ADV1591BU Delivering Virtual Desktops and Apps via the Digital Workspace with Workspace ONE and VMware Horizon VMworld 2017 Content: Not for publication Peter Bjork @thepeb & Matt Coppinger @mcopping #VMworld #ADV1591BU
Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitment from VMware to deliver these features in any generally available product. Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind. Technical feasibility and market demand will affect final delivery. Pricing and packaging for any new technologies or features discussed or presented have not been determined. CONFIDENTIAL 2
Agenda 1 What is Workspace ONE? 2 Setting up Horizon with Workspace ONE 3 User Experience and Demo #ADV1591BU CONFIDENTIAL 3
Agenda 1 What is Workspace ONE? 2 Setting up Horizon with Workspace ONE 3 User Experience and Demo #ADV1591BU CONFIDENTIAL 4
IT/it Used to Be Simple... #ADV1591BU CONFIDENTIAL 5
Bridging Two Worlds Client-Server Era Mobile-Cloud Era #ADV1591BU CONFIDENTIAL 6
Bridging Two Worlds Client-Server Era Domain joined Network based security Managing devices OPEX heavy 1:150 ratio Slow Migration Projects Mobile-Cloud Era #ADV1591BU CONFIDENTIAL 7
Bridging Two Worlds Client-Server Era Domain joined Network based security Managing devices OPEX heavy 1:150 ratio Slow Migration Projects Mobile-Cloud Era Enrollment Identity based security Managing policies Massive scale 1:15 000 ratio Fast Continuous Delivery #ADV1591BU CONFIDENTIAL 8
Applications in the Enterprise Universal Windows Apps #ADV1591BU CONFIDENTIAL 9
Bridging Two Worlds Client-Server Era Mobile-Cloud Era #ADV1591BU CONFIDENTIAL 10
Bridging Two Worlds Client-Server Era Workspace One AirWatch ThinApp Flex Horizon BLAST Unified Access Horizon PCoIP Mirage VMware Identity Gateway App Volumes Manager UEM Horizon Cloud Mobile-Cloud Era #ADV1591BU CONFIDENTIAL 11
VMware Empowers the Digital Workspace You can t transform business without a great user experience VMworld 2017 You don t need to compromise security to get there Content: Not for publication #ADV1591BU CONFIDENTIAL 12
Simple App Delivery through a Unified Catalog Web-based Mobile app Any app to any device #ADV1591BU CONFIDENTIAL 13
Agenda 1 What is Workspace ONE? 2 Setting up Horizon with Workspace ONE 3 User Experience and Demo #ADV1591BU CONFIDENTIAL 14
Horizon Deployment Options ACTIVE DIRECTORY Horizon Cloud with Hosted Infrastructure MOBILE USERS USER APP DATA CLOUD PROVIDER OPEX model of utility based pricing Scalability on demand Minimal internal expertise required Remote locations where building data center capacity is impossible SECURE VPN CUSTOMER IT ENVIRONMENT REMOTE USERS SECURE VPN CORP USER DEVICES Horizon Cloud with On-premises Infrastructure VIRTUAL DESKTOPS & APPS ON HYPER-CONVERGED INFRASTRUCTURE Hybrid OPEX/CAPEX model Management infrastructure in the cloud On-premises virtual desktops & apps on hyper-converged infrastructure Minimal internal expertise required and easily scalable G CLOUD PROVIDER CONTROL PLANE ACCESS POINTS ACTIVE DIRECTORY LOAD BALANCERS CAPEX Model CONNECTION BROKERS CUSTOMER IT ENVIRONMENT On Premises (Horizon 7) Greater flexibility in desktop options Scalable to customer requirements Feature rich management MANAGEMENT SERVERS SANSTORAGE ACTIVE DIRECTORY COMPUTE SERVERS RUNNING VIRTUAL DESKTOPS #ADV1591BU CONFIDENTIAL 15
Simple Access to Apps & Desktops Access to Horizon 7 and Horizon Cloud desktops from Workspace ONE Full support for Horizon 5.x 6.x 7.x Virtual Desktops Published Applications Horizon Cloud Pod Architecture Single Sign On & True SSO Support for Horizon Air / Cloud Horizon Cloud Hosted Horizon Cloud On-premises SSO to virtual desktops and apps Support for Citrix XenApp 5/6/7.x XenDesktop 7.x #ADV1591BU CONFIDENTIAL 16
Horizon Entitlement Sync and Access RDS Farm Horizon 7.x Desktops Horizon Connection Server Get Resources, Entitlements VMworld 2017 Content: Not for Connector VMware Identity Manager publication Horizon Client #ADV1591BU CONFIDENTIAL 17
Horizon 7 Integration #ADV1591BU CONFIDENTIAL 18
