Release Notes for VMware Horizon 7 version 7.0.3
Last Updated: 26 May 2016
These release notes include the following topics:
What's New in This Release
VMware Horizon 7 version 7.0.3 provides the following new features and enhancements. This information is grouped by installed component.
For information about the issues that are resolved in this release, see Resolved Issues.
View Connection Server
View PowerCLI is deprecated. Horizon PowerCLI replaces View PowerCLI and includes cmdlets that you can use with VMware PowerCLI.
- For more information about Horizon PowerCLI cmdlets, read the VMware PowerCLI Cmdlets Reference.
- For information on the API specifications to create advanced functions and scripts to use with Horizon PowerCLI, see the View API Reference at the VMware Developer Center
- For more information about sample scripts that you can use to create your own Horizon PowerCLI scripts, see the Horizon PowerCLI community on GitHub.
Horizon Agent for Linux
Linux desktops now support the following features:
- Audio input support
- Ubuntu 16.04 support
- Software H.264 Encoder to support multiple monitors
- Clipboard redirection support on all distributions
- vGPU support with NVIDIA M6 graphics card on RHEL 6.6/6.7/6.8/7.2 Workstation x64
- You can compile a black list to ensure that the URLs specified in the list will not be able to redirect Flash content. You must enable the Horizon Agent GPO setting FlashMMRUrlListEnableType to use either a white list or black list.
- Horizon Agent and Horizon Client can now leverage H.264 codec technology.
- Previously, Horizon Agent and Horizon Client supported only a single monitor. This feature has been enhanced to support multiple monitors.
- The following remote desktop operating systems are now supported:
- Windows 10 version 1607 Long-Term Servicing Branch (LTSB)
- Windows Server 2016
For enhanced security, you can enable the digest access authentication method for View Composer.
- Persona Management supports guest operating systems that use the "v6" version of the user profile.
- You can use the migration tool to migrate the "v2" and "v5" user profiles versions to the "v6" user profile version. The tool is installed with the Persona binary file.
View GPO Bundle
The following Horizon Agent group policy settings have been added:
- The VMwareViewAgentCIT policy setting enables remote connections to Internet Explorer to use the Client's IP address instead of the IP address of the remote desktop machine.
- The FlashMMRUrlListEnableType and FlashMMRUrlList policy settings specify and control the white list or black list that enables or disables the list of URLs from using Flash Redirection.
For information about new features in Horizon Client 4.3, including resolved and known issues, see the Horizon Clients Documentation page.
Before You Begin
- Important note about installing VMware View Composer
If you plan to install or upgrade to View Composer 7.0.3, you must upgrade the Microsoft .NET framework to version 4.6.1. Otherwise, the installation will fail.
- Important note about installing VMware Tools
If you plan to install a version of VMware Tools downloaded from VMware Product Downloads, rather than the default version provided with vSphere, make sure that the VMware Tools version is supported. To determine which VMware Tools versions are supported, go to the VMware Product Interoperability Matrix, select the solution VMware Horizon View and the version, then select VMware Tools (downloadable only).
- If you want to install Horizon Composer silently, see the VMware Knowledge Base (KB) article 2148204, Microsoft Windows Installer Command-Line Options for Horizon Composer.
- The Horizon 7 release includes new configuration requirements that differ from some earlier releases. See the View Upgrades document for upgrade instructions.
- If you intend to upgrade a pre-6.2 installation of View, and the Connection Server, security server, or View Composer server uses the self-signed certificate that was installed by default, you must remove the existing self-signed certificate before you perform the upgrade. Connections might not work if the existing self-signed certificates remain in place. During an upgrade, the installer does not replace any existing certificate. Removing the old self-signed certificate ensures that a new certificate is installed. The self-signed certificate in this release has a longer RSA key (2048 bits instead of 1024) and a stronger signature (SHA-256 with RSA instead of SHA-1 with RSA) than in pre-6.2 releases. Note that self-signed certificates are insecure and should be replaced by CA-signed certificates as soon as possible, and that SHA-1 certificates are no longer considered secure and should be replaced by SHA-2 certificates.
Do not remove CA-signed certificates that were installed for production use, as recommended by VMware. CA-signed certificates will continue to work after you upgrade to this release.
- To take advantage of Horizon 7 features such as Virtual SAN 6.1, GRID vGPU, and Virtual Volumes, install vSphere 6.0 and subsequent patch releases.
When you upgrade to this release, upgrade all Connection Server instances in a pod before you begin upgrading View Agent, as described in the View Upgrades document.
- The download page in this release includes a Horizon View HTML Access Direct-Connection file that provides web server static content for supporting HTML Access with View Agent Direct-Connection (VADC). For information about setting up HTML Access for VADC, see Setting Up HTML Access in the View Agent Direct-Connection Plug-in Administration document.
Selecting the Scanner Redirection setup option with Horizon Agent installation can significantly affect the host consolidation ratio. To ensure the optimal host consolidation, make sure that the Scanner Redirection setup option is only selected for those users who need it. (By default, the Scanner Redirection option is not selected when you install Horizon Agent.) For the particular users who need the Scanner Redirection feature, configure a separate desktop pool and select the setup option only in that pool.
Horizon 7 uses only TLSv1.1 and TLSv1.2. In FIPS mode, it uses only TLSv1.2. You might not be able to connect to vSphere unless you apply vSphere patches. For information about re-enabling TLSv1.0, see Enable TLSv1 on vCenter Connections from Connection Server and Enable TLSv1 on vCenter and ESXi Connections from View Composer in the View Upgrade document.
FIPS mode is not supported on releases earlier than 6.2. If you enable FIPS mode in Windows and upgrade Horizon Composer or Horizon Agent from a release earlier than 6.2 to 7.0.3, the FIPS mode option is not shown. You must do a fresh install instead to install Horizon 7.0.3 in FIPS mode.
- Linux desktops use port 22443 for the VMware Blast display protocol.
Top of Page
The Horizon Administrator user interface, Horizon Administrator online help, and Horizon 7 product documentation are available in Japanese, French, German, Spanish, simplified Chinese, traditional Chinese, and Korean. For the documentation, see the Documentation Center for VMware Horizon 7.
