Comprehensive policy in VMware View 3.0.1 no matter who got the job

We strive to disable access to the local drive and the only way to it is by loading the models of global policy of VMware in our Active Directory.  We did tis and the Active Directory team ensure that the vms and the user are policy assigned to them. However VMware policy I never see in the local politics of the vmwhen I have VMware view connection.

We disable the local drive and obivous still see them.  Any who do know another way of disabling the local disk access or know what I could do bad on the setyp of world politics.  It did not work on version 3 or 3.0.1

Hi Paul,.

disable the local disks of VMware strategy within the ADM file (client.adm) affects customer theView. So, this means that you must apply the policy to the connected device and is a member of an actress Directory domain. It is also a political base user and should be set to the OU where the user account is in or granted to the user.

If you want to control at the peripheral level (agent, Virtual Office) based readers, you must use the Active Directory policy for this.

In the screenshot below, there was no policy applied:

Now, I put the standard Active Directory policy. This rule is computerized and must be applied to the OU where the virtual office resists in.

Now readers are not visible to the user, not mapped...

I hope this helps.

Thank you

Christoph

Tags: VMware

Similar Questions

  • VMware View - Windows 8?

    Hello

    I am new to this forum and VMware so please be delicate :-)

    First of all, I would like to just confirm that VMware View 5 does not support Windows 8 OS, right? So what (older version number) version of Horizon view don't?

    I already have vSphere Client Version 5.1.0 so if I buy the Horizon view I should be able to deploy Windows 8 workstations, right?


    Best regards, Valentin

    Hello

    You need VMware view 5.2 for windows 8 supported https://www.vmware.com/support/view52/doc/horizon-view-52-release-notes.html

    What's new for the 5.2 Horizon

    VMware view Horizon 5.2 offers improvements valuable to the terms of use and ease of management, further reducing total cost of ownership for VDI.

    What's new with the end-user experience

    • Support for Windows 8 according to desktop computers1
    • 1 3D graphics hardware acceleration
    • Best video and VOIP with Microsoft Lync 2013 support4 communication
    • Simplified access to desktops of Horizon view2
    • Easily connect to any device with HTML3 access desktop
    • Improved productivity from mobile devices with the new feature 'The unit touch'3A

    Concerning

    Mohammed

  • VMware View Enterprise 5 licenses

    Hi all

    I tried to search around the forum, but I have not found any answer...

    We plan to make a View 5 infrastructure with a host on which will run 40 MV and a vCenter server. This infrastructure will be used for a COMPUTER lab in a school and a few machines for teachers.

    We purchase these licenses:

    -1 x academic VMware View 5 Enterprise Bundle: Starter Kit (with x 1 basic support/subscription year)

    -3 x academic VMware View 5 Enterprise Bundle: package of 10 (with the Support/Basic membership x 1 yr)

    If I understand correctly, the VMware licensing is by Sockets, so if I buy a license, I can make a host that is equipped with a plug (and the number of cores). In this case, with the additional licenses for 40 VMS, would I think make a host with more than an outlet? In this case, Sockets how could I implement?

    Thanks in advance

    Cristian

    Hi Christian.

    There isn't "vSphere for desktop" included 40 desktop with these licenses.

    This means that you can run ESX hosts as much as you want and use all sockets in these hosts to your workstations.

    'vSphere for desktop PC' is equivalentto "vSphere Enterpris more ', but the difference is that you are allowed to run the operating systems of office and servers supported on hosts the necessary permits.

    The downside with the help of the 'Business' license, is that you will not be able to use linked clones, offline mode, etc.. For these features, you need the "Prime Minister" license.

    Linjo

  • Migrate to VMware View 4.6

    Hello

    What are the exact differences between VMware View 4.6 and 4.5.

    What operating system supports VMware View 4.6?

    Do we get the best performance with VMware View 4.6 on WAN?

    Note that 4172 between the connection to the server and security server is not necessary. The correct rules are here - http://www.vmware.com/pdf/view-46-architecture-planning.pdf - there is an entire section detailing "for servers security DMZ Firewall rules. See also http://communities.vmware.com/docs/DOC-14974 for the three steps needed to implement.

    Also note that https is the default value for the configuration of the Security server for interaction with the normal client and the secure tunnel (https).

    Select this option.

  • VMware-view-open-client for windows

    Hello

    Anyone know why there is no vmware-view-open-client for windows?

    http://code.Google.com/p/VMware-view-open-client/

    Laughing out loud

    The windows version includes PCoIP that isn't Open source.

  • VMware view Administrator console... increase timeout

    Hi guys

    just migrated to view 4.5 and everything was fine...

    Is it possible to increase the limit of the Vmware view admin console timeout? I would have the dashboard always on my 2nd screen without going all day logon due to delays...

    Thanks

    Very well, you can do this by following these steps:

    Go to: Display Configuration > global settings > check Activate the automatic updates.

    You'll notice that the heading aid next to him said: "the idle session timeouts not happen when automatic updates are enabled, causing the Administrator display to remain active until the browser is closed or an explicit logout is performed."