Network Ranges #ADV1591BU CONFIDENTIAL 19
Network Ranges #ADV1591BU CONFIDENTIAL 20
Network Ranges #ADV1591BU CONFIDENTIAL 21
End to End SSO with TrueSSO Streamlined single sign on to Horizon via Workspace ONE
Horizon TrueSSO VMworld 2017 Users authenticate to VMware Identity Manager using a variety of credential options Once authenticated, users select Horizon desktop or hosted application No need to enter AD credentials or SmartCard Content: Not for publication Uses SAML to connect the Identity Provider s (IdP) authentication with user s UPN for access to AD credentials True SSO generates unique, short-lived certificate to manage Windows logon process #ADV1591BU CONFIDENTIAL 23
Horizon TrueSSO Benefits VMworld 2017 Separates Authentication (validating a user s identity) from Access (user can use a Windows desktop or application Enhanced security. User credentials are secured by digital certificate, no passwords are vaulted or transferred within the datacenter Supports a wide range of authentication methods enterprises can select or change authentication protocols with limited impact to the infrastructure Content: Not for publication #ADV1591BU CONFIDENTIAL 24
Horizon TrueSSO Workflow 1 VMware Identity Manager VMworld 2017 Content: Not for 2 3 VMware Enrollment Service Horizon Broker 4 5 Microsoft Certificate Authority publication AD 6 Horizon Client 7 Virtual Desktop #ADV1591BU CONFIDENTIAL 25
Horizon TrueSSO Support & Requirements Horizon 7 or Horizon Cloud (latest version) Horizon Enrollment Server Latest Horizon Client (v4) Identity Manager On-Premises or SaaS (latest version) Joined to Active Directory Domain Enterprise Microsoft CA Custom CA templates for short lived certs #ADV1591BU CONFIDENTIAL 26
Horizon Client SP Init Flow Access Policy Support in Horizon VMworld 2017 Content: Not for publication
Horizon 7 Integrated With Workspace ONE Workspace ONE access policies enforced through the Horizon Client 28
Workspace ONE Configuration in Horizon 7.2 1 2 3 1. Require external authentication (IDM) 2. Enables redirection to WS1 hostname 3. Force access policy compliance 29
Access Policy Control in Identity Manager 30
Gotchas!
Horizon Metadata Expired https://kb.vmware.com/kb/2144331 Change metadata expire period to 4-5 days Make sure VMware Identity Manager syncs Horizon entitlements once per day Also mentioned in manual http://pubs.vmware.com/horizon-7- view/topic/com.vmware.horizon- view.administration.doc/guid-3e170c23-097f-46d0-82bd-7cacff04fc9a.html VMworld 2017 Content: Not for publication 34
Horizon Sync require a Worker If deploying many separate connectors in a large environment. Make sure you create a Workspace One idp Add connector to above worker process.. 35
Integrating Horizon Cloud Pod Multiple Horizon instances with Workspace ONE
Horizon Cloud Pod Architecture Layout and Sync Core tcserver IDM VA API SUSE Linux Connector Sync Traffic Connector vpostgres Connector Sync Traffic London Site / POD 1 Paris Site / POD 2 Global Entitlement Home Site AD Groups Global Finance Home Site London Paris Cloud Pod Federation #ADV1591BU CONFIDENTIAL 37
Horizon Cloud Pod Architecture Local Configurations #ADV1591BU CONFIDENTIAL 38
Horizon Cloud Pod Architecture Global Configurations #ADV1591BU CONFIDENTIAL 39
Integrating Horizon Cloud Setting up access to Horizon Cloud with Workspace ONE
Horizon Cloud Hosted Desktops & Apps Integration Requires On-Premises IDM Connector Requires IDM Connector be joined to Active Directory Domain Integrated using sync between Identity Manager & Horizon Cloud Enable Horizon Cloud Desktops and Applications in IDM administration console Create Horizon Cloud Federation Artifact in IDM Configure SAML Authentication in Horizon Cloud From IDM initiate Sync with Horizon Cloud Desktops and Hosted applications are part of the same sync
Horizon Cloud Hosted Desktops & Apps Integration #ADV1591BU CONFIDENTIAL 42
Agenda 1 What is Workspace ONE? 2 Setting up Horizon with Workspace ONE 3 User Experience and Demo #ADV1591BU CONFIDENTIAL 43
DEMO Horizon TrueSSO and Workspace ONE
Questions!