Administration
Table Of Contents
- View Administration
- Contents
- View Administration
- Using Horizon Administrator
- Configuring View Connection Server
- Configuring vCenter Server and View Composer
- Create a User Account for View Composer AD Operations
- Add vCenter Server Instances to View
- Configure View Composer Settings
- Configure View Composer Domains
- Allow vSphere to Reclaim Disk Space in Linked-Clone Virtual Machines
- Configure View Storage Accelerator for vCenter Server
- Concurrent Operations Limits for vCenter Server and View Composer
- Setting a Concurrent Power Operations Rate to Support Remote Desktop Logon Storms
- Accept the Thumbprint of a Default SSL Certificate
- Remove a vCenter Server Instance from View
- Remove View Composer from View
- Conflicting vCenter Server Unique IDs
- Backing Up View Connection Server
- Configuring Settings for Client Sessions
- Set Options for Client Sessions and Connections
- Change the Data Recovery Password
- Global Settings for Client Sessions
- Global Security Settings for Client Sessions and Connections
- Message Security Mode for View Components
- Configure the Secure Tunnel and PCoIP Secure Gateway
- Configure the Blast Secure Gateway
- Off-load SSL Connections to Intermediate Servers
- Configure the Gateway Location for a Horizon Connection Server or Security Server Host
- Disable or Enable View Connection Server
- Edit the External URLs
- Join or Withdraw from the Customer Experience Program
- View LDAP Directory
- Configuring vCenter Server and View Composer
- Setting Up Smart Card Authentication
- Logging In with a Smart Card
- Configure Smart Card Authentication on View Connection Server
- Configure Smart Card Authentication on Third-Party Solutions
- Prepare Active Directory for Smart Card Authentication
- Verify Your Smart Card Authentication Configuration
- Using Smart Card Certificate Revocation Checking
- Setting Up Other Types of User Authentication
- Using Two-Factor Authentication
- Using SAML Authentication
- Using SAML Authentication for VMware Identity Manager Integration
- Configure a SAML Authenticator in Horizon Administrator
- Configure Proxy Support for VMware Identity Manager
- Change the Expiration Period for Service Provider Metadata on Connection Server
- Generate SAML Metadata So That Connection Server Can Be Used as a Service Provider
- Response Time Considerations for Multiple Dynamic SAML Authenticators
- Configure Workspace ONE Access Policies in Horizon Administrator
- Configure Biometric Authentication
- Authenticating Users Without Requiring Credentials
- Providing Unauthenticated Access for Published Applications
- Using the Log In as Current User Feature Available with Windows-Based Horizon Client
- Saving Credentials in Mobile and Mac Horizon Clients
- Setting Up True SSO
- Determining an Architecture for True SSO
- Set Up an Enterprise Certificate Authority
- Create Certificate Templates Used with True SSO
- Install and Set Up an Enrollment Server
- Export the Enrollment Service Client Certificate
- Import the Enrollment Service Client Certificate on the Enrollment Server
- Configure SAML Authentication to Work with True SSO
- Configure View Connection Server for True SSO
- Command-line Reference for Configuring True SSO
- Advanced Configuration Settings for True SSO
- Identify an AD User That Does not Have an AD UPN
- Using the System Health Dashboard to Troubleshoot Issues Related to True SSO
- Configuring Role-Based Delegated Administration
- Understanding Roles and Privileges
- Using Access Groups to Delegate Administration of Pools and Farms
- Understanding Permissions
- Manage Administrators
- Manage and Review Permissions
- Manage and Review Access Groups
- Manage Custom Roles
- Predefined Roles and Privileges
- Required Privileges for Common Tasks
- Best Practices for Administrator Users and Groups
- Configuring Policies in Horizon Administrator and Active Directory
- Maintaining View Components
- Backing Up and Restoring View Configuration Data
- Monitor View Components
- Monitor Machine Status
- Understanding View Services
- Change the Product License Key
- Monitoring Product License Usage
- Update General User Information from Active Directory
- Migrate View Composer to Another Machine
- Update the Certificates on a View Connection Server Instance, Security Server, or View Composer
- Information Collected by the Customer Experience Improvement Program
- How VMware Ensures Your Privacy
- Preview Data Collected by the Customer Experience Improvement Program
- Additional Information About the Customer Experience Improvement Program
- Global View Data Collected by VMware
- View Connection Server Data Collected by VMware
- Security Server Data Collected by VMware
- Desktop Pool Data Collected by VMware
- Machine Data Collected by VMware
- vCenter Server Data Collected by VMware
- ThinApp Data Collected by VMware
- Cloud Pod Architecture Information Collected by VMware
- Horizon Client Data Collected by VMware
- Data Collected by VMware
- Managing ThinApp Applications in View Administrator
- View Requirements for ThinApp Applications
- Capturing and Storing Application Packages
- Assigning ThinApp Applications to Machines and Desktop Pools
- Best Practices for Assigning ThinApp Applications
- Assign a ThinApp Application to Multiple Machines
- Assign Multiple ThinApp Applications to a Machine
- Assign a ThinApp Application to Multiple Desktop Pools
- Assign Multiple ThinApp Applications to a Desktop Pool
- Assign a ThinApp Template to a Machine or Desktop Pool
- Review ThinApp Application Assignments
- Display MSI Package Information
- Maintaining ThinApp Applications in View Administrator
- Remove a ThinApp Application Assignment from Multiple Machines
- Remove Multiple ThinApp Application Assignments from a Machine
- Remove a ThinApp Application Assignment from Multiple Desktop Pools