    This will allow you to follow the Administrator display without waiting times. (And you don't forget to lock your workstation when you leave your desk anyway, so you should be fine. )

  • VmWare View and working group

    You can install VMware View in a workgroup environment. What is the view installation sequence?. I tried to installed on a working group and it keep asking to connect to a domain during installation View Composer. Then I discovered that you must install sight connection to the server first, then composer. But the view connection server doesnot allow me to install in a workgroup environment. Thank you.

    In regards FT then is it not possible to have that between physical and virtual. Both machines must be virtual.

    It should be easy to connect your computers to a new network. Did you create a new vSwitch? The error messages?

    Best regards

    Linjo

    If you find this information useful, please give points to "correct" or "useful".

  • VMWare View 3.1 attribute to the access device?

    Does anyone know how to get VMWare View 3.1 allocate VM sessions based on the device (or place)?  We have a classroom environment where we want user Sally to sit down to a thin client XPe in Science class and receive a science VM session.  Then move to the class of mathematics and connection to get a math VM session... all with no other than login prompt.

    As much as I know, VMWare View 3.1 can only assign rights to users, not computers.  Does anyone know if there is a way around this?

    I hear that someone would have a solution based on the use of Microsoft GPOs, but I do not have many details on that... waiting for the reports of GPO.

    Thank you

    You can't computers right.  You can give right to several pools and the user to choose which pool she wants to go to when you connect.

  • VMware view for office management

    Our Organization is currently looking in the options of office management. Currently the staff to manage their own desktop computers (run as administrator) and assistance to support (painful, yes I agree). We seek to make progress on the path to a strategy of Fund managed with a product like the MS system center configuration Manager. However, we are also interested the concept of vmware view, since he would theoretically cut down on the need to support and boost security.

    Does anyone have any success stories/reccomendations of implementation of vmware view as a desktop replacement in a common scenario?

    I worked on a project where the customer has replaced desktop 1200 by VDI. Initially they BIG clients like the connection device, but now they also used will be to implement thin clients. It is a client of finance, so that they use Office products, Acrobat Reader and some banking applications.

    Don't forget to assign points if this answer was helpful for you.

    Blog:

    http://Communities.VMware.com/blogs/Dommermuth | http://www.thatsmyview.NET/

  • Disable the protocols and encryption algorithms in VMware View connection server and security

    Hello

    In my recent deployment, I had a customer request to disable some protocols and encryption at the Server VMware View connection and security. I read some articles and found that this has been achieved by editing the locked.properties file. But when we have edited and replaced the file, users could not connect to the virtual desktop, so came back to us backwards and desktop computers worked fine.

    I found a few articles that we don't need to edit the locked.properties file in VMware view Horizon 6. If someone has done this please guide me through. Here are the details of the protocols and encryption algorithms that should be disabled

    Diffie-Hellman key

    Enable SSL v2/V3 and TLS 1.1 and 1.2

    Disable the RC4 encryption algorithm

    Select the secret of transfer (if possible)


    VMware view 6 is the connection to the server and security server.


    Thank you.

    Hello

    I implemented the following steps (from the manual):

    1. update the JCE policy files to take in charge the high-strength Cipher Suites

    You can add some cipher suites of high resistance for greater assurance, but first you must update the local_policy.jar and US_export_policy.jar files to each server instance and the security strategy for JRE 7 see connection to the server. You update these policy files by downloading the files to extend JCE (Java Cryptography) unlimited strength political jurisdiction from the Oracle Java SE download site 7.

    If you include some high-strength cipher suites in the list and you do not replace the policy files, you cannot restart the VMware view Horizon connection to the Server service.

    Policy files are located in the directory C:\Program View\Server\jre\lib\security from VMware.

    For more information on the download of the JCE unlimited strength jurisdiction policy 7 files, see the Oracle Java SE download site: http://www.oracle.com/technetwork/java/javase/downloads/index.html.

    After you update the policy files, you need to create backups of the files. If you upgrade the instance of the view connection server or security server, any changes you have made to these files can be replaced, and you may need to restore the backup files.

    2. the changes that policies of global acceptance with ADSI Edit

    • Start the ADSI utility on your computer see connection to the server.
    • In the console tree, select Connect to
    • In the selection or type a unique name text box or a naming context, type the unique name
      DC, DC = vdi is vmware, DC = int.
    • In the type or select a text field or the server box, select or type localhost: 389 or the name of a fully qualified domain (FQDN) of the server computer to connect to port 389 followed view.

    For example: localhost: 389 or mycomputer.mydomain.com:389

    • Expand the tree of the ADSI Editor, OU = properties, select OU = Global, then select OU = common in the right pane.
    • On the object CN = common, Global = UO, UO = properties, select each attribute that you want to change and enter the new list of security protocols or cipher suites.
      I used the following settings:

    EAP-ServerSSLCipherSuites: \LIST:TLS_RSA_WITH_AES_128_CBC_SHA,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_256_CBC_SHA256

    EAP-ServerSSLSecureProtocols_ \LIST:TLSv1.1,TLSv1.2

    It is not the highest possible, but they work with all the features of our customers.

