Skip to main content

Overview and Prerequisites for Using App Volumes Applications in Horizon Cloud

Using App Volumes applications functionality, you can manage the entire lifecycle of applications, including packaging, updating, and retiring applications. You can also customize application entitlements to deliver specific versions of an application to end users.

Important:

  • If you intend to use, but do not see App Volumes in the console, then you must contact your account representative to verify whether your license and tenant account configuration allows you to use App Volumes. After the license is activated, App Volumes is automatically available for use in the Horizon Universal console.

  • For operations such as importing or deleting application packages, provisioning file shares, and replication of application packages from staging to delivery file shares, the Horizon Edge deployment must be connected. For more information about file shares, see the Horizon Edge-related prerequisites section on this page.

For guest operating system support, see the Product Interoperability Matrix.

Overview of App Volumes Functionality in Horizon Cloud

The following table provides an overview of App Volumes functionality in Horizon Cloud.

Functional AreaDescription
Deployment
  • Zero-touch deployment. Auto-provisioning of App Volumes infrastructure components such as storage.
  • Edge infrastructure supporting App Volumes module to manage Microsoft Azure file shares and Amazon FSx for Windows file server.
  • Automatic provisioning of Microsoft Azure File Shares or Amazon FSx for Windows file server during Horizon Edge deployment to store and deliver apps.
Management Console
  • App Volumes console is seamlessly integrated into the Horizon Universal Console. Manage desktops and apps in the same console.
  • App Volumes Agent installation experience seamlessly integrated into the Horizon Cloud image creation workflows.
App Volumes 4 agent Unified performance-optimized agent used both for on-premises, Microsoft Azure, and Amazon Workspaces Core deployments.
Packaging
  • Supports VHD-based packages that are delivered using Microsoft Azure file shares and Amazon FSx for Windows file server.
  • Application package creation performed natively within Horizon Cloud. No command-line tools necessary.
  • Customers can import MSIX app attach VHDs and deliver this new package format using App Volumes.
Application Lifecycle Management Supports Simplified Application Management (SAM) capability that is already a part of App Volumes 4 on-prem. Administrators can now manage the entire life cycle of the application, including packaging, updating, and retiring.
Application Assignment
  • Administrators can customize their application entitlements (assignments) to deliver specific versions of an application to end users.
  • Supports multi-edge application delivery.
Identity ProviderApp Volumes supports Active Directory and Microsoft Entra ID. To configure Microsoft Entra ID as your identity provider, see Configure Microsoft Entra ID as Your Identity Provider.
Hybrid Cloud Support On-prem App Volumes customers can now import their application packages from their on-prem deployments into Horizon Cloud on Microsoft Azure or Amazon Workspaces Core. Reuse on-prem packages. Repackaging is not required.

Overview of the App Volumes Application Process

Making App Volumes applications available to users is a two-step process:

  • Add an App Volumes application in the Horizon Universal Console. There are two ways of doing this:

    • Add an App Volumes application by creating and importing a new application package.

      If an application package has not yet been created, you can create it with the Add Package option, which uses App Volumes to create the application package and automatically import it. See Add an App Volumes Application Using Horizon Cloud.

      Alternately, you can also create an application package while creating an application using the Add Application functionality.

    • Add an App Volumes application by importing an existing application package.

      If you have an application package that was previously created with App Volumes, you can import it with the Import Application option. This means you can reuse application packages from on-premises deployments without having to repackage the applications. See Add an App Volumes Application by Importing an Existing Application Package Using Horizon Cloud.

  • Create an App Volumes entitlement to entitle the App Volumes application to users. See Create an Entitlement for an App Volumes Application using Horizon Cloud.

Requirements and Prerequisites for Using App Volumes with your Horizon Cloud on Microsoft Azure and Horizon Cloud on Amazon Workspaces Core Deployments

Storage Account Access Key Rotation for Azure

You can rotate the storage account access keys for an App Volumes application storage account in the Microsoft Azure portal and update the rotated key for the storage account in the Horizon Universal Console.

Note: Ensure that you follow all the best practices and recommendations by Microsoft Azure when rotating the storage account access keys.

