See sections Single Active Directory Domain Scenarios and User Login Requirements and Multiple Active Directory Domain Scenarios and User Login Requirements.
| Option | Description |
|---|---|
| Show Default Domain Only |
This option controls what domain information the system sends to connecting clients prior to user authentication.
|
| Hide Domain Field |
This option controls the visibility in the client login screen of whatever domain-related information is sent to the client, based on the Show Default Domain Only setting.
|
Default Behavior Compared with Past Releases
The following table details the previous default behavior, the new default behavior, and the settings you can use to adjust the behavior to meet your organization's needs.
| Past Default Behavior | Default Behavior Now | Corresponding Domain Security Settings Combination for this Release's Default Behavior |
|---|---|---|
| The system sent the names of the registered Active Directory domains to the clients. |
The system sends only a literal string value (*DefaultDomain*) to the clients and not the names of the registered Active Directory domains.
Note: Sending the literal string provides support for older Horizon clients which are implemented to expect a string list of domain names. | Show Default Domain Only Default setting: Yes |
| The clients displayed a drop-down menu in the login screen that presents the list of registered Active Directory domain names for the end user to choose their domain prior to logging in. |
The clients display that literal string *DefaultDomain*. | Hide Domain Field Default setting: No |
Relationship to Your Pods' Manifest Levels
When you are an existing customer with pods created in an earlier service release, until all of your pods in Microsoft Azure are updated to the manifest level for this Horizon Cloud release, your environment is configured by default to provide the same behavior as it had in the previous Horizon Cloud release. That legacy behavior is:
- The system sends the Active Directory domain names to the client (Show Default Domain Only is set to No).
- The clients have a drop-down menu that displays the list of domain names to the end user prior to logging in (Hide Domain Field is set to No).
Also, until all of your pods are at this service release level, the General Settings page does not display the Domain Security Settings controls. If you have a mixed environment with existing non-updated pods and newly deployed pods at this release level, the new controls are not available. As a result, you cannot change from the legacy behavior until all of your pods are at this service release level.
When all of your environment's pods are updated, the settings are available in the Horizon Cloud administrative console. The post-update defaults are set to the pre-update behavior (Show Default Domain Only is No and Hide Domain Field is No). The post-update default settings are different than the new-customer defaults. These settings are applied so that the pre-update legacy behavior continues for your end users after the update, until you choose to change the settings to meet your organization's security needs.
Single Active Directory Domain Scenarios and User Login Requirements
The following table describes the behavior for various setting combinations when your environment has a single Active Directory domain, without two-factor authentication, and your end users use the Horizon Clients 5.0 and later versions.
Show Default Domain Only (enabled sends *DefaultDomain*) | Hide Domain Field | Horizon Client 5.0 Login Screen Details | How Users Log In |
|---|---|---|---|
| Yes | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. No domain name is sent.
The following screenshot is an example for how the resulting login screen looks like for the Windows client.
![]() | When there is a single domain, to log in, end users can enter either of the following values in the User name text box. The domain name is not required.
|
| Yes | No | The client's login screen has the standard user name and password fields. The domain field displays *DefaultDomain*. No domain name is sent.
The following screenshot is an example for how the resulting login screen looks like for the Windows client.
![]() | When there is a single domain, to log in, end users can enter either of the following values in the User name text box. The domain name is not required.
|
| No | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. The system sends the domain name to the client. Note: This combination is atypical. You would not normally use this combination because it hides the domain field even though the system is sending the domain name. The login screen looks the same as the one in the first row of this table, with no domain field displayed. | An end user must include the domain name in the User name text box.
|
| No | No | The client's login screen has the standard user name and password fields and a standard drop-down domain selector displays the one available domain name. The domain name is sent. | The end user can specify their user name in the User name text box and use the single domain that is in the list visible in the client. Using the command-line client launch and specifying the domain in the command works. |
This table describes the behavior when your environment has a single Active Directory domain and your end users use previous versions of the Horizon clients (pre-5.0).
