Configuring Remote Desktop Features

Table Of Contents
With earlier client or agent releases, client drive redirection folders and les are sent across the network
without encryption and might contain sensitive data, depending on the content being redirected. If the
secure tunnel is enabled, client drive redirection connections between Horizon Client and the View Secure
Gateway are secure, but connections from the View Secure Gateway to desktop machines are not encrypted.
If the secure tunnel is disabled, client drive redirection connections from Horizon Client to the desktop
machines are not encrypted. To ensure that this data cannot be monitored on the network, use client drive
redirection only on a secure network if Horizon Client is earlier than version 3.5 or agent is earlier than
version 6.2.
The Client Drive Redirection setup option in the agent installer is selected by default. As a best practice,
enable the Client Drive Redirection setup option only in desktop pools where users require this feature.
Use Group Policy to Disable Client Drive Redirection
You can disable client drive redirection by conguring a Microsoft Remote Desktop Services group policy
seing for remote desktops and RDS hosts in Active Directory.
For more information about client drive redirection, see the Using VMware Horizon Client document for the
specic type of desktop client device. Go to
hps://www.vmware.com/support/viewclients/doc/viewclients_pubs.html.
N This seing overrides local registry and Smart Policies seings that enable the client drive redirection
feature.
Prerequisites
If your View deployment includes a back-end rewall between your DMZ-based security servers and your
internal network, verify that the back-end rewall allows trac to port 9427 on your single-user and RDS
desktops. TCP connections on port 9427 are required to support client drive redirection.
For Horizon Client 4.2 or Horizon 7 version 7.0.2 or later, port 9427 is not required to be open if VMware
Blast Extreme is enabled because client drive redirection transfers data through the virtual channel.
Procedure
1 In the Group Policy Editor, go to Computer 
Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Device
and Resource Redirection.
This navigation path is for Active Directory on Windows Server 2012. The navigation path diers on
other Windows operating systems.
2 Enable the Do not allow drive redirection group policy seing.
Use Registry Settings to Configure Client Drive Redirection
You can use Windows registry key seings to control client drive redirection behavior on a remote desktop.
This feature requires Horizon Agent 7.0 or later and Horizon Client 4.0 or later.
The Windows registry seings that control client drive redirection behavior on a remote desktop are located
in the following path:
HKLM\Software\VMware, Inc.\VMware TSDR
You can use the Windows Registry Editor on the remote desktop to edit local registry seings.
N Client drive redirection policies set with Smart Policies take precedence over local registry seings.
Configuring Remote Desktop Features in Horizon 7
48 VMware, Inc.