After rotating an access key in the Microsoft Azure portal for an App Volumes application storage account, the access key for that storage account is no longer valid. As a result, the pool VM loses access to the storage account and the end user who has logged into that pool VM can no longer use the applications. To prevent affecting the end user, you must update the secondary (key2) access key for the App Volumes application storage in the Horizon Universal Console even before rotating the primary key (key1).

To update an access key for an App Volumes application storage, use the Update Access Key functionality in the Horizon Universal Console > Capacity > Edge > App Volumes Application Storage grid section. To view this functionality, in the grid, you must click the ellipsis icon for that storage account. The Access Key Status in the storage grid indicates whether the status of the updated key is Valid or Invalid. After successfully updating the access key for the storage account, the status of the key becomes Valid. The pool VMs are able to access the storage account and the user can continue using the applications.

Important: There might be active attachments on the pool VM accessing the storage account whose access key you intend to update. Hence, after updating the storage account with the secondary (key2) access key, restart the pool VM. This restart ensures that the pool VM continues to access the storage account and the attachments remain active. As a result, the end user can continue using the applications on that pool VM. Following this action, the intended key can be rotated.

If you want to use the rotated access key to update for the storage account, ensure that no attachments are using this key before rotating the intended access key.

Update the Domain Join Service Account Details for App Volumes

If you change the domain join service account credentials in the AWS console, then you must ensure that the changed service account details are updated in the Horizon Universal console. This update ensures that the Horizon Edge continues to access the Amazon FSx file shares through the service account and administrator operations continue normally.

Note:

  • The service account details must be updated in every Horizon Edge which uses the same service account.

  • In the AWS console, service account details must be updated for all FSx file shares which are used by the App Volumes Application storage account in a specific Horizon Edge.

  • If there is a change in the DNS Server IP address of the Active Directory domain for App Volumes, then the changed IP address must also be updated in the Horizon Universal console.

Procedure

  1. Change the domain join service account credentials.

    a. Go to the Horizon Universal console, navigate to the Capacity page, select the desired Horizon Edge, and click Edit.

    b. Navigate to the App Volumes Storage section and make note of all the File Share Names.

    c. Go to the AWS Console, navigate to File systems (File Share Names), and update the service account details (username and password) in all the required File systems.

    If necessary, update the DNS IP addresses for all the required File systems.

  2. Go to the Horizon Universal console, navigate to the Capacity page, select the desired Horizon Edge, and click Edit.

  3. Navigate to the App Volumes Application Storage section.

  4. Beside the Service Account details table title, click Edit.

  5. Update the Service Account username and password with the same values that were used to update in the AWS console.

    If you have changed the DNS IP address in the AWS console, then you must update the DNS IP address on this page too.

Prerequisites for Using App Volumes with your Horizon Cloud on Microsoft Azure and Horizon Cloud on Amazon Workspaces Core Deployments

Before you can add App Volumes applications into your inventory, confirm that your environment meets the following prerequisites.

  • The deployment must have a gateway configuration (Unified Access Gateway instances), and you have completed the Unified Access Gateway’s FQDN-mapping steps, as it is required for Horizon Cloud on Microsoft Azure or Horizon Cloud on Amazon Workspaces Core deployments that are configured with Unified Access Gateway instances.

  • These file shares are generated by the service, and these are required for App Volumes.

    To view the file shares, in the Horizon Universal Console, navigate to the Capacity page, click the Horizon Edge, and scroll to the App Volumes Application Storage section.

    • Staging file share

      The staging file share is either an Azure file share or an Amazon FSx for Windows file server which is used to stage new application packages for discovery and import into the application inventory. The application packages can be copied from an existing App Volumes 4.x deployment. The file share is also used for application packaging.

      A single file share is automatically provisioned when a Horizon Edge is deployed.

    • Delivery file share

      The delivery file share is an Azure file share or an Amazon FSx for Windows file server which is used to deliver existing application packages that are entitled to users or groups. The desktop pool VMs mount the application package disks from this file share.

      Six delivery file shares for Azure and one delivery file share for Amazon FSx are automatically provisioned when the first pool is created for every provider.

      For example: For a Microsoft Azure edge with one primary provider and four secondary providers, App Volumes provisions one staging file share and six delivery Azure file shares for every secondary provider. As a result, a total of 24 delivery file shares are provisioned.