Important: Using the command-line client launch of older (pre-5.0) clients and specifying the domain in the command fails for all of the combinations below. To work around this behavior, either use *DefaultDomain* for the command's domain option or update the client to the 5.0 version. However, when you have more than one Active Directory domain, passing *DefaultDomain* does not work.
Show Default Domain Only (enabled sends *DefaultDomain*) | Hide Domain Field | Pre-5.0 Horizon Client Login Screen Details | How Users Log In |
|---|---|---|---|
| Yes | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. No domain name is sent. | An end user must include the domain name in the User name text box.
|
| Yes | No | The client's login screen has the standard user name and password fields. The domain field displays *DefaultDomain*. No domain name is sent. | An end user must enter username in the User name text box. When the domain name is included, an error message displays that states the specified domain name does not exist in the domain list. |
| No | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. The system sends the domain name to the client. Note: This combination is atypical. You would not normally use this combination because it hides the domain field even though the system is sending the domain name. The login screen looks the same as the one in the first row of this table, with no domain field displayed. | An end user must include the domain name in the User name text box.
|
| No | No | The client's login screen has the standard user name and password fields and a standard drop-down domain selector displays the one available domain name. The domain name is sent. | The end user can specify their user name in the User name text box and use the single domain that is in the list visible in the client. |
Multiple Active Directory Domain Scenarios and User Login Requirements
This table describes the behavior for various setting combinations when your environment has multiple Active Directory domains, without two-factor authentication, and your end users use the Horizon Clients 5.0 and later versions.
Basically, the end user has to include the domain name when they type in their user name, like domain\username, except for the legacy combination where the domain names are sent and are visible in the client.
Show Default Domain Only (enabled sends *DefaultDomain*) | Hide Domain Field | Horizon Client 5.0 Login Screen Details | How Users Log In |
|---|---|---|---|
| Yes | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. No domain names are sent.
The following screenshot is an example for how the resulting login screen looks like for the Windows client.
![]() | An end user must include the domain name in the User name text box.
|
| Yes | No | The client's login screen has the standard user name and password fields. The domain field displays *DefaultDomain*. No domain names are sent.
The following screenshot is an example for how the resulting login screen looks like for the Windows client.
![]() | An end user must include the domain name in the User name text box.
|
| No | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. The system sends the domain names to the client. Note: This combination is atypical. You would not normally use this combination because it hides the domain field even though the system is sending the domain names. The login screen looks the same as the one in the first row of this table, with no domain field displayed. | An end user must include the domain name in the User name text box.
|
| No | No | The client's login screen has the standard user name and password fields and a standard drop-down domain selector displays the list of domain names. The domain names are sent. | The end user can specify their user name in the User name text box and select their domain from the list visible in the client. Using the command-line client launch and specifying the domain in the command works. |
This table describes the behavior when your environment has multiple Active Directory domains and your end users use previous versions of the Horizon clients (pre-5.0).
Important:
- Setting Hide Domain Field to Yes allows end users to enter their domain in the User name text box in these pre-5.0 Horizon clients. When you have multiple domains and you want to support use of pre-5.0 Horizon clients by your end users, you must set Hide Domain Field to Yes so that your end users can include the domain name when they type in their user name.
- Using the command-line client launch of older (pre-5.0) clients and specifying the domain in the command fails for all of the combinations below. The only work around when you have multiple Active Directory domains and want to use command-line client launch is to update the client to the 5.0 version.
