Skip to main content

Creating Active Directory Domain Bind and Domain Join Accounts

After you configure your identity provider, create two domain bind and two domain join accounts on your on-premise Active Directory. Later, you will use the Horizon Universal Console to provide the details of these accounts to Horizon Cloud.

Note: If you are using Microsoft Entra ID as your identity provider, see Configure Microsoft Entra ID as Your Identity Provider before proceeding.

Horizon Cloud requires that you specify two instances of the following AD accounts to use as service accounts:

  • A domain bind account that is used to perform lookups in your AD domain.

  • A domain join account that is used for joining computer accounts to the domain, removing computer accounts from the domain, and performing Sysprep operations

For the Active Directory accounts that you specify for these service accounts, if both the primary and auxiliary domain bind accounts expire or become inaccessible, single sign-on does not work and you cannot join to new desktops. If you do not set Never Expires on the primary or auxiliary domain bind accounts, ensure that they have different expiration times. You must keep track as the expiration time approaches and update your Horizon Cloud domain bind account information before the expiration time is reached.

Domain Bind Account - Required Active Directory Permissions

The domain bind account must have read permissions which can look up AD accounts for all the AD organizational units (OUs) that you anticipate using in the Desktop-as-a-Service operations that Horizon Cloud provides — operations such as assigning desktop VMs to your end users. The domain bind account needs the ability to enumerate objects from your Active Directory. The domain bind account requires the following permissions on all the OUs and objects that you anticipate and expect to use with Horizon Cloud:

  • List Contents
  • Read All Properties
  • Read Permissions
  • Read tokenGroupsGlobalAndUniversal (implied by the Read All Properties permission)

Generally speaking, the domain bind accounts should be granted the default out-of-the-box read-access-related permissions that are typically granted to Authenticated Users in a Microsoft Active Directory deployment. In an out-of-the-box Microsoft Active Directory deployment, those default settings typically granted to Authenticated Users usually give a standard domain user account the ability to do the required enumeration that Horizon Cloud needs for the domain bind account. However, if your organization's AD administrators have chosen to lock down read-access-related permissions for regular users, you must request those AD administrators preserve the Authenticated Users standard defaults for the domain bind accounts you will use for Horizon Cloud.

Domain Join Account - Required Active Directory Permissions

The domain join account is configured at a tenant level. The system uses the same domain join account that is configured in the Active Directory registration for all of its domain-join-related operations with all of the pods in your tenant's fleet.

The system performs explicit permission checks on the domain join account within the OU you specify in the Active Directory registration workflow (in the Default OU text box in that workflow) and within the OUs you specify in the farms and VDI desktop assignments you create, if those farm and VDI desktop assignment Computer OU text boxes are different from the default OU in the Active Directory registration.

To cover the cases where you might ever use a sub-OU, a best practice is for you to set these required permissions to apply for all descendant objects of the Computer OU.

Important:

  • Some of the AD permissions in the list are typically assigned by Active Directory to accounts by default. However, if you have limited the security permission in your Active Directory, you must ensure that the domain join account has these permissions for the OUs and objects that you anticipate and expect to use with Horizon Cloud.

  • In Microsoft Active Directory, when you create a new OU, the system might automatically set the Prevent Accidental Deletion attribute which applies a Deny to the Delete All Child Objects permission for the newly created OU and all descendant objects. As a result, if you explicitly assigned the Delete Computer Objects permission to the domain join account, in the case of a newly created OU, Active Directory might have applied an override to that explicitly assigned Delete Computer Objects permission. Because clearing the Prevent Accidental Deletion flag might not automatically clear the Deny that Active Directory applied to the Delete All Child Objects permission, in the case of a newly added OU, you might have to verify and manually clear the Deny permission set for Delete All Child Objects in the OU and all child OUs before using the domain join account in the Horizon Universal Console.

Reusing Computer Accounts

Domain join user accounts must be granted permission to reuse existing computer accounts using the following steps:

  • Create a new Universal Security Group.
  • Add all domain join user accounts to the new security group.
  • For all relevant Group Policy Objects (GPO, activate Domain controller: Allow computer account re-use during domain join.
  • Click Edit Security....
  • In the Security Settings For Trusted Computer Account Owners dialog, click Add....
  • Select the new security group and click OK.

Perform these steps for every domain.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…