Top of Page
- For the supported guest operating systems for Horizon Agent on single-user machines and RDS hosts, see Supported Operating Systems for Horizon Agent in the View Installation document.
- If you use Horizon 7 servers with a version of View Agent older than 6.2, you will need to enable TLSv1.0 for PCoIP connections. View Agent versions that are older than 6.2 support the security protocol TLSv1.0 only for PCoIP. Horizon 7 servers, including connection servers and security servers, have TLSv1.0 disabled by default. You can enable TLSv1.0 for PCoIP connections on these servers by following the instructions in VMware Knowledge Base (KB) article 2130798, Configure security protocols for PCoIP for Horizon 6 version 6.2 and later, and Horizon
Client 3.5 and later.
- For the supported Linux guest operating systems for Horizon Agent, see System Requirements for Horizon 7 for Linux in the Setting Up Horizon 7 for Linux Desktops document.
- For the supported operating systems for Connection Server, security server, and View Composer, see System Requirements for Server Components in the View Installation document.
- Horizon 7 functionality is enhanced by an updated set of Horizon Clients provided with this release. For example, Horizon Client 4.0 or later is required for VMware Blast connections. See the VMware Horizon Clients Documentation page for information about supported Horizon Clients.
- The instant clones feature requires vSphere 6.0 Update 1 or later.
- Windows 7 and Windows 10 are supported for instant clones, but not Windows 8 or Windows 8.1.
- See the VMware Product Interoperability Matrix for information about the compatibility of Horizon 7 with current and previous versions of vSphere.
- For the supported Active Directory Domain Services (AD DS) domain functional levels, see Preparing Active Directory in the View Installation document.
- For more system requirements, such as the supported browsers for Horizon Administrator, see the View Installation document.
- RC4, SSLv3, and TLSv1.0 are disabled by default in View components, in accordance with RFC 7465, "Prohibiting RC4 Cipher Suites," RFC 7568, "Deprecating Secure Sockets Layer Version 3.0," PCI-DSS 3.1, "Payment Card Industry (PCI) Data Security Standard", and SP800-52r1, "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations." If you need to re-enable RC4, SSLv3, or TLSv1.0 on a Connection Server, security server, View Composer, or Horizon Agent machine, see Older Protocols and Ciphers Disabled in View in the View Security document.
If a PCoIP Secure Gateway (PSG) has been deployed for PCoIP connections, zero client firmware must be version 4.0 or later.
- When using Client Drive Redirection (CDR), deploy Horizon Client 3.5 or later and View Agent 6.2 or later to ensure that CDR data is sent over an encrypted virtual channel from an external client device to the PCoIP security server and from the security server to the remote desktop. If you deploy earlier versions of Horizon Client or View Agent, external connections to the PCoIP security server are encrypted, but within the corporate network, the data is sent from the security server to the remote desktop without encryption. You can disable CDR by configuring a Microsoft Remote Desktop Services group policy setting in Active Directory. For details, see Managing Access to Client Drive Redirection in the Setting Up Desktop and Application Pools in View document.
- The USB Redirection setup option in the Horizon Agent installer is deselected by default. You must select this option to install the USB redirection feature. For guidance on using USB redirection securely, see Deploying USB Devices in a Secure View Environment in the View Security document.
- The Global Policy, Multimedia redirection (MMR), defaults to Deny. To use MMR, you must open Horizon Administrator, edit Global Policies, and explicitly set this value to Allow. To control access to MMR, you can enable or disable the Multimedia redirection (MMR) policy globally or for an individual pool or user.
Multimedia Redirection (MMR) data is sent across the network without application-based encryption and might contain sensitive data, depending on the content being redirected. To ensure that this data cannot be monitored on the network, use MMR only on a secure network.
- Before you set the level of Transparent Page Sharing (TPS) in Horizon Administrator, VMware recommends that the security implications be understood. For guidance, see the VMware Knowledge Base (KB) article 2080735, Security considerations and disallowing inter-Virtual Machine Transparent Page Sharing.
To use View Storage Accelerator in a vSphere 5.5 or later environment, a desktop virtual machine must be 512GB or smaller. View Storage Accelerator is disabled on virtual machines that are larger than 512GB. Virtual machine size is defined by the total VMDK capacity. For example, one VMDK file might be 512GB or a set of VMDK files might total 512GB. This requirement also applies to virtual machines that were created in an earlier vSphere release and upgraded to vSphere 5.5.
Horizon 7 does not support vSphere Flash Read Cache (formerly known as vFlash).
In Horizon (with View) version 6.0 and later releases, the View PowerCLI cmdlets Get-TerminalServer, Add-TerminalServerPool, and Update-TerminalServerPool have been deprecated.
- Screen DMA is disabled by default in virtual machines that are created in vSphere 6.0 and later. View requires screen DMA to be enabled. If screen DMA is disabled, users see a black screen when they connect to the remote desktop. When Horizon 7 provisions a desktop pool, it automatically enables screen DMA for all vCenter Server-managed virtual machines in the pool. However, if Horizon Agent is installed in a virtual machine in unmanaged mode (VDM_VC_MANAGED_AGENT=0), screen DMA is not enabled. For information about manually enabling screen DMA, see VMware Knowledge Base (KB) article 2144475, Manually enabling screen DMA in a virtual machine.
- Kiosk mode clients are now supported in a Cloud Pod Architecture environment if you implement a workaround. For instructions, see
VMware Knowledge Base (KB) article 2148888, Using kiosk mode clients in a Cloud Pod Architecture environment.
Supported Windows 10 Operating Systems
Horizon 7 version 7.0.3 supports the following Windows 10 operating systems:
- Windows 10 version 1507 (RTM) Long-Term Servicing Branch (LTSB)
- Windows 10 version 1511 Current Business Branch (CBB)
- Windows 10 version 1607 Long-Term Servicing Branch (LTSB)
- Windows 10 version 1607 Current Branch (CB) as a tech preview feature.
For more information on upgrade requirements for Windows 10 operating systems, see VMware Knowledge Base (KB) article 2148176, Upgrade Requirements for Windows 10 Operating Systems.
Note: Microsoft treats the Current Branch as a development pilot branch and can issue periodic updates to this branch.
Top of Page
Prior Releases of View
Features that were introduced in prior releases of View are described in the release notes for each release, along with existing known issues.