- Remove Multiple ThinApp Application Assignments from a Desktop Pool
- Remove a ThinApp Application from View Administrator
- Modify or Delete a ThinApp Template
- Remove an Application Repository
- Monitoring and Troubleshooting ThinApp Applications in View Administrator
- ThinApp Configuration Example
- Setting Up Clients in Kiosk Mode
- Configure Clients in Kiosk Mode
- Prepare Active Directory and View for Clients in Kiosk Mode
- Set Default Values for Clients in Kiosk Mode
- Display the MAC Addresses of Client Devices
- Add Accounts for Clients in Kiosk Mode
- Enable Authentication of Clients in Kiosk Mode
- Verify the Configuration of Clients in Kiosk Mode
- Connect to Remote Desktops from Clients in Kiosk Mode
- Configure Clients in Kiosk Mode
- Troubleshooting Horizon 7
- Using Horizon Help Desk Tool
- Monitoring System Health
- Monitor Events in Horizon 7
- Collecting Diagnostic Information for Horizon 7
- Create a Data Collection Tool Bundle for Horizon Agent
- Save Diagnostic Information for Horizon Client
- Collect Diagnostic Information for View Composer Using the Support Script
- Collect Diagnostic Information for Horizon Connection Server
- Collect Diagnostic Information for Horizon Agent , Horizon Client, or Horizon Connection Server from the Console
- Update Support Requests
- Troubleshooting an Unsuccessful Security Server Pairing with Horizon Connection Server
- Troubleshooting View Server Certificate Revocation Checking
- Troubleshooting Smart Card Certificate Revocation Checking
- Further Troubleshooting Information
- Using the vdmadmin Command
- vdmadmin Command Usage
- Configuring Logging in Horizon Agent Using the -A Option
- Overriding IP Addresses Using the -A Option
- Setting the Name of a View Connection Server Group Using the ‑C Option
- Updating Foreign Security Principals Using the ‑F Option
- Listing and Displaying Health Monitors Using the ‑H Option
- Listing and Displaying Reports of View Operation Using the ‑I Option
- Generating View Event Log Messages in Syslog Format Using the ‑I Option
- Assigning Dedicated Machines Using the ‑L Option
- Displaying Information About Machines Using the -M Option
- Reclaiming Disk Space on Virtual Machines Using the ‑M Option
- Configuring Domain Filters Using the ‑N Option
- Configuring Domain Filters
- Displaying the Machines and Policies of Unentitled Users Using the ‑O and ‑P Options
- Configuring Clients in Kiosk Mode Using the ‑Q Option
- Displaying the First User of a Machine Using the -R Option
- Removing the Entry for a View Connection Server Instance or Security Server Using the ‑S Option
- Providing Secondary Credentials for Administrators Using the ‑T Option
- Displaying Information About Users Using the ‑U Option
- Unlocking or Locking Virtual Machines Using the ‑V Option
- Detecting and Resolving LDAP Entry Collisions Using the -X Option
- Index
Table 5‑11. Certificate Template Status
Status Text Description
The template <name> does not exist
on the <FQDN> enrollment server
domain.
Check that you specied the correct template name.
Certicates generated by this
template can NOT be used to log on
to windows.
This template does not have the smart card usage enabled and data signing
enabled. Check that you specied the correct template name. Verify that you
have .completed the steps described in “Create Certicate Templates Used with
True SSO,” on page 80.
The template <name> is smartcard
logon enabled, but cannot be used.
This template is enabled for smart card logon, but the template cannot be used
with True SSO. Check that you specied the correct template name, verify that you
have gone through the steps described in “Create Certicate Templates Used with
True SSO,” on page 80. You can also check the enrollment server log le, since it
will log what seing in the template is preventing it from being used for True SSO.
Table 5‑12. Certificate Server Configuration Status
Status Text Description
The certicate server <CN of CA>
does not exist in the domain.
Verify that you specied the correct name for the CA. You must specify the
Common Name (CN).
The certicate is not in the NTAuth
(Enterprise) store.
This CA is not an enterprise CA or its CA certicate has not been added to the
NTAUTH store. If this CA is not a member of the forest, you must manually add
the CA certicate to the NTAUTH store of this forest.
Table 5‑13. Certificate Server Connection Status
Status Text Description
The <FQDN> enrollment server is
not connected to the certicate
server <CN of CA>.
The enrollment server is not connected to the certicate server. This state might be
a transitional state if the enrollment server just started, or if the CA was recently
added to a True SSO connector. If the state remains for longer than one minute, it
means that the enrollment server failed to connect to the CA. Validate that name
resolution is working correctly, and that you have network connectivity to the CA,
and that the system account for the enrollment server has permission to access the
CA.
The <FQDN> enrollment server has
connected to the certicate server
<CN of CA>, but the certicate
server is in a degraded state
This state is displayed if the CA is slow at issuing certicates. If the CA remains in
this state, check the load of the CA or the domain controllers used by the CA.
N If the CA has been marked as slow, it will retain this state until at least one
certicate request has been completed successfully, and that certicate was issued
within a normal time frame.
The <FQDN> enrollment server can
connect to the certicate server <CN
of CA>, but the service is
unavailable.
This state is issued if the enrollment server has an active connection to the CA but
it is unable to issue certicates. This state is typically a transitional state. If the CA
does not become available quickly, the state will be changed to disconnected.
Chapter 5 Authenticating Users Without Requiring Credentials
VMware, Inc. 97