Show Default Domain Only (enabled sends *DefaultDomain*) | Hide Domain Field | Pre-5.0 Horizon Client Login Screen Details | How Users Log In |
|---|---|---|---|
| Yes | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. No domain name is sent. | An end user must include the domain name in the User name text box.
|
| Yes | No | The client's login screen has the standard user name and password fields. The domain field displays *DefaultDomain*. No domain name is sent. | This combination is unsupported for environments with multiple Active Directory domains. |
| No | Yes | The client's login screen has the standard user name and password fields. No domain field is displayed. The system sends the domain name to the client. Note: This combination is atypical. You would not normally use this combination because it hides the domain field even though the system is sending the domain names. | An end user must include the domain name in the User name text box.
|
| No | No | The client's login screen has the standard user name and password fields and a standard drop-down domain selector displays the one available domain name. The domain name is sent. | The end user can specify their user name in the User name text box and select their domain from the list visible in the client. |
About Pods in Microsoft Azure with Unified Access Gateway Instances Configured with Two-Factor Authentication
As described in First-Gen Tenants - Specify Two-Factor Authentication Capability for the Pod, when you deploy a pod into Microsoft Azure, you have the option of deploying it with two-factor authentication configured on its Unified Access Gateway instances.
When a pod in Microsoft Azure has its Unified Access Gateway configured with two-factor authentication, end users attempting to authenticate with their Horizon clients first see a screen asking for their two-factor authentication credentials, followed by a login screen asking for their Active Directory domain credentials. In this case, the system sends the domain list to the clients only after the end user's credentials successfully pass that initial authentication screen.
Generally speaking, if all of your pods have two-factor authentication configured on their Unified Access Gateway instances, you might consider having the system send the domain list to the clients and have the clients display the domain drop-down menu. That configuration provides the same legacy end-user experience for all of your end users, regardless of which Horizon client version they are using or how many Active Directory domains you have. After the end user successfully completes the two-factor authentication passcode step, they can then select their domain from the drop-down menu in the second login screen. They can avoid having to include their domain name when they enter their credentials into the initial authentication screen.
However, because the Domain Security Settings are applied at the Horizon Cloud customer account (tenant) level, if some of your pods do not have two-factor authentication configured, you might want to avoid sending the domain list, because those pods will send the domain names to the clients connecting to them prior to the end users logging in.
Important: When a pod's two-factor authentication configuration has Maintain Username configured as Yes, ensure that the Hide Domain Field is set to No. Otherwise, your end users will not be able to provide the required domain information for the system to associate with their login credentials.
The end-user login requirements by Horizon client follow the same patterns that are described in Single Active Directory Domain Scenarios and User Login Requirements and Multiple Active Directory Domain Scenarios and User Login Requirements. When connecting to a pod that has two-factor authentication configured and you have multiple Active Directory domains, the end user must provide their domain name as domain\username if Hide Domain Field is set to Yes.
Horizon Cloud - Deprecated - File Share Page
Use of the File Share page in the Horizon Universal Console is deprecated. As a result, if you happen to see this page displayed, no information is provided on this page. Typically this page will not even be visible in the console when your environment only has pods deployed in Microsoft Azure.
First-Gen Tenants - Obtaining License Information Using the Horizon Universal Console
This section describes the ways that the first-generation Horizon Universal Console provides for obtaining license-related information from your first-generation Horizon Cloud environment.
A Horizon Cloud tenant can have various types of license-related information associated with it. Such types typically include Horizon subscription licenses, keys for perpetual-key-based products if your Horizon license includes those, and add-on licenses that might be entitled for use with your tenant.
Note: Not every SKU is eligible for perpetual-key-based product licenses. If the UI doesn't display the View action to you for a product and you believe your SKU provides for that product's license, please follow the guidance in KB article 6000014.
Logging In Solely to Obtain Keys for Perpetual-Key-Based Products
If your Horizon Cloud tenant's associated licenses include perpetual-key-based products such as vSphere, and you log in to the Horizon Universal Console with the Horizon Cloud Customer Administrator role, the console provides a link View perpetual keys on the console's Getting Started page.
If you do not meet the preceding requirements, the console does not display that link.
The following screenshot shows where you can see this View perpetual keys link on that Getting Started page, only when you meet the preceding requirements.

If you see that link, clicking it opens a UI screen that provides for viewing and copying those keys.