When the current user is logged in, the Horizon Client on a Windows 8.1 operating system takes 15 seconds to connect to the Connection Server instance.
A remote desktop fails in rare cases because the PCoIP server has an incorrect IPv6 address for an IPv4 environment when the virtual machine is configured for both the IPv6 and IPv4 environments but uses only the IPv4 environment.
When you use the Cloud Pod Architecture feature to access a desktop from another pod, the value of the Security Gateway field does not get populated in the Desktop Pool, Session, and Users and Groups tabs.
View Persona Management does not support any guest operating system that uses the "v6" version of the user profile.
Horizon Agent ignores the value for the maximum frame rate registry setting.
- Horizon Administrator performance decreases when you browse or import user data disks from the vCenter server to the Horizon Connection Server.
On rare occasions, initializing Cloud Pod Architecture on any Connection Server instance in a pod federation fails and Horizon Administrator displays the error "no Global instance can be found".
There is no alphabetic or any other type of order for the OU and CN structures when you create linked-clone desktop pools in Horizon Administrator.
In the Horizon 7 environment, each client has to wait for two minutes to connect to the desktop, which is in a suspended state.
When you deploy a large number of instant-clone desktop pools, some virtual machines fail because of domain trust errors.
You cannnot view and select vGPU enabled virtual machines while creating a desktop pool with the NVIDIA GRID option selected in the 3D Renderer setting.
The known issues are grouped as follows:
Installation, Upgrade, and Uninstall Operations
The USB HUB device driver might not be installed properly when you install Horizon Agent on a desktop in a manual desktop pool. This issue can occur if, during the Horizon Agent installation, you restart the system before the USB HUB device driver is fully installed.
Workaround: When you install Horizon Agent and you are prompted to restart the system, check the system tray to see if the USB HUB device driver software is still being installed. Wait until the device driver software is completely installed (typically about 30 seconds) before you restart the system.
If you use a command-line script to install Horizon Agent silently, make sure to wait or sleep the script for long enough to allow the driver installation to complete before you restart the system.
If you encounter this issue after Horizon Agent is installed, or you could not delay the system restart during a silent installation, update the USB HUB device driver by taking these steps:
1. In the Device Manager, under Other Devices, right-click VMware View Virtual USB Hub.
2. Click Update Driver Software > Browse my computer for driver software.
3. Go to C:\Program Files\VMware\VMware View\Agent\bin\drivers and click Next to let Windows install the driver.
To upgrade a desktop from Windows 8 to Windows 8.1, you must uninstall Horizon Agent, upgrade the operating system from Windows 8 to Windows 8.1, and then reinstall Horizon Agent. Alternatively, you can perform a fresh installation of Windows 8.1 and then install Horizon Agent.
If you upgrade to vSphere 5.5 or a later release, verify that the domain administrator account that you use as the vCenter Server user was explicitly assigned permissions to log in to vCenter Server by a vCenter Server local user.
USB redirection fails in linked-clone images after you upgrade the master image from View Agent 5.1.x or earlier to the current Horizon Agent version. This issue does not occur if you upgrade from View Agent 5.2 or later to the current version.
Workaround: See VMware Knowledge Base (KB) article 2062215, USB redirection fails in linked-clone images after you upgrade to View Agent 5.3.
When you run the View Agent installer on a Windows 8 virtual machine, the Windows desktop appears black when the video driver is being installed. The Windows desktop might appear black for several minutes before the installation completes successfully.
Workaround: Apply the Windows 8.0 May 2013 roll-up before you install View Agent. See Microsoft KB article 2836988.
When you run any Horizon 7 installer on a Windows 8.1 or Windows Server 2012/2012 R2 virtual machine (deployed as an RDS host or virtual desktop), the installer can take an unusual amount of time to finish. This problem occurs if the virtual machine's domain controller, or another domain controller in its hierarchy, is unresponsive or unreachable.
Workaround: Verify that the domain controllers have the latest patches, enough free disk space, and can communicate with each other.
When you uninstall Horizon Agent from an RDS host, an error dialog can be displayed, which prevents the uninstall operation from being completed. The dialog states that the uninstall operation failed to stop an RDS video driver. This issue can occur when disconnected desktop sessions are still running on the RDS host.
Workaround: Reboot the RDS host to complete the uninstallation of Horizon Agent. As a best practice, ensure that all RDS sessions are logged off before you uninstall Horizon Agent.
In FIPS mode, Horizon Agent fails to pair with Connection Server and the pool status is not available when Horizon Agent is installed to a drive other than the C drive.
Workaround: When operating in the FIPS mode, install Horizon Agent on the C drive.
A warning message that states applications are in use appears when you uninstall the Horizon 7.0.2 Agent from a Windows 2016 operating system.
Workaround: Click Ignore on the message dialog box to proceed with the uninstallation.
A file in use pop up message appears during Horizon Agent upgrade from version 6.2.3 to version 7.0.3.
Workaround: Click Ignore on the pop up message dialog box and proceed with the ugrade or, use the Microsoft command line to perform a silent upgrade.
During provisioning of an instant-clone desktop pool, if there is not enough space available on the datastores, the error message that is displayed in Horizon Administrator is "Cloning of VM <VM name> has failed - VC_FAULT_FATAL: Failed to extend swap file from 0 KB to 2097152 KB." This message does not clearly indicate the root cause of the problem.
Workaround: Not required.
In Horizon Administrator, if you go to Catalog > Desktop Pools, double-click an instant-clone desktop pool, go to the Inventory tab and click Machines (InstantClone Details), the window displays details of the instant clones. However, the OS Disk datastore column displays no information.
RDS Desktops and Applications
For this release, Windows Universal apps are not supported as hosted remote applications. For example, Universal apps do not appear in the list of apps provided by a Windows Server 2016 RDS farm. Universal apps,
such as the Edge browser or the Calculator included with Windows 10 or a Windows Server 2016 RDS host, are built on the Universal Windows Platform (UWP). Universal apps require Windows Explorer to be run.
In addition, manually launching Universal apps through the Command Prompt will show an error message.
If you deploy an automated farm from a Windows Server 2012 parent virtual machine that has the RDS role enabled, Sysprep customization will fail on the deployed linked-clone virtual machines. This 3rd-party issue does not occur on other Windows Server versions that have the RDS role enabled.
