- Install – Horizon Client 4.4 Manual
- Launch Horizon Client
- Certificate Validation
- Client Device Redirection
- HTML Blast
- Thin Clients
- Repurposed PCs
- Horizon Client GPO – Security Settings
💡 = Recently Updated
Install – Horizon Client Manual
The Horizon Clients can be downloaded from http://www.vmware.com/go/viewclients.
- Logon to the client machine as an administrator. Administrative rights are required for the Horizon Client installation. You can also push the client silently as described in the next section.
- Open a browser and enter the name of your Horizon Connection Server in the address bar (e.g. https://view.corp.local). Use https://.
- Click the Install VMware Horizon Client link. If the Horizon Clients are installed on the Connection Server, the client will download immediately. Or, you’ll be taken to vmware.com to download the client.
- If you are redirected to https://my.vmware.com/en/web/vmware/info/slug/desktop_end_user_computing/vmware_horizon_clients/4_0#win64, then find the Horizon Client for Windows, and click Go to Downloads.
- Then click Download.
- Run the downloaded VMware-Horizon-Client-4.4.0.exe.
- If you want to use the URL Content Redirection feature in Horizon 7, run the installer with the following switches:
- In the Install VMware Horizon Client page, click I Agree & Install. Or you can select Customize.
- If you selected Customize, in the Network protocol configuration page, select IPv4, and click Next.
- In the Custom Setup page, note the default features, and click Next.
- In the Default Server page, enter the load balanced name of your Horizon Connection Server or Horizon Security Server or Unified Access Gateway (formerly known as Access Point), and click Next.
- In the Enhanced Single Sign On page, make your desired selections, and click Next.
- In the Configure Shortcuts page, click Next.
- In the Ready to Install the VMware Horizon Client page, click Install.
- In the Completed the VMware Horizon Client Setup Wizard page, click Finish.
- Click Yes when prompted to restart.
Verify URL Redirection
- To verify that URL Content Redirection is installed, verify the presence of the file C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-url-protocol-launch-helper.exe.
- There’s also a new IE add-on.
- URL Content Redirection is configured using group policy.
- Horizon Client 4.1 and newer has an online update feature that can be enabled using group policy. The Enable Horizon Client online update setting is available in the vdm_client.adm GPO template.
- Once the GPO setting is enabled, in the Horizon Client, click the hamburger icon on the top right, and click Software Updates.
- Then click Check for Updates.
Install – Horizon Client Silent
https://www.vmware.com/pdf/horizon-view/horizon-client-windows-44-document.pdf has instructions on how to install the Horizon Client silently. Common methods for installing the client silently include: SCCM and Active Directory Group Policy Computer Startup Script.
Note that there is no space between /v and the first “. Also, everything after /v is enclosed in a single pair of quotes. If you need to use quotes somewhere in the middle of the /v parameter, use \ “ so the quotes are escaped.
Launch Horizon Client
VMware Fling View Auto-Connection Utility: The View Auto-Connection Utility allows you to connect the VMware View Client automatically into a View desktop or an application pool when the system starts up.
To launch a View Desktop or application manually:
- From the Start Menu run VMware Horizon Client.
- If there is no server in the list, then use the New Server button on the top left.
- To change SSL certificate verification, open the Options (hamburger) menu, and click Configure SSL.
- You can also click the Options menu to Hide the selector after launching an item.
- If you want to perform pass-through authentication, click the hamburger icon, and select Log in as current user.
- If you have apps published to an Unauthenticated User, click the hamburger icon, and select Log in anonymously using Unauthenticated Access.
- Double-click the server.
- Enter your username and password, and then click Login.
- If you see too many domains in the Domain list, you can filter them by running the
vdmadmin -Ncommand. See Configuring Domain Filters Using the ‑N Option at VMware Pubs.
- Horizon 7.1 has an option to Hide domain list in client user interface. If you enable this in Global Settings, then users must enter UPN, or Domain\Username. 💡
- If you see a certificate message, click Continue.
- If you have a bunch of icons, start typing in the name of the icon and it will highlight.
- If the pool settings allow it, you can right-click and icon, and select a protocol. VMware Blast is the recommended protocol.
- Either double-click an icon, or right-click an icon, and click Launch.
- When connecting, you might be prompted to access your local files.
- Once you are connected to a remote desktop, you can use the menu at the top of the screen. An interesting option is Autoconnect to this Desktop. This setting is stored on the Horizon Connection Server in LDAP and there doesn’t appear to be any way to automate enabling it.
- In Horizon Client 4.4, administrators can enable a Pool Setting that allows users to Restart the remote desktop gracefully. 💡
- The Horizon Client also has a taskbar jump list showing recently launched applications and desktops.
Tom Fenton How To Determine Your Horizon View Desktop Protocol: View Administrator > Sessions node, netstat, and registry.
In the Horizon Client, once you are connected to a server, you can right-click an icon, and click Create Shortcut. This places an icon on your local desktop.
Or you can right-click an icon, and click Add to Start Screen.
Find the shortcut in the VMware Horizon folder of your Start Menu.
