7.0

Table Of Contents
What to do next
Specify the account in View Administrator when you configure View Composer domains in the Add
vCenter Server wizard and when you configure and deploy linked-clone desktop pools.
Create a User Account for Instant Clone Operations
If you deploy instant clones, you must create a user account in Active Directory that allows View to perform
certain operations in Active Directory.
Specify this account when you add an instant clone domain administrator in View Administrator before
deploying instant clones. For more information, see "Add an Instant Clone Domain Administrator" in the
Setting Up Desktop and Application Pools in View document.
Procedure
1 In Active Directory, create a user account in the same domain as your Connection Server or in a trusted
domain.
2 Add the Create Computer Objects, Delete Computer Objects, and Write All Properties permissions to
the account in the Active Directory container in which the linked-clone computer accounts are created
or to which the linked-clone computer accounts are moved.
The following list shows all the required permissions for the user account, including permissions that
are assigned by default:
n
List Contents
n
Read All Properties
n
Write All Properties
n
Read Permissions
n
Reset Password
n
Create Computer Objects
n
Delete Computer Objects
3 Make sure that the user account's permissions apply to the Active Directory container and to all child
objects of the container.
Configure the Restricted Groups Policy
To be able to connect to a remote desktop, users must belong to the local Remote Desktop Users group of
the remote desktop. You can use the Restricted Groups policy in Active Directory to add users or groups to
the local Remote Desktop Users group of every remote desktop that is joined to your domain.
The Restricted Groups policy sets the local group membership of computers in the domain to match the
membership list settings defined in the Restricted Groups policy. The members of your remote desktop
users group are always added to the local Remote Desktop Users group of every remote desktop that is
joined to your domain. When adding new users, you need only add them to your remote desktop users
group.
Prerequisites
Create a group for remote desktop users in your domain in Active Directory.
Chapter 5 Preparing Active Directory
VMware, Inc. 33