Workaround: On the Windows Server 2012 parent virtual machine, apply the Microsoft hotfix available at https://support.microsoft.com/en-us/kb/3020396.
When multiple connections are made consecutively to a single RDS host, a few users (for example, one or two of 120 users) might not be able to start or restart RDS desktop sessions.
Workaround: Increase the number of vCPUs and the RAM size on the RDS host.
The first connection to an RDS desktop or application fails if it has been more than 120 days since the RDS role was configured on the RDS host, and no previous connection was made. This issue also occurs with RDP.
Workaround: Wait a few seconds and connect to the RDS desktop or application again.
Persistent settings for location-based printers are not supported if the settings are saved in the printer driver's private space and not in the DEVMODE extended part of the printer driver, as recommended by Microsoft.
Workaround: Use printers that have the user preference settings saved in the DEVMODE part of the printer driver.
Horizon Agent cannot install the virtual printing feature on RDS hosts that are physical machines. Virtual printing is supported on RDS desktops when Horizon Agent is installed on RDS hosts that are virtual machines.
Workaround: Configure RDS hosts on virtual machines and install Horizon Agent.
In a desktop session running on a Windows Server 2008 R2 SP1 RDS host, you cannot play back an H.264 video file, or play back AAC audio with a video file, in Windows Media Player. This is a known third-party issue.
Workaround: Go to the Microsoft KB article 2483177 and download the Desktop Experience Decoder Update for Windows Server 2008 R2 package.
When you play a YouTube video in a Chrome browser in a desktop session running on a Windows Server 2012 R2 RDS host, the video display can be corrupted. For example, black boxes might pop up in the browser window. This issue does not occur on any other browser or on Windows Server 2008 R2 SP1 RDS hosts.
Workaround: In your Chrome browser, select Chrome > Settings > Show advanced settings > System, and deselect Use hardware acceleration when available.
If you play a video in a desktop running on a Windows 2008 R2 SP1 physical RDS host, and you move the video display from the main monitor to another monitor, the video stops playing or the visual frames stop updating (although the audio might continue to play). This issue does not occur on a virtual machine RDS host or in a single monitor configuration, and it only occurs on Windows Server 2008 R2 SP1.
Workaround: Play videos on the main monitor only, or configure your RDS desktop pool on a virtual machine RDS host.
If you launch a remote application that becomes unresponsive and then launch another application, the second application's icon is not added to the taskbar on the client device.
Workaround: Wait for the first application to become responsive. (For example, an application might be unresponsive while large files are being loaded.) If the first application continues to be unresponsive, terminate the application process on the RDS virtual machine.
The application Lync 2013 that does not have the February, 2013 update and is hosted on an RDS host running Windows Server 2012 R2 will crash shortly after launch with the error message "Microsoft Lync has stopped working." This is a known issue with Lync 2013.
Workaround: Apply the February, 2013 update of Lync. The update is available at Microsoft KB article 2812461.
For RDS host farms that are created with VMware Blast display protocol support, enabling the UDP network protocol for VMware Blast sessions reduces Blast Secure Gateway scale and sessions might fall back to the TCP network protocol.
Workaround: Do not enable the UDP network protocol for VMware Blast sessions on RDS hosts.
During a Horizon Agent upgrade on an RDS Host from Horizon 7 version 7.0.2 to Horizon 7 version 7.0.3, the Real Time Audio-Video component is deselected even though Horizon Agent 7.0.2 has this component for an IPv6 environment.
Workaround: Manually select the Real Time Audio-Video component during the upgrade.
Configuration and Horizon Administrator
For True SSO, the connectivity status between the connection server and the enrollment server is displayed only on the System Health Status dashboard for the connection server that you are using to access Horizon
Administrator. For example, if you are using https://server1.example.com/admin for Horizon Administrator, the connectivity status to the enrollment server is collected only for the
server1.example.com connection server. You might see one or both of the following messages:
It is mandatory to configure one enrollment server as primary. Configuring a secondary enrollment server is optional. If you have only one enrollment server you will see only the first message (on error).
If you have both a primary and a secondary enrollment server and both have connectivity issues, you will see both messages.
- The primary enrollment server cannot be contacted to manage sessions on this connection server.
- The secondary enrollment server cannot be contacted to manage sessions on this connection server.
- When you setup True SSO in an environment with CAs and SubCAs with different templates setup on each of them, you are allowed to configure True SSO with a combination of template from a CA or SubCA with another CA or SubCA. As a result, the dashboard might display the status of True SSO as green. However, it fails when you try to use True SSO.
When using Horizon Administrator from a Firefox browser, if you enter Korean characters in a text field using the Korean Input Method Editor (IME), the Korean characters are not displayed correctly. This issue occurs only with Firefox. This is a 3rd-party issue.
Workaround: Use a different browser. If you still want to use Firefox, input Korean characters one by one.
If you change the Blast Secure Gateway (absg.log) log level on a Connection Server instance from Info to Debug, the log level remains Info. (You change the log level by opening the Set View Connection Server Log Levels on a Connection Server instance, changing the absg log level, and restarting the VMware View Blast Secure Gateway service.) Changing the log level from Debug to Info works properly.
The View PCoIP ADM (pcoip.adm) group policy setting, Configure SSL connections to satisfy Security Tools, is not supported in this release of View. If you attempt to implement certain options in this group policy setting, unexpected results might occur in your Horizon 7 deployment.
Workaround: Do not use this setting in this release of Horizon 7.
Setting the size of the retry port range to 0 when configuring the Configure the TCP port to which PCoIP Server binds and listens or Configure the UDP port to which PCoIP Server binds and listens group policy causes a connection failure when users log in to the desktop with the PCoIP display protocol. Horizon Client returns the error message The Display protocol for this desktop is currently not available. Please contact your system administrator. The help text for the group policies incorrectly states that the port range is 0 through 10.
Note: On RDS hosts, the default base TCP and UDP port is 4173. When PCoIP is used with RDS hosts, a separate PCoIP port is used for each user connection. The default port range that is set by the Remote Desktop Service is large enough to accommodate the expected maximum of concurrent user connections.