- In the Horizon Client, you can right-click an icon, and Mark as Favorite. Favorites are stored in the LDAP database on the Horizon Connection Server.
- This places a star icon on the top-right of the application or desktop.
- On the top right of the Horizon Client, you can switch to the Favorites View so that only icons selected as Favorites are displayed.
- Or switch back to the All View.
- On the Question Mark menu is Support Information.
- Users can click this to find the client name, client operating system, Horizon Client version, the Horizon Connection Server name, and currently connected desktops.
When you connect to a Horizon Connection Server, and if the certificate is not trusted or valid, then the user is prompted to accept the certificate. You can disable this prompt for any client machine that can be controlled using group policy.
- Copy the Horizon .admx files to PolicyDefinitions if you haven’t already.
- Create a GPO that is linked to an OU containing the Horizon Client machines. These are the end-user PCs, not the virtual desktops.
- Edit the GPO.
- Go to Computer Configuration | Policies | Administrative Templates | VMware Horizon Client Configuration | Scripting Definitions.
- On the right, double-click Server URL.
- Set the URL to your Horizon View URL, and click OK.
- On the left, click Security Settings. On the right, open the setting Certificate verification mode.
- Enable the setting and make your choice. No Security will disable the certificate prompt. Then click OK.
Client Drive Redirection
- When you connect to a Horizon Agent that has Client Drive Redirection enabled, you are prompted to allow it.
- By default, only the user’s local profile is redirected.
- You can redirect more folders or drives by clicking the Options menu, and clicking Share Folders.
- In the Sharing tab, add drives or folders, and then click OK.
- The folders or drives you added are now visible within Explorer in the Horizon Desktop.
- Client Drive Redirection also works in published applications.
- To change Client Drive Redirection settings in published applications, go back to the Horizon Client, right-click an icon, and click Settings. Or use the gear icon on the top right.
- The client drive redirection prompt configuration is stored in %appdata%\VMware\VMware Horizon View Client\prefs.txt. You can edit this file to disable the prompt. See Rob Beekmans Customizing the VMware Horizon Client sharing pop-up for more info.
Serial Port Redirection
- If you connect to a Horizon Agent that has Serial Port Redirection enabled, then a new icon will appear in the system tray.
- Right-click the icon to map the remote COM port to the local COM port.
RDSH USB Drive Redirection
The new Client Drive Redirection feature in Horizon View 6.2 and newer replaces the older USB Redirection feature detailed in this section.
VMware Blog USB Redirection of Storage Devices in Horizon with View for RDSH Desktops and Apps: Requirements:
- Horizon 6 Agent 6.1 or later with USB Redirection feature selected
- Horizon Client 3.3 or later with USB Redirection feature selected
- USB Access Policy set to Allow
The client UI for USB redirection in RDSH desktops is the same as the client UI in VDI desktops.
The client UI for USB redirection in RDSH apps is different from the client UI in VDI desktops. To open the app contextual menu, the end user launches the application. After the application is launched, the user returns to the desktop and application selection screen and right-clicks the application icon.
The user selects Settings from the application contextual menu to open the settings dialog box. The user can alternatively launch the settings dialog box by right-clicking the Horizon Client icon from the system tray and selecting Settings.
When the user clicks USB Devices in the left panel of the settings window, the available USB storage devices are shown in the middle panel. The user selects the device they want to redirect to Notepad and then clicks Connect.
They are presented with a list of open applications to which the USB device can be connected. The redirected USB storage device belongs to the user’s Windows session, not to the specific application. If the user launches another application later on, and that application is hosted from the same RDSH server, that application can also have access to the redirected USB storage device. If an application is published from a different RDSH server, then the device must first be disconnected from the applications already using it on the other RDSH server.
In some cases, you might want to allow only specific USB storage devices to be redirected. You achieve this by configuring Global Policy Object (GPO) settings for View and applying them to either the RDSH server or one or more client machines. Details at the blog post.
From VMware BlogsScanner Redirection in Horizon with View: we have added scanner redirection to Horizon with View for use with both VDI desktops and Remote Desktop Session Host (RDSH) applications and desktops. The new scanner redirection functionality in View works by capturing the entire image at the client with the scanning device, compressing the image, and sending that compressed image to the guest in the data center, where the image is presented by a “virtual scanner device” to the application that requested the image capture. The scanner redirection functionality supports both TWAIN and WIA scanning modes, and allows images to be captured from both scanners and other imaging devices (such as webcams).
The scanner redirection functionality requires the Horizon Agent version 6.0.2 or later, and the Windows Horizon Client 3.2 or later.
When you install the Horizon Agent component, be sure to select the scanner redirection feature if you want to use it; it is disabled by default. If you are installing the feature onto a server-based OS (Windows Server 2008 R2 or Windows Server 2012 R2) for either VDI desktops or RDSH desktops or applications, then be sure that the Desktop Experience feature (a Microsoft operating system feature) is installed on the server OS first. (This is a prerequisite for installing scanners in a server-based OS.)
After a user makes a connection from a compatible Windows Horizon Client to the new Horizon Agent, a new tool-tray application icon appears. The user clicks the icon to reveal the compatible image acquisition devices available for scanning.