Viewing or Copying a Key
Clicking View perpetual keys displays the UI screen illustrated in the following screenshot. This screen lists various perpetual-key-based products that might be associated with this tenant. The UI indicates which products have associated keys.
For an available key, use the icons in that key's row to view the key or copy the key.

When a key is unavailable and you want additional guidance, click the displayed link to view the online guidance.
When the Tenant Has At Least One Registered Active Directory Domain
Only when the Horizon Cloud tenant has at least one registered Active Directory domain, then you have access to view the UI page named the Licenses page.
By design, access to all of the console's pages that reside in the left hand navigation is blocked until that initial registration is completed, with the exception of the Getting Started UI page.
The Licenses page is one such UI page that has blocked access until the first domain registration is completed.
However, if at least one domain is registered for the tenant, you can access the Licenses page from the console's left hand navigation Settings > Licenses.
The Licenses page will display a View Perpetual Keys link only when the following conditions are true. Otherwise, that link is not present.
-
The tenant has an associated Horizon subscription license that includes perpetual-key-based products such as vSphere.
-
You are logged in to the console with the Horizon Cloud Customer Administrator role.
If you do see that link, clicking it opens a UI screen that provides for viewing and copying the keys, as described in this page's section Viewing or Copying a Key.
Licenses Page
The following table describes the types of information displayed in the Licenses page.
| Field | Description |
|---|---|
| SID | Service Instance ID. This value is a unique identifier generated for each subscription. This value is also a hyperlink that you can use to open that SID's associated subscription list page located on the Customer Connect login page. Clicking this hyperlink displays the login page. |
| Total Seats | Number of seats included in the license. |
| Billing | Type of billing and total length of license. Billing types are:
|
| Type | The type of the specific license. For each table row, the name displayed in this column will be one of those subscription licenses and add-on licenses from your Customer Connect account that are also associated for use with this tenant, such as Horizon Service Universal, Workspace ONE Assist for Horizon, and so on. |
| Classification | License classifications are:
|
| Start Date | Date that the license became active. |
Identity Management Page in the Horizon Universal Console
This page is visible to you when your Horizon Cloud environment is configured to use single-pod brokering with your Horizon Cloud pods in Microsoft Azure. In that configuration, you use the Identity Management page to add, edit, and configure the required identity management provider information for the Access cloud tenant that is integrated with this Horizon Cloud tenant.
Note: The console dynamically reflects the current configuration and state of your tenant environment. The console makes the Identity Management page available when your tenant environment is configured to use single-pod brokering for your pods in Microsoft Azure. When your environment is configured to use the Universal Broker, this page is not available for your use and you use the Broker page instead. To see the brokering type that is configured for your environment, navigate to the console's Broker page (Settings > Broker).
Note: If your single-pod broker Horizon Cloud tenant was integrated with an Access cloud tenant prior to the v2207 service release, the console might display the name of that associated Access cloud tenant at the top of the Identity Management page.
Access Configuration
In this section, the console displays the identity management providers currently configured for this Horizon Cloud tenant, including the following information for each.
- Status - Current status of the listed configuration. Hover on the icon to see the current status.
- Access URL - The metadata URL of the identity management provider.
- Access Redirection - Indicates whether automatic redirection to Access is configured for the listed configuration. You can only enable redirection for one identity provider per tenant. This feature is primarily used with the feature to force end-user access to their desktops and applications through Access. See Configure the Option to Force End-User Access to Use Access.
- Timeout SSO Token - Timeout value in minutes.
- Data Center - For a pod deployed in Microsoft Azure, the displayed value corresponds to the pod's software version for the specific pod that is configured with this particular provider. This number is the same as the pod's version number that is listed in the pod's details page. See the description of the pod's details page in First-Gen Tenants - Managing Your Cloud-Connected Pods, for All First-Gen Horizon Cloud Supported Pod Types.