- PCoIP on single-user machines: Set the retry port range to a value between 1 and 10. (The correct port range is 1 through 10.)
- PCoIP on RDS hosts: As a best practice, do not use these policy settings to change the default port range on RDS hosts, or change the TCP or UDP port value from the default of 4173. Most important, do not set the TCP or UDP port value to 4172. Resetting this value to 4172 will adversely affect PCoIP performance in RDS sessions.
On rare occasions, the system health status of Event Database may be displayed as red on the Horizon Administrator dashboard, with the error message "Cannot drop the view 'VE_user_events', because it does not exist or you do not have permission." This condition does not indicate a real error and will resolve itself after a short period of time.
Horizon Administrator incorrectly shows Windows Server 10 as the RDS host for a Windows Server 2016 RDS host.
Workaround: This problem occurs because the value of the operating system registered in the Horizon Connection Server LDAP is 11, which is the value for Windows Server 10. To enable Horizon Administrator to display the correct version of the RDS host, set pae-OSVersion = 12 in the
Horizon Connection Server ADAM database using ADAM ADSI Edit. For more information, see the VMware Knowledge Base article 2146850 Setting the RDS Host Operating System Version.
Horizon Client and Remote Desktop Experience
- Horizon Client cannot connect to Connection Server instance if the server name or fully qualified domain name (FQDN) for the Connection Server instance contains non-ASCII characters.
On remote desktops that connect using PCoIP and are configured with multiple monitors, if a user plays a slide show in Microsoft PowerPoint 2010 or 2007, specifies a resolution, and plays the slides on the second monitor, part of each slide appears on each monitor.
Workaround: On the host client system, resize the screen resolution on the second monitor to the desired resolution. Return to the remote desktop and start the slide show on the second monitor.
On remote desktops that connect using PCoIP, if users play slides in Microsoft PowerPoint 2010 or 2007 and specify a resolution, the slides are played at that chosen resolution and are not scaled to the current resolution.
Workaround: Choose "Use current resolution" as the playback resolution.
The virtual printing feature is supported only when you install it from Horizon Agent. It is not supported if you install it with VMware Tools.
When you play videos in Windows Media Player on a desktop, PCoIP disconnections might occur under certain circumstances.
Workaround: On the remote desktop, open the Windows registry and navigate to the HKLM\Software\Wow6432Node\Policies\Teradici\PCoIP\pcoip_admin_defaults registry key for 64-bit Windows or the
HKLM\Software\Policies\Teradici\PCoIP\pcoip_admin_defaults registry key for 32-bit Windows. Add the pcoip.enable_tera2800 DWORD registry value and set the value to 1.
For Windows 2008 R2 SP1 desktop pools hosted on an RDS host, the language sync setting (from client to guest) is turned on by default and cannot be turned off. Therefore, disabling the group policy "Turn on PCoIP user default input language synchronization" for Horizon Agent has no effect. The remote desktop language always synchronizes with the language used on the client system.
Copying and pasting an image from a remote desktop to the client system, or from the client system to a remote desktop, can fail because the clipboard memory size is not large enough to accommodate the image, even though the configured clipboard memory size is greater than or the same as the size of the image on disk. This problem occurs because the image size on disk is less than the image size in clipboard memory. For example, the size of the image in the clipboard memory can be two to three times size of the image on disk.
Workaround: Increase the clipboard memory size until it can accommodate the image.
Using the VMware Blast protocol and with Blast Secure Gateway (BSG) disabled, Horizon Client sometimes cannot recover from a brief (about 1 minute) network outage and the connection to the desktop is disconnected. This issue does not occur when BSG is enabled.
Workaround: Reconnect the session.
After a brief network outage and the VMware Blast session between Horizon Client and a remote desktop has recovered or has been reconnected, certain features might stop working, such as:
Workaround: Disconnect and reconnect the session.
- Smart card
- Client Drive Redirection (CDR) and File Association
- Multimedia Redirection (MMR)
Sometimes, when using Lync VDI to make a video call, the local image is not displayed.
Workaround: Update Microsoft Lync VDI to the latest version.
If a user connects to an F5 server to access a remote desktop, and the F5 server is configured to use an RSA server, the user must input an RSA username and passcode. If the RSA user's PIN is not set, Horizon Client might fail to submit the passcode for the user. This problem is an F5 limitation.
Workaround: Users must contact their RSA administrator to set their PINs before using their PINs in an F5 and RSA setup.
Data transfer is slow when copying and pasting text and images between Horizon Client and a remote desktop.
Reduce the effective clipboard size so that less data is transferred at one time.
Horizon 7 for Linux Desktops
When you configure a virtual desktop for multi-monitor support with a maximum 2560x1600 screen resolution, the submenu dialogs do not open.
- If you configure two monitors with different resolutions, and the resolution of the primary screen is lower than that of the secondary screen, you might not be able to move the mouse or drag application windows to certain areas of the screen.
Workaround: Make sure that the primary monitor's resolution is at least as large as the secondary monitor's.
Configuring four monitors at 2560x1600 resolution on RHEL 6.6 or CentOS 6.6 virtual machines in vSphere 6.0 is not supported.
Workaround: Use 2048x1536 resolution or deploy this configuration in vSphere 5.5.
If you configure two or more monitors at 2560x1600 resolution on RHEL 6.6 virtual machines in a vDGA environment, desktop performance is poor. For example, application windows do not move smoothly. This issue occurs when RHEL Desktop Effects are enabled.
Workaround: Disable Desktop Effects by going to System > Preference > Desktop Effects and selecting Standard.
- Unicode keyboard input does not work correctly with HTML Access in Horizon 7 for Linux Desktops.
When you connect to a Linux desktop, some keyboard inputs do not work. For example, if you are using a non-English IME on both the client device and the remote desktop, some non-English keys are not displayed correctly.
Workaround: Set the English IME on the client device and set the non-English IME on the remote desktop.
Flash Media MMR
If you switch browser tabs while playing a redirected video in Internet Explorer, part of the video window continues to be displayed behind or next to the browser window. This issue only occurs on Windows 7 desktops.
Workaround: Use Windows 8.1 desktops. Alternatively, do not switch to another tab while a redirected video is playing.
An action script error occurs when you play a YouTube Flash video on a remote desktop that has Flash MMR enabled.
