5.2

Table Of Contents
Preparing Active Directory 3
View uses your existing Microsoft Active Directory infrastructure for user authentication and management.
You must perform certain tasks to prepare Active Directory for use with View.
View supports the following versions of Active Directory:
n
Windows 2003 Active Directory
n
Windows 2008 Active Directory
This chapter includes the following topics:
n
“Configuring Domains and Trust Relationships,” on page 21
n
“Creating an OU for View Desktops,” on page 22
n
“Creating OUs and Groups for Kiosk Mode Client Accounts,” on page 22
n
“Creating Groups for View Users,” on page 22
n
“Creating a User Account for vCenter Server,” on page 22
n
“Create a User Account for View Composer,” on page 23
n
“Configure the Restricted Groups Policy,” on page 24
n
“Using View Group Policy Administrative Template Files,” on page 24
n
“Prepare Active Directory for Smart Card Authentication,” on page 25
Configuring Domains and Trust Relationships
You must join each View Connection Server host to an Active Directory domain. The host must not be a
domain controller. You place View desktops in the same domain as the View Connection Server host or in a
domain that has a two-way trust relationship with the View Connection Server host's domain.
You can entitle users and groups in the View Connection host's domain to View desktops and pools. You
can also select users and groups from the View Connection Server host's domain to be administrators in
View Administrator. To entitle or select users and groups from a different domain, you must establish a
two-way trust relationship between that domain and the View Connection Server host's domain.
Users are authenticated against Active Directory for the View Connection Server host's domain and against
any additional user domains with which a trust agreement exists.
NOTE Because security servers do not access any authentication repositories, including Active Directory,
they do not need to reside in an Active Directory domain.
VMware, Inc.
21