The default mode of operation is, however, that “it should just work,” and the seamless hosted application should be able to acquire an image without needing manual intervention. The user may need to adjust the preferences if more than one imaging device is connected to the client machine, and the user wants to select a specific scanner, or if the user wants to adjust the scan resolution, and so on.
Scanner Redirection Preferences, available by clicking Preferences from the tool-tray icon, allows further configuration of the scanning process, for example, adjusting the default compression applied to the scanning. This can greatly reduce the bandwidth needed to transmit the image (the compression is applied on the client side before the image is transmitted to the guest), but, of course, the more an image is compressed, the lower the image quality. In addition, in the Scanner Redirection Preferences, options are available to adjust the default image capture device (for example, automatic mode, last-used, or an absolute specified device).
These preferences can also be adjusted by way of Group Policy options in the guest OS. A new GPO file (available in the Horizon with View GPO Bundle) allows this configuration. See Configuring Scanner Redirection in Setting Up Desktop and Application Pools in View for more information
Scanner Redirection Caveats
From VMware Communities:
- Scanner redirection does not create a device on your virtual desktop that matches the name of the actual scanner. It creates a generic scanner in Device Manager called VMWare Virtual WIA Scanner (or VMWare Virtual TWAIN Scanner I am assuming). For us this stinks because the image capture software our client uses (Vertex by Jack Henry), has a prepopulated list of scanners you can select. So if we plug in a Canon-CR50 and select Canon CR50/80 in the application, it does not recognize that this scanner is attached to the virtual desktop.
- There is a tick box option in the scanner preferences dialog box titled “Use vendor defined names for TWAIN scanners”. This should solve the issue you mention and we added it specifically to cover the problematic use case you mention.
- This only applies to TWAIN scans, WIA can’t use the vendor name.
- You must install a TWAIN or WIA driver on your thin client. If you can’t find a TWAIN or WIA driver, you are out of luck. For teller check image scanners, we have found no TWAIN or WIA drivers for the TellerScan TS-230, TS-240, or the Canon CR-55. We have found a TWAIN driver for the Canon CR-50 (from the Canon Europe site no less), but issue #1 above means we are out of luck.
Inside the virtual desktop, if you go to Devices and Printers, it will look a little weird. To see all of the client printers, right-click on the TP printer and use the expandable menus.
But when you print from an application, all printers appear normally.
File Type Association
Some published applications might have file types associated with them. When you double-click a file with the configured extension, you might be prompted to open the file using the remote application.
In Horizon Client, if you right-click an icon and click Settings:
On the Sharing page, you can disable this functionality.
It’s also configurable in the client-side registry at HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\VMware, Inc.\VMware VDM\Client by creating a String value at named AllowFileRedirection and setting it to false. See VMware Communities for more information.
From the Horizon Connection Server webpage, you can click the VMware Horizon View HTML Access link to launch a desktop or application inside your browser. While Internet Explorer 9 is supported, some functionality, like clipboard and audio, is only available in Internet Explorer 10 and newer, Chrome and Firefox.
In Horizon 6.2 and later, you can launch applications as well as desktops from HTML Blast.
If you click the star icon then you can Mark the icon as a Favorite. Favorites are stored in the LDAP database on the Horizon Connection Server.
Applications and desktops are launched within the browser window. You can click the vertical lines on the left to switch to a different application or desktop.
You can open the Copy & Paste panel to copy between the local machine and the remote machine.
VMware View Thin Client Compatibility Guide – Thin Client Device and Model Information. It shows thin client models and the version of Horizon View that is supported with the model.
From Chris Halstead VMware Horizon View AutoConnection Utility: I decided to write an app in .NET that is essentially a wrapper for the View Client. It creates the command line variables based on what the user configures in the GUI and automatically connects to the specified desktop or application pool. All of the user configured information is stored in the registry under the current user hive.
The application silently and automatically connects into either a desktop or application pool each time a user logs in by placing it in the startup folder.
Once you have tested your connection, you are ready to enable AutoConnection. You enable AutoConnection by checking the “Enable AutoConnection” box. A common use case would be to place the .exe in the Windows startup folder so that every time a user logs in it will automatically connect to the Virtual Desktop.
This will run the application with the GUI hidden and will automatically connect to the specified pool. The application will minimize to the system tray and a balloon will indicate the connection process is occurring.
Horizon Client Group Policy – Security Settings
The Horizon GPO Bundle includes policy templates for the Horizon Client. See http://www.carlstalhood.com/horizon-group-policy-and-profiles/#viewtemplates to install the ADMX files.
Here are some security GPO settings recommended (VMware Horizon with View Security Hardening Overview) by VMware:
|Computer Config | Policies | Administrative Templates | VMware Horizon Client Configuration | Scripting definitions
Disable 3rd-party Terminal Server plugins = enabled
|Computer Config | Policies | Administrative Templates | VMware Horizon Client Configuration | Security Settings
Allow command line credentials = disabled
Certificate verification mode = enabled, Full Security
Default value of the ‘Log in as current user’ checkbox = disabled
Display option to Log in as current user = disabled
Servers Trusted for Delegation = enabled