- Option 1. Open the script support for the YouTube Web site and add appMode=1 with the URL of the YouTube site to the UrlWhiteList.
- Option 2. Open Internet Explorer > Tools > Internet Options > General. Under “Browsing history” click the “Settings” button. In the next window, click the “View files” button. Delete all files from the INetCache folder.
3D Graphics Acceleration
For Intel vDGA, only the Haswell and Broadwell series of Intel integrated GPUs are supported. Broadwell integrated GPUs are supported only on vSphere 6 Update 1b and later. Haswell integrated GPUs are supported on
vSphere 5.5 and later. Also note that the GPU needs to be enabled in the BIOS before it can be recognized by ESXi. For more information, see the documentation for your specific ESXi host.
Intel recommends leaving the graphics memory settings in the BIOS set to their default values. If you choose to change the settings, keep the aperture setting at its default (256M).
For Intel vDGA, multiple-monitor support is limited to no more than 3 monitors. The Intel driver supports only up to 3 monitors with a resolution of up to 3840 X 2160. If you try to connect with 4 monitors, the
connection shows 3 black screens with just one screen working.
When 4K monitors are configured on machines where 3D Rendering and vSGA are enabled, moving, resizing, or toggling the Windows Media Player window to full screen mode can be very slow. This issue does not occur with 2D, software 3D Rendering, or monitors with 2560x1440 resolution.
If NVIDIA drivers are installed on a virtual machine that you use as a parent or template to deploy a desktop pool, and the machines are deployed on non-NVIDIA GRID hardware on the ESXi hosts, users might not be able to start desktop sessions correctly. This issue might occur if the virtual machine was used previously in an NVIDIA GRID vGPU deployment.
Workaround: Remove the NVIDIA drivers from the virtual machine before you take a snapshot or make a template and deploy the desktop pool.
If vDGA is enabled on a Windows 7 virtual machine that is configured to use NVIDIA driver version 347.25, the desktop session can be disconnected. This issue does not occur on Windows 8.1 or on other NVIDIA driver versions.
Workaround: Do not use NVIDIA driver version 347.25.
On Windows 8/8.1 desktops, 3D screen savers operate even when the 3D Renderer setting is disabled, and the screen savers do not render correctly. This issue does not occur on Windows 7 desktops.
Workaround: Make sure your end users do not use 3D screen savers, or enable the 3D Renderer setting for the desktop pool.
With NVIDIA M60 GPU and driver version 361.89 or 361.94, users might see a blurred screen when they first connect to the Windows desktop, or when they right click on the desktop and then select NVIDIA Control Panel > System Information.
Workaround: Changing the resolution of the display or changing to full-screen mode fixes the problem and you can revert back to the original resolution or screen mode. The problem disappears after the first time it occurs. Also, the problem does not occur with NVIDIA driver 361.51.
Using a smart card to log in to an RDS desktop takes longer than with a VDI, single-user desktop. This issue is less acute on Windows clients than other clients.
On Windows 7 client machines, Horizon Client exits when the smart card removal policy is triggered.
When you use a proxy server for the connection between the client and Connection Server, the smart card user name hints feature does not work and always uses the default account that is mapped to the certificate for authentication.
- Option 1: Disable the proxy server for HTTPS when Horizon Client is connecting to Connection Sever 7.0.3.
- Option 2: Set up Access Point 2.7.2 with Connection Server 7.0.3. Horizon Client connects to the Access Point server with the smart card user name hint.
Microsoft Windows Fax and Scan does not work with Scanner Redirection on Windows 10 desktops.
Workaround: Use another scan application on Windows 10 desktops or change to another desktop platform.
Selecting the Scanner Redirection setup option with View Agent installation can significantly affect the host consolidation ratio. By default, the Scanner Redirection option is not selected when you install View Agent.
Workaround: Make sure that the Scanner Redirection setup option is not selected for most users. For the particular users who need the Scanner Redirection feature, configure a separate desktop pool and select the setup option only in that pool.
Sometimes the scanner settings do not take effect on WIA scanners. For example, if you select grayscale mode and select a partial area of the original image, the scanner might use color and scan the whole image.
Workaround: Use a TWAIN scanner.
In some environments, if you switch to a different WIA scanner, the images might continue to be scanned from the original scanner.
Workaround: Log off the View desktop session. Launch a new desktop session and perform the scan using the selected scanner.
When you uninstall View Agent with the Scanner Redirection feature installed, the uninstall process requires you to close any running applications.
Workaround: None. You must close the listed applications before you continue to uninstall View Agent.
When you use the Ambir ImageScan Pro 490i to perform a scan on a remote desktop or application, the dialog box always displays “Scanning…” and does not complete.
Workaround: Perform a scan on the client. The client scan calibrates the scanner. After the calibrate operation is finished, run the scan within the remote desktop or application.
Serial Port Redirection
The Bandwidth limit group policy setting does not take effect. The value you enter in the setting is ignored, and the existing bandwidth is used for serial port redirection. The bandwidth consumption depends on the number of concurrently used serial port devices and the baud rate used by each device.
When you use the TOPAZ signature pad for multiple remote desktop sessions on Windows 2012 remote desktops, you might get only one device for a session that is redirected successfully. This problem can occur because the TOPAZ signature pads have the same serial number.
Workaround: Use TOPAZ signature pad devices with different serial numbers. You can use the serial number modifier software provided by the TOPAZ manufacturer to modify the serial numbers.
Persona Management might not correctly replicate a user persona to the central repository if the desktop virtual machine is extremely low on disk space.
- With Persona Management, you can use group policy settings to redirect user profile folders to a network share. When a folder is redirected, all data is stored directly on the network share during the user session. Windows folder redirection has a check box called Grant user exclusive rights to folder-name, which gives the specified user exclusive rights to the redirected folder. As a security measure, this check box is selected by default. When this check box is selected, administrators do not have access to the redirected folder. If an administrator attempts to force change the access rights for a user's redirected folder, Persona Management no longer works for that user.
Workaround: See VMware Knowledge Base (KB) article 2058932, Granting domain administrators access to redirected folders for View Persona Management.
Persona Management is not supported on session-based desktop pools that run on RDS hosts.