- Client Access FQDN - The FQDN that you tell your end users to make their connections to, for connecting to Horizon Cloud.
- Location - The pod's location.
- Pod - The pod for which this configuration applies.
Adding a New Configuration
Configuring an Access cloud tenant to use with a Horizon Cloud pod that is using single-pod broker is a multi-step process.
- Read Single-Pod Broker - Integrating with Access.
- Follow the steps in Single-Pod Broker - Steps for Configuring with the Relevant Access Tenant.
Edit Settings for a Configuration
To edit the information for a configuration on this page:
-
Select the listed configuration.
-
Click Edit.
-
Edit the following information.
Field Description Timeout SSO Token Timeout value in minutes. Client Access FQDN For a pod in Microsoft Azure, you enter here the FQDN that you tell your end users to make their connections to, for connecting to Horizon Cloud. Access Redirection When editing the configuration, you can change the current setting of this toggle. When you also have the configuration to force end-user access to go through Access, you can set this toggle to YES to have the end users' clients automatically redirect to their Access environment. Read about the options to force end-user access to go through Access in the following section Configure the Option to Force End-User Access to Use Access. With the automatic redirection configured to YES, in the end-user clients, when the client attempts to connect to Horizon Cloud and is forcing access through Access, the client is automatically redirected to the Workspace Access environment that is specified in this identity management provider configuration. When the toggle is set to NO, automatic redirection is not enabled, and the clients display an informational message to the user instead. Note: You can have this redirection enabled for only one of the identity management URLs per pod. If you try to enable this feature for multiple URLs and the same pod, an error message is displayed. -
Click Save.
Configure the Option to Force End-User Access to Use Access
For each listed provider, you can use the following steps to configure whether end users can access their assigned desktops and remote applications directly from Horizon Cloud or must access only using Access.
Note: When you change these settings, it can take up to 5 minutes for the update to take effect.
-
Click Configure.
-
Edit settings as described below.
Field Description Force Remote Users to Access Select YES to block remote user access except through the identity management provider. Option only displays if that provider status is green. Force Internal Users to Access Select YES to block internal user access except through the identity management provider. Option only displays if that provider status is green. -
Click Save.
When you force end-user access through Access, you typically also edit the corresponding identity provider configuration to specify that the end-user clients automatically redirect to Access. See previous section Edit Settings for a Configuration.
The feature to force end-user access to Access works with the Access redirection feature in the following ways.
| Force end-user access through Access setting | Access redirection setting | What happens when the end user's client connects to Horizon Cloud to access their desktops and applications |
|---|---|---|
| Enabled (yes) | Enabled (yes) | Client is automatically redirected to Access. |
| Enabled (yes) | Deactivated (no) | Client displays a message that tells the user that they must access Horizon Cloud using Access. Automatic redirection does not occur. |
| Deactivated (no) | Enabled (yes) | Client displays the Horizon Cloud login screen for the end user to log in. Automatic redirection does not occur because forced access to Access is not enabled. |
| Deactivated (no) | Deactivated (no) | Client displays the Horizon Cloud login screen for the end user to log in. In this scenario, both forced access and the automatic redirection features are Deactivated. |
Remove a Configuration
To remove one of the configurations:
- Select the configuration in the list.
- Click Remove.
- Click Delete to confirm.
Broker-Related Settings for Your Horizon Cloud Tenant Environment
Use the Horizon Universal Console's Broker page to modify broker-related settings that apply to your overall Horizon Cloud tenant environment.
Remember: The console dynamically reflects the current state of your tenant environment. As a result, the console displays sections on this page and the various settings based on which ones are relevant and appropriate for the current, up-to-the minute state of your tenant environment.
Note: When changing any of the following settings described in the sections below, it can take up to 5 minutes for the update to take effect.
- The settings in the Session Timeout sections.
- The Clean Up Horizon Web Client Credentials When Tab is Closed setting.
