User manual

Table Of Contents
2 Congure the smart card removal policy.
Option Description
Set the policy on the server
If you use Horizon Administrator to set a policy, the choices are to
disconnect users from Connection Server when they remove their smart
cards or to keep users connected to Connection Server when they remove
their smart cards and let them start new desktop or application sessions
without reauthenticating.
a In Horizon Administrator, select View  > Servers.
b On the Connection Servers tab, select the Connection Server instance
and click Edit.
c On the Authentication tab, select or deselect the Disconnect user
sessions on smart card removal check box to congure the smart card
removal policy.
d Click OK to save your changes.
e Restart the Connection Server service to make your changes take eect.
If you select the Disconnect user sessions on smart card removal check
box, Horizon Client returns to the Recent window when users remove
their smart cards.
Set the policy on the desktop
If you use the Group Policy Editor (gpedit.msc), you have the following
possible seings: no action, lock workstation, force log o, or Disconnect if
a Remote Desktop Services session.
After you open gpedit.msc in the desktop operating system, go to
Windows  > Security  > Local policies > Security options >
Interactive logon: smart card removal behavior. Run the
gpupdate /force command after you change the conguration to force a
group policy refresh.
Touch ID Authentication Requirements
To use Touch ID for user authentication in Horizon Client, you must meet certain requirements.
iPad and iPhone models
Any iPad or iPhone model that supports Touch ID, for example, iPad Air 2
and iPhone 6.
Operating system
requirements
n
iOS 8 or later.
n
Add at least one ngerprint in the Touch ID & Passcode seing.
Connection Server
requirements
n
Horizon 6 version 6.2 or a later release.
n
Enable biometric authentication in Connection Server. For information,
see "Congure Biometric Authentication" in the View Administration
document.
n
The Connection Server instance must present a valid root-signed
certicate to Horizon Client.
Horizon Client
requirements
n
Set the certicate checking mode to Never connect to untrusted servers
or Warn before connecting to untrusted servers. For information about
seing the certicate checking mode, see “Seing the Certicate
Checking Mode for Horizon Client,” on page 27.
n
Enable Touch ID by tapping Enable Touch ID on the server login
window. After you successfully log in, your Active Directory credentials
are stored securely in the iOS device's Keychain. The Enable Touch ID
option is shown the rst time you log in and does not appear after Touch
ID is enabled.
Using VMware Horizon Client for iOS
10 VMware, Inc.