Workaround: Install Persona Management in automated or manual desktop pools that run on single-user machines.
After every login, Persona Management take a long time to replicate the first user persona on a guest operating system that uses the "v6" version of the user profile.
vSphere Platform Support
View Storage Accelerator might take tens of minutes to generate or regenerate the digest files for large virtual disks (for example, a 100GB virtual disk). As a result, the desktop might be inaccessible for longer than expected.
Workaround: Use the blackout period to control when digest regeneration operations are allowed. Also, use the digest regeneration interval to reduce the frequency of these operations. Alternatively, disable View Storage Accelerator in desktop pools that contain very large virtual machines.
If a linked-clone pool consists of vSphere 5.5 virtual machines, a View Composer rebalance operation can fail with a FileAlreadyExists error. This problem occurs only when the desktop pool uses different datastores for the OS disk and the user data disk and the datastore selection for the user data disk changes before the View Composer rebalance operation takes place.
Workaround: Detach the persistent disk from the linked clone desktop that has the FileAlreadyExists error. Later, you can attach the archived disk to a new virtual machine and recreate the linked-clone desktop or attach it to an existing linked-clone desktop as a secondary disk. You can prevent this problem from occurring by either keeping the OS disk and user data disk on the same datastore or by not changing the datastore selections before a View Composer rebalance operation.
After you upgrade to vSphere 5.5, a heap size error can occur if you use space-efficient virtual disks and you have more than 200 linked-clone virtual machines per ESXi host. For example: Error: Heap seSparse could not be grown by 12288 bytes for allocation of 12288 bytes
Workaround: Reduce the number of linked-clone virtual machines that use space-efficient virtual disks to less than 200 per ESXi host.
When Horizon Administrator provisions a linked-clone pool with thousands of desktops, a few machines (one or two per thousand) might fail with a "Customization timed out" error. If automatic recovery is enabled (the recommended setting for production environments), machines in error are automatically recreated and provisioned. No workaround is required.
Workaround: If automatic recovery is disabled, manually delete the machines in error in Horizon Administrator. Horizon Administrator will provision new machines as part of normal pool management.
When deleting a large desktop pool, a number of folders containing an .hlog file and an empty subfolder named .sdd.sf might remain undeleted.
Workaround: Manually delete the folders that are left behind after a deletion operation. For instructions, see the Solution in VMware Knowledge Base (KB) article 2108928, Rebalance operation leaves VM folders in previous datastores.
If you upgrade a virtual machine with an IDE controller from Windows XP to Windows 7, take a snapshot of the virtual machine, and create a linked-clone pool, the linked clones cannot be customized, and pool creation fails.
Workaround: Add a SCSI controller and a disk to the virtual machine. Next, launch VMware Tools and install a VMware SCSI controller driver on the virtual machine. Next, take a snapshot and create the linked-clone pool.
When you provision linked-clone desktops that are customized by Sysprep, some desktops might fail to customize.
Workaround: Refresh the desktops. If a small number of desktops still fail to customize, refresh them again.
Do not change the log on account for the VMware View Composer Guest Agent Server service in a parent virtual machine. By default, this is the Local System account. If you change this account, the linked clones created from the parent do not start.
Desktop pool provisioning fails with the error message Polling progress failure: Unable to connect to View Composer server <https://machine-name:18443>: java.net.ConnectException: Connection refused: connect.
Workaround: Restart the VMware vCenter Server service and then reprovision the desktop pool.
Windows 10 Support
Windows Media Player is not active and cannot be made visible when the Windows 10 remote desktop display is resized to one monitor and Windows Media Player is open on another monitor. This problem occurs regardless of whether the video is playing or not and whether MMR is enabled or not.
Workaround: Close and reopen Windows Media Player or resize the remote desktop to multi-monitor display.
Creating or recomposing desktop pools fails after you upgrade the parent virtual machine from build 1511 to build 1607 of the Windows 10 operating system. Build 1607 is the Windows 10 Anniversary Update operating system.
- Option 1. Perform a fresh installation of Windows 10 Build 1607 on the parent virtual machine.
- Option 2. Do not select "Redirect disposable files" in the desktop pool creation wizard.
If you install the Horizon Agent on a Windows 10 or Windows Server 2016 operating system, and the scaling is not set to 100%, you cannot drag and drop applications from the primary monitor in a multi-monitor setup to another monitor. This issue can occur because of incorrect cursor input.
Workaround: Set the Horizon Agent DPI setting to 100% scaling.
After a recompose, refresh, or rebalance operation with a persistent disk, Windows 10 desktops might fail to start, or become untiled from the Start menu. Windows applications can include applications such as Windows Store, native applications, Edge Browser, and Cortana Search. This issue is caused by a characteristic of Windows 10 applications. This problem affects the following desktop types:
This issue is not seen with floating or dedicated linked-clone Windows 10 version 1607 desktop pools where user profile is redirected to network share with or without Persona Management enabled. If Persona Management is enabled, the user profile is set to roam with VMware Persona GPO settings.
- Linked-clone dedicated desktops with a persistent disk.
- Linked-clone floating desktops with Persona Management enabled that use a persistent disk as a local disk and the Persona Management setting Roam Local Settings Folders enabled.
Windows 8.x Support
On some occasions, when you reconnect to a Windows 8.x desktop session, you might not see the desktop display immediately. A black screen might be displayed for up to 20 seconds.
When a space reclamation operation is run for Windows 8.x linked clone virtual machines, the size of the system disposable disk and user persistent disk might increase to its maximum capacity. This space increase only happens the first time space reclamation is done. For the OS disk, space reclamation works as expected and reclaims the unused space. This issue does not affect View Composer desktops that do not use system disposable disks or user persistent disks.
Workaround: When you configure View Composer desktops on Windows 8 or 8.1 virtual machines and enable space reclamation, do not configure system disposable disks or user persistent disks.
Adobe Flash optimization settings that use high quality and aggressive throttling are not fully enabled when end users use Internet Explorer 10 or Internet Explorer 11 on Windows 8 or Windows 8.1 desktops.
On a Windows 8 desktop, if you enable the Persona Management setting, Remove local persona at logoff, and a user creates a PDF file, logs off of the desktop, and logs back in again, the user cannot open the offline PDF file. The Windows 8 Reader cannot download the offline PDF content.
