6.0.2

Table Of Contents
Prevent Access to View Desktops Through RDP
In certain View environments, it is a priority to prohibit access to View desktops through the RDP display
protocol. You can prevent users and administrators from using RDP to access View desktops by configuring
pool settings and a group policy setting.
By default, while a user is logged in to a View desktop session, you can use RDP to connect to the virtual
machine from outside of View. The RDP connection terminates the View desktop session, and the View
user's unsaved data and settings might be lost. The View user cannot log in to the desktop until the external
RDP connection is closed. To avoid this situation, disable the AllowDirectRDP setting.
NOTE Remote Desktop Services, called Terminal Services on Windows XP systems, must be started on the
virtual machine that you use to create pools and on the virtual machines that are deployed in the pools.
Remote Desktop Services are required for View Agent installation, SSO, and other View session-
management operations.
Prerequisites
Verify that the View Agent Configuration Administrative Template (ADM) file is installed in Active
Directory. See “Using View Group Policy Administrative Template Files,” on page 204.
Procedure
1 Select PCoIP as the display protocol that you want View Connection Server to use to communicate with
Horizon Client devices.
Option Description
Create a desktop pool
a In View Administrator, start the Add Desktop Pool wizard.
b On the Desktop Pool Settings page, select PCoIP as the default display
protocol.
Edit an existing desktop pool
a In View Administrator, select the desktop pool and click Edit.
b On the Desktop Pool Settings tab, select PCoIP as the default display
protocol.
2 For the Allow users to choose protocol setting, select No.
3 Prevent devices that are not running Horizon Client from connecting directly to View desktops through
RDP by disabling the AllowDirectRDP group policy setting.
a On your Active Directory server, open the Group Policy Management Console and select
Computer Configuration > Policies > Administrative Templates > Classic Administrative
Templates (ADM) > VMware View Agent Configuration.
b Disable the AllowDirectRDP setting.
Deploying Large Desktop Pools
When many users require the same desktop image, you can create one large automated pool from a single
template or parent virtual machine. By using a single base image and pool name, you can avoid dividing the
machines arbitrarily into smaller groups that must be managed separately. This strategy simplifies your
View deployment and administration tasks.
To support large pools, you can create pools on ESXi clusters that contain up to 32 ESXi hosts. You can also
configure a pool to use multiple network labels, making the IP addresses of multiple port groups available
for the virtual machines in the pool.
Setting Up Desktop and Application Pools in View
124 VMware, Inc.