Specifications

Restricting View Desktop Access
You can use the restricted entitlements feature to restrict View desktop access based on the View Connection
Server instance that a user connects to.
With restricted entitlements, you assign one or more tags to a View Connection Server instance. Then, when
configuring a desktop pool, you select the tags of the View Connection Server instances that you want to be
able to access the desktop pool. When users log in through a tagged View Connection Server instance, they
can access only those desktop pools that have at least one matching tag or no tags.
For example, your VMware View deployment might include two View Connection Server instances. The first
instance supports your internal users. The second instance is paired with a security server and supports your
external users. To prevent external users from accessing certain desktops, you could set up restricted
entitlements as follows:
n
Assign the tag "Internal" to the View Connection Server instance that supports your internal users.
n
Assign the tag "External" to the View Connection Server instance that is paired with the security server
and supports your external users.
n
Assign the "Internal" tag to the desktop pools that should be accessible only to internal users.
n
Assign the "External" tag to the desktop pools that should be accessible only to external users.
External users cannot see the desktop pools tagged as Internal because they log in through the View Connection
Server tagged as External, and internal users cannot see the desktop pools tagged as External because they log
in through the View Connection Server tagged as Internal. Figure 5-1 illustrates this configuration.
Figure 5-1. Restricted Entitlements Example
Chapter 5 Planning for Security Features
VMware, Inc. 55