Workaround: Manually download the file by right-clicking the file and selecting Properties or selecting Open with... Adobe Reader.
When using Internet Explorer 10 or 11 on a Windows 8 or later computer, if you set the browser locale to Traditional Chinese, and you log in to Horizon Administrator, the navigation panel might be displayed in Simplified Chinese.
Workaround: Use an alternate browser to log in to Horizon Administrator.
- If a user of a Windows 8 View desktop logs in using Kerberos authentication, and the desktop is locked, the user account for unlocking the desktop that Windows 8 shows the user by default is the related Windows Active Directory account, not the original account from the Kerberos domain. The user does not see the account he or she logged in with.
This is a Windows 8 issue, not directly a Horizon 7 issue. This issue could, but does not usually, occur in Windows 7.
Workaround: The user must unlock the desktop by selecting "Other user." Windows then shows the correct Kerberos domain and the user can log in using the Kerberos identity.
When provisioning 64- or 32-bit Windows 8 desktops in a vSphere 5.1 environment, the Sysprep customization can fail. The desktops end up in an ERROR state with a Customization timed out error message. This issue occurs when anti-virus software is installed in the parent virtual machine or template. The issue applies to full clone and linked clone desktops. It does not apply to linked clone desktops customized with QuickPrep.
Workaround: Uninstall the anti-virus software on the parent virtual machine or template and recreate the pool.
When recomposing Windows 8.1 desktops, the Sysprep customization can fail with a Customization operation timed out error message. This problem is caused by a Windows 8.1 scheduled maintenance task that recovers disk space by removing unused features.
Workaround: Use the following command to disable the maintenance task immediately after completing Setup: Schtasks.exe /change /disable /tn "\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup"
Windows Server for Desktop Use
You cannot connect to a Windows Server 2008 R2 SP1 desktop, or you encounter a black screen the first time that you use Horizon Client, even though the desktop that you are connecting to is in the Available state.
Workaround: Shut down and power on the Windows Server 2008 R2 SP1 virtual machine. When the desktop is in the Available state, try to connect again. Note: Resetting or restarting the virtual machine does not solve this problem. You must shut down the virtual machine first and then power it back on.
VMware Identity Manager (formerly VMware Workspace Portal) Integration
If you change the default HTTPS port, 443, on a Connection Server instance or security server, and Horizon users try to start their desktops from the Horizon User Portal, the desktops fail to launch. This issue occurs when users attempt to access their desktops via Horizon Workspace with either Horizon Client or HTML Access.
Workaround: Keep the default HTTPS port 443.
When you add a SAML Authenticator in Horizon Administrator, an "Invalid certificate detected" window might be displayed, even when the Metadata URL points to a trusted certificate in the Trusted Root Certificate Authorities folder in the Windows certificate store. This issue can occur when an existing SAML Authenticator with a self-signed certificate was using the same Metadata URL when the trusted certificate was added to the Windows certificate store.
- Remove any trusted certificates for the Metadata URL from the Trusted Root Certificate Authorities folder in the Windows certificate store.
- Remove the SAML Authenticator with the self-signed certificate.
- Add the trusted certificate for the Metadata URL to the Trusted Root Certificate Authorities folder in the Windows certificate store.
- Add the SAML Authenticator again.
Virtual SAN and Virtual Volumes
In a hybrid vSAN environment, about three percent of the virtual machines might not use View Storage Accelerator. These machines will take few seconds longer to start up.
Workaround: Delete and recreate the virtual machines that failed to use View Storage Accelerator.
In this release, View Storage Accelerator is not supported on Virtual Volume datastores.
Provisioning View Composer linked clones fails on some Virtual Volumes storage arrays. The following message is displayed: "Error creating disk Error creating VVol Object. This may be due to insufficient available space on the datastore or the datastore's inability to support the selected provisioning type." View Composer creates a small internal disk in thick-provisioned format, although all other linked clone disks use thin provisioning. This issue occurs if the 3rd-party Virtual Volumes storage array does not support thick-provisioned disks by default.
Workaround: Enable thick provisioning on the storage array to allow Virtual Volumes to create thick-provisioned disks.
When you attach or recreate a View Composer persistent disk stored on a Virtual SAN datastore, the virtual disk's storage policy in vCenter Server is shown as "Out of date." The original storage profile is not preserved.
Workaround: In vSphere Web Client, reapply the storage policy to the virtual disks.
Virtual SAN datastores are only accessible from hosts that belong to the Virtual SAN cluster, and not from hosts that belong to a different cluster. Therefore, rebalance of pools from one Virtual SAN datastore to another Virtual SAN datastore in a different cluster is not supported.
In an environment where a large VDI desktop pool (for example, 2,000 desktops) is created on Virtual Volumes datastores that reside on a NetApp storage system running ONTAP 8.2.x or earlier, a recompose operation may fail for a small number of desktops with the error message "The VVol target encountered a vendor specific error."
Workaround: Upgrade the NetApp storage system to ONTAP 8.3 or later.
Cloud Pod Architecture
Cloud Pod Architecture configuration changes made by another Horizon administrator while you are logged in to Horizon Administrator are not visible in your current Horizon Administrator session.
Workaround: Log out of Horizon Administrator and log in again to see the changes.
The ViewDbChk utility can display an "Archiving persistent disks..." message while removing machines from an automated linked-clone pool with floating assignment or an automated farm.
For virtual machines that have hardware version 8, the maximum allowed video RAM is 128MB. For virtual machines that have hardware version 9 and later, the maximum allowed video RAM is 512MB. If you configure a value from Horizon Administrator that exceeds the video RAM limit for a virtual machine's hardware version, errors appear in the vSphere Client Recent Tasks pane and the configuration operation keeps repeating. This problem occurs only if you configure the video memory value through Horizon Administrator (Pool Settings page) and not through vSphere Client.
Workaround: Either upgrade the hardware version of the virtual machines in vSphere Client, or use Horizon Administrator to set the proper value for video memory based on the current virtual machine hardware version.
When you try to add a SAML authenticator in Horizon Administrator, the Add button is disabled on the Manage SAML Authenticators page.
Workaround: Log in to Horizon Administrator as a user who has the Administrators or Local Administrators role.
Top of Page