Universal Broker
The console displays this section when your tenant is configured to have your cloud-connected pods use the Universal Broker to broker end users' clients to their entitled pod-provisioned resources. When the Universal Brokersettings are already saved to the system, those current settings are displayed in this section. To change those settings, click the pencil icon next to the Universal Broker label and then follow the on-screen prompts. For additional details about the on-screen settings, see the information described in Configure Universal Broker Settings.
Depending on the tenant's up-to-date configuration, the Broker page might display some additional tabs, such as the following items.
- Settings to identify IP ranges to Universal Broker, to distinguish when a client's incoming traffic is coming from your internal network. Refer to Define Internal Network Ranges.
- Client restriction settings for end-user sessions. Refer to Configure Global Client Restrictions.
- Integration with Access and Intelligent Hub services. Refer to Integrate the Tenant with Access and Intelligent Hub Services.
Single-Pod Broker
The console displays this section when your tenant is configured to have your Horizon Cloud pods in Microsoft Azure use the service's classic pod-based brokering method to broker end users' clients to their entitled pod-provisioned resources. These pods are the ones running the Horizon Cloud pod-manager technology.
As of the v2111 service release, use of single-pod brokering is not available to greenfield customer tenant environments. In this context, greenfield means a tenant environment in which the console's enablement procedure was never previously initiated within the console's Broker page for the tenant's Horizon Cloud pods.
-
Session Timeout
These settings govern the end users' connections made from their endpoint devices using Horizon Client, Horizon Web Client, Omnissa Access, and Workspace ONE Intelligent Hub. You can adjust these timeout settings to allocate enough time to avoid a user unexpectedly finding that they need to re-authenticate to Horizon Cloud. These settings are associated with the connection between the client running on the entitled end user's endpoint device and the pod that provisions VDI desktops, RDS session desktops, and remote applications to that entitled end user. These settings are separate from the users' logged-in session to the underlying Windows operating system of those desktops and applications. When the pod detects the conditions determined by these settings have occurred, it expires the user's authenticated Horizon Client, Horizon Web Client, Omnissa Access, or Workspace ONE Intelligent Hub connection.
Timeout Description Client Heartbeat Interval Controls the interval between Horizon Client heartbeats and the state of the endpoint's connection to the pod manager in the pod. These heartbeats report to the pod manager the amount of idle time that has passed in the connection to the endpoint. Idle time occurs when no interaction occurs with the endpoint device, as opposed to idle time in the Windows operating system session that underlies the user's desktop or remote application usage. In large desktop deployments, setting the activity heartbeats at longer intervals might reduce network traffic and increase performance. Client Idle User Pertaining to the connection between an end user's endpoint device and the pod's pod manager, the maximum time that the end user can be idle in that connection, such as when no keyboard or mouse activity on the client device is detected. When this maximum is reached, the connection's authentication to the pod manager expires and all active Horizon Client, Horizon Web Client, Omnissa Access, and Workspace ONE Intelligent Hub remote (RDS-based) application connections are closed. - The single sign-on (SSO) credentials at the pod manager are discarded. The user must re-authenticate in their client to reopen a connection from their end-point device to connect to the pod manager within that pod.
- RDS-based application sessions are disconnected.
Client Broker Session Pertaining to the connection between an end user's endpoint device and the pod's pod manager, the maximum time that a Horizon Client, Horizon Web Client, Omnissa Access, or Workspace ONE Intelligent Hub connection can be connected to the pod manager before the connection's authentication expires. The timeout count starts each time the user authenticates to the pod in the client on their endpoint device. When this timeout occurs, the user can continue to work in their existing session that is currently assigned from the pod manager. If the user performs an action in the client on their endpoint device that requires communication to the pod manager, such as changing a client setting, the pod manager requires a re-authenticated connection. The end user must log back in to the client on their endpoint device (Horizon Client, Horizon Web Clients, Omnissa Access, or Workspace ONE Intelligent Hub). Note: The Client Broker Session timeout must be at least equal to the sum of the Client Heartbeat Interval setting and the Client Idle User timeout. -
Horizon Web Client
The Clean Up Horizon Web Client Credentials When Tab is Closed setting affects system security and ease of use when end users use Horizon Web Client to access their desktops or applications. The setting determines if end users must enter their credentials again.