    • Restart the service of VMware view Horizon connection server (server connection and security).

    This is not Activate secret transfer (if possible) , but other points are covered.

    If anyone can give a tip to activate the transfer secret, I would be grateful.

  • VMware View Agent 5.2.0 PCoIP over WAN fails

    Recently, I did an upgrade on VMware View VMware view horizon 5.2 4.6 square.

    After the upgrade the 4.6.0 view agent in virtual machines of my parents to view agent 5.2.0 and rebuild the office pools, external PCoIP does not work. Can I open a session in the 5.2 Client view, see the list of office pools, select a pool, the desk at work close and try to open remotely. After 1 second, this error appears:

    Error: Overview of VMware View Client: The connection to the remote computer has ended.

    What does not work:

    • External/WAN via PCoIP for workstations with the view Agent 5.2.0

    What does not work:

    • Internal/LAN via PCoIP for workstations with the view Agent 5.2.0
    • Internal/LAN via RDP for workstations with the view Agent 5.2.0
    • External/WAN via RDP for workstations with the view Agent 5.2.0
    • External/WAN via PCoIP for workstations with the Agent View 5.1.3 or lower (tested up to 4.6.0 Agent view)

    I even tried to build a new pool of desktop Windows 7 in a new OU in the active without optimizations VDI directory or group policy. I tried with and without the firewall Windows is activated. In any case, this new office pool works externally via any Agent from view but the view Agent 5.2.0.

    Is it the 5.2.0 Agent view have the same firewall/port that the Agent View 5.1.3 requirements? What else can I test or try to get external PCoIP for desktop computers to work with the view Agent 5.2.0?

    Finally, we discovered the problem / solution. We on a security apparatus of Palo Alto Networks that blocked traffic PCoIP 5.2.0 but not PCoIP 5.1.3 traffic.

    According to a backline Vmware engineer:

    "A change was made to the ephemeral TLS connection that is used to establish trust and to negotiate parameters for subsequent UDP traffic network. This change allows the customer to use their own certificate for TLS server for this connection. For more details of what happens during the installation of PCoIP, and how this changed view 5.2, see KB 1038762. »

    It seems that Palo Alto Networks did not like this change. When we removed our Palo Alto of WAN device, PCoIP 5.2.0 connections could be created. We finally had create a rule to allow the category: private-ip-addresses and URL: pcoip - by default-sni. Once this change has been made, connections WAN PCoIP 5.2.0 started working.

  • Card reader chip as a pass through for VMware View 5.1 device (NOT USED for AUTHENTICATION)

    I try to get a USB Smart Card Reader * to work on related under VMware View 5.1 clones

    * not as an authentication device, just like a transmission of smart card reader

    Not tried:

    1 activated pass through card reader in the registry for the VMware view client

    2. active "allow redirection of card reader" in the policy active directory

    3. customer connected to view, selected USB drive list, connected to the customer

    After that, the card reader will appear with a "generic smart card", but it does not actually work.

    We executed the diagnosis of the smart card and he pointed out that the drivers are ok and windows service is ok, but the map can not be found.

    PS: When we tried first, about 2 weeks ago it worked, but it has suddenly stopped working. (Needless to say that the virtual machines and the Clients were restarted several times).

    Check that you have not installed the "PCoIP smart card Redirection" option during the installation of the agent. If it is present, it will redirect calls made RDP client smart card. Because you use a 'local' to the desktop USB drive, you don't want to do.

  • To print from a virtual machine in VMware View

    I need to set up printing if the VMware View Client running on an xp system, some so that I can operate that this either through Group Policy.

    Post edited by: a.p. - adjusted/fixed the title

    Hello

    These topics should help you set up printing in view approx.

    Setting Up Location-Based printing - page 154 https://www. VMware.com/pdf/view-46-administration.pdf

    Set preferences for the virtual printer to windows printing function
    Clients - Page 100 www. VMware.com/pdf/view-46-installed.pdf

    -noble

  • VMware View client silent install switches

    I am unable to find a doc who has all the silent install switches listed for installation of the vmware view client. I found this thread http://communities.vmware.com/message/924962 but it does not list what makes each switch and I need to remove the reboot. I use landesk for this to get out for our customers. Also is there anyway to also put in the default server view vmware with a switch without using Group Policy? Thanks for any help I get.

    http://OZTeK.blogspot.com/2009/07/VMware-view-client-silent-installation.html

    See you soon,.

    Oz

  • ThinPro with VMware View USB Redirection

    Hi all:

    I'm trying to configure my workstation (t620 ThinPro 5.1 running) to start required services necessary for USB with VMware View forwarding at startup.  I tried to add the command to /etc/rc.local and created my own init.d script, but none of these options automatically launch services.  Run manually /etc/rc.local and the custom init.d script launches the services successfully.

    Has someone managed to get the necessary USB redirection services running at the start?  Any guidance is appreciated.

    Thank you.

    Solved my problem... changed under USB Manager Remote Protocol of VMware View.  Updated this setting caused VMware services to run at startup.

Maybe you are looking for