      Note:

    • If you intend to use the primary provider to create your pools, then App Volumes provisions one staging file share and six delivery Azure file shares.

    • Within a Horizon Edge, Horizon Cloud automatically replicates the application packages from the staging file share to the delivery file shares.

Configuration requirements

OptionsDescription
Horizon Edge on Microsoft Azure
  • If you choose to configure an Active Directory domain as the machine identity, ensure that you have completed the Active Directory domain registration workflow as described in Identity and Access Management in a Horizon Cloud Environment

  • Alternately, you can choose Azure Active Directory as the machine identity.

  • See Port and Protocol Requirements for Your Horizon Cloud Deployment in Microsoft Azure.
    In addition to meeting the Horizon Cloud ports and protocol requirements, you must also open port 445 for TCP protocol traffic. Port 445 is the standard SMB port for accessing an SMB file share on Microsoft Windows. The application packages are stored in the Microsoft Azure's file shares present in a resource group identified by the Horizon Edge's primary provider instance.
Horizon Edge on Amazon Workspaces Core

Image requirements

Ensure that the App Volumes agent is installed.

How to locate the Agent Version of an image

To locate the Agent Version of an image for a specific pool, follow these steps:

  1. Navigate to the Pools page.

  2. Click a pool name.

  3. In the pool details page, go to the General Settings section.

  4. In the Image pane, make note of the Name value.
    The Name is the image name used for that particular pool.

  5. To view a list of images, navigate to the Images page.

  6. To view the Versions table that lists the image versions and status, click the image name link.

  7. Click the link of the desired image version.

  8. In the image version details page, go to the Image Copies table.

  9. View the Agent Version.
    The Agent Version indicates the Horizon Agent Installer build installed on the image version.

Packaging requirements

  • If you have configured firewall rules for access to storage account provisioned by App Volumes, ensure that you allowlist all the subnets that are associated with the provider for the Horizon Edge deployment used to package the applications.
  • You must deactivate auto-update services for each application you intend to package, as an auto-update behavior is problematic.
    • If the application has an auto-update service, deactivate the service, such as with Windows Services Manager, during the application-provisioning process.
    • If you cannot or do not deactivate the auto-update service during the application provisioning process, after you encounter an issue, such as users receive an incomplete version of an unassigned application, modify the base image by configuring the registry. This configuration ensures that the service of interest is not started when the application package is deployed to the user VM. Specifically, configure the registry by adding the application service name to the svservice registry configuration DisableAppServicesList.

Prerequisite for Displaying App Volumes Applications in the App Catalog in Hub Services

For the App Volumes applications to be displayed in the Hub catalog (App Catalog) in a VDI desktop, the latest HAI version must be used. For information about the HAI version, see the Horizon Cloud Release Notes at Omnissa Product Documentation.

If the VDI desktop has an earlier version of HAI or the App Volumes agent is not installed, then the App Volumes applications are not displayed in the Hub catalog.

For information about the Horizon Cloud integration with Workspace ONE Intelligent Hub, see Integrating Horizon Cloud with Workspace ONE Intelligent Hub.

Best Practices for Using a Microsoft Windows Enterprise Multi-Session Image with App Volumes Applications in Horizon Edge Deployments

The following practices help provide a better user and administrator experience. Also see Setting up a Microsoft Windows Enterprise Multi-Session Image with App Volumes Applications.

  • Install hardware printers, with printer drivers, in the base image.

  • As described in the Microsoft documentation FAQ, Microsoft Windows 10 or 11 Enterprise multi-session is a Remote Desktop Session Host (RDSH) type of VM that allows multiple concurrent interactive sessions, which previously only Microsoft Windows Server operating systems provided. As Microsoft Windows 10 or 11 Enterprise multi-session is an RDSH type of operating system, the Horizon Cloud RDSH-applicable workflows apply to it instead of the VDI-related workflows. As a result, to provide session desktops to end users based on these multi-session systems, create a multi-session pool group as described in Create a Multi-Session Pool Group.

  • Inform users that when they install applications or create files that they do not intend to share among all user sessions on the same VM, they can place the file in their own profile location.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…