- A value of Yes, the option that emphasizes security, prompts end users to again enter their credentials when they reconnect.
- A value of No, the option that emphasizes ease of use, does not prompt end users to enter their credentials when they reconnect.
-
Pool/Farm Options
The Allow Client To Wait For Powered-Off VM option governs what happens if the end user uses Horizon Client to try to connect to a desktop or remote application when the underlying VDI or RDSH virtual machine is powered off in the cloud. As a result of an assignment's or RDSH farm's power management settings, there might not be enough powered-on virtual machine capacity to serve the client's request. When the connection is initiated, Horizon Cloud starts powering on the underlying virtual machine needed to fulfill the request. However, although the underlying virtual machine is powering on, the Horizon Cloud agent in the virtual machine has not yet started up and cannot respond to the Horizon Client connection request. Because it can take some time between the client connecting and the agent starting, you can use this option to have the client retry the connection and inform the end user of the estimated time. For this scenario, when the Enable Client Retry toggle is set to Yes, the client presents a message to the end user that describes the estimated waiting time.
- Horizon Cloud starts powering on the underlying virtual machine in the cloud that will serve the end user's client request.
- Horizon Cloud notifies Horizon Client to retry the connection when the agent in the virtual machine is up and running.
- The client prompts the user with a message that describes the wait time estimated before the client retries the connection.
Horizon Cloud Getting Started Wizard - Overview
You use the Getting Started wizard to perform the configuration steps that are needed before you can fully manage and use the environment, such as registering an Active Directory domain. The Getting Started wizard displays by default when you log in to the Horizon Universal Console for the first time. After you have finished registering one Active Directory domain and given the Horizon Cloud Super Administrators role to an Active Directory group in that domain, then you have access to the console's left hand navigation bar for performing administration tasks in your environment. Also at that point in time, you can switch the toggle at the bottom of the Getting Started page to stop using the Getting Started as the default console home page and use the Dashboard page as your default home page instead.
Note: Terms used here:
- A Horizon Cloud pod is built on pod-manager technology from Horizon Cloud on Microsoft Azure.
- A Horizon pod is built on Connection Server technology from Horizon.
The Getting Started wizard provides a high-level overview of the work that you have done, and what is still to do. You can access the wizard from Settings > Getting Started.
Note: To ensure that you completed all tasks required to run and manage the environment, review the steps in the following topics, depending on what type of pod was the one that you first deployed into your environment. You cannot perform certain tasks from the Getting Started wizard, such as uploading certificates.
- For Horizon Cloud on Microsoft Azure deployments: First-Gen Tenants - Horizon Cloud on Microsoft Azure - High-Level Sequence
- For Horizon pod plus Horizon Cloud Connector deployments: First-Gen Tenants - Onboarding a Horizon Pod to First-Gen Horizon Cloud Control Plane
| Section | Description |
|---|---|
| Capacity |
When your tenant's pod fleet has zero pods, from this section. you can:
|
| General Setup | Provides details and links for the initial configuration of various tenant-wide settings, such as registering an Active Directory domain. See General Setup Section of the Horizon Universal Console's Getting Started Wizard. |
| Desktop Assignment |
|
| Application Assignment | Note: In this release, this section is not displayed when your pod fleet consists solely of Horizon pod. When your pod fleet has at least one Horizon Cloud pod, this section provides links to task pages related to applications and application assignments. See Applications in Your Horizon Cloud Inventory and its subtopics. |
When you have completed the required steps of registering at least one Active Directory domain and given the Super Administrator role to at least one of your Active Directory user groups, displaying the wizard is optional. To toggle having the wizard appear every time you log in to the console, move the slider at the bottom of the wizard's main page to Yes.
