Installation guide

Table Of Contents
Procedure
1 On your Active Directory server, select Start > Administrative Tools > Active Directory Users and
Computers.
2 Right-click your domain and select Properties.
3 On the Group Policy tab, click Open to open the Group Policy Management plug-in.
4 Right-click Default Domain Policy and click Edit.
5 Expand the Computer Configuration section and open Windows Settings\Security Settings.
6 Right-click Restricted Groups, select Add Group, and add the Remote Desktop Users group.
7 Right-click the new restricted Remote Desktop Users group and add your View desktop users group to
the group membership list.
8 Click OK to save your changes.
Using View Group Policy Administrative Template Files
View includes several component-specific group policy administrative (ADM) template files.
During View Connection Server installation, the View ADM template files are installed in the
install_directory
\VMware\VMware View\Server\Extras\GroupPolicyFiles directory on your View
Connection Server host. You must copy these files to a directory on your Active Directory server.
You can optimize and secure View desktops by adding the policy settings in these files to a new or existing
GPO in Active Directory and then linking that GPO to the OU that contains your View desktops.
See the VMware View Administrator's Guide for information on using View group policy settings.
Prepare Active Directory for Smart Card Authentication
You might need to perform certain tasks in Active Directory when you implement smart card authentication.
n
Add UPNs for Smart Card Users on page 27
Because smart card logins rely on user principal names (UPNs), the Active Directory accounts of users
that use smart cards to authenticate in View must have a valid UPN.
n
Add the Root Certificate to Trusted Root Certification Authorities on page 27
If you use a CA to issue smart card login or domain controller certificates, you must add the root certificate
to the Trusted Root Certification Authorities group policy in Active Directory. You do not need to
perform this procedure if the Windows domain controller acts as the root CA.
n
Add the Root Certificate to the Enterprise NTAuth Store on page 28
If you use a CA to issue smart card login or domain controller certificates, you must add the root certificate
to the Enterprise NTAuth store in Active Directory. You do not need to perform this procedure if the
Windows domain controller acts as the root CA.
VMware View Installation Guide
26 VMware, Inc.