Note: Even though the wizard's primary use occurs during your first time setting up a pod and most people toggle off the wizard after that, some people find the wizard might be a convenient launching point when performing some of the standard tasks.
General Setup Section of the Horizon Universal Console's Getting Started Wizard
In the first-time configuration for a pod connected to your Horizon Cloud environment, you use the choices in the General Setup section for the initial configuration of various pod-wide settings, such as registering an Active Directory domain. After the first-time configuration, you can use the choices in the General Setup section to open the console pages in which you can edit the configurations.
| Selection | Description |
|---|---|
| Accounts | Give access for other people to log in to the console and your Horizon Cloud environment using their own Customer Connect accounts. See Give Admin Roles for Logging In and Performing Actions in Your Tenant. |
| Active Directory | Register the initial Active Directory domain and add the domain bind and domain join information. Domain registration of at least one Active Directory domain is required to give roles and permissions to console users or assign services to users. You must register an Active Directory domain and finish the domain join before you can perform other operations with the first cloud-connected pod, including registering additional Active Directory domains. For information about tasks related to Active Directory and your pods, see:
|
| Roles & Permissions | Assign roles to users who will be managing the environment. A role grants its associated permissions to the users given that role. See Assign Roles to Active Directory Groups that Control Which Areas of the Horizon Universal Console are Activated for Individuals in Those Groups After They Authenticate to Your Horizon Cloud Tenant Environment. |
| Broker | Enable the brokering technology that you want used when your end users' clients connect to the pod-provisioned resources that you have entitled those end users to use. Configure settings related to the brokered end-user sessions, such as session timeout settings. |
| Cloud Monitoring Service | The Horizon Cloud cloud monitoring service collects and stores session, application, and desktop data from connected pods for monitoring and reporting purposes.
|
Using the Filter Field in the Horizon Universal Console
Various pages in the Horizon Cloud administrative console provide ways to filter the medium to large amount of information that is displayed on the page, such as the various reports and the Activity page. On some pages, a filter field appears at the top of the page. On other pages, each column has a filter icon in the column heading that you click to access the filter text box. For those pages that provide filtering, as you enter characters into the filter text box, the system displays only the subset of the displayed records that contain characters that match that pattern.
The following screenshots illustrate examples of the filter box that is provided in some pages and the filter icon that is provided for columns in some pages. This first example is in the Images page.

This second example is in the Activity page.

Note: For those filter text boxes that are at the top of the page, the system begins matching the pattern and filtering the records displayed in the page after you have entered three (3) characters into the filter text box. For the filter icon at the top of column headings, the system begins filtering after you enter one (1) character.
On-Screen Filtering in the Reports Pages
In the tabs of the Reports page, the filtering text box works on the number of items that are displayed on the user interface itself and not on the total set of system records for that item. These pages support displaying up to 500 items. Therefore, if the system contains more than 500 records for an item, up to 500 items only are displayed in the user interface page. Using the filter text box only filters the 500 displayed records. The filter is not applied to the full set. Here is an example to illustrate:
- You have 2000 users assigned to a VDI floating desktop assignment.
- The user names range from vdiuser-1 to vdiuser-2000, such as vdiuser-500, vdiuser-501, vdiuser-502, and so on, up to vdiuser-2000.
- Over the course of a day, all 2000 users log in and use a desktop from that assignment.
- When you navigate to Monitor > Reports > Desktop Mapping, a displayed message states the report has more than 500 items.
- When you enter vdiuser-54 into the filter to see the records for users vdiuser-54, vdiuser-540, vdiuser-541 up to vdiuser-549, you expect to see 11 rows displayed.
However, instead of displaying the expected 11 rows filtered out of the full 2000 set, the Desktop Mapping page displays only the subset of the originally displayed 500 rows that match the filter pattern. To see the full data set, use the export feature (
).
Questa pagina è stata utile?

