Lab 2: Deploy UEM Agent in Horizon Golden Image and validate pool enrollment

Objective and Tasks

In this lab, a Horizon pod is already deployed, and a Windows 11 golden image VM with the Horizon Agent installed is powered off and waiting for you.

You will install the Workspace ONE Intelligent Hub into the golden image so that it survives image customization (Sysprep/ClonePrep) and defers enrollment, configure a desktop pool to enroll its clones automatically, and log in to a desktop to start enrollment.

  1. Install the Workspace ONE Intelligent Hub in the Horizon golden image.
  2. Configure the Horizon desktop pool for automated Workspace ONE UEM enrollment.
  3. Launch a desktop and verify that enrollment flips to the logged-on user.

For more information and guidance on integrating the two platforms, see the Omnissa Tech Zone guide, Omnissa Workspace ONE Unified Endpoint Management Integration with Horizon.

 

Expand or collapse content Task 1: Install the Workspace ONE Intelligent Hub in the Horizon golden image

This step makes a golden image safe to clone.

Two command-line parameters do the work. DEFERENROLLMENT=Y caches the enrollment details when there is no interactive Windows session and holds enrollment back until a user logs in. PROVISIONHUB=Y allows the Intelligent Hub to survive Sysprep.

Without them, every clone inherits the golden image identifiers and the console cannot tell your desktops apart.

  1. Open the vCenter admin console.
    • On your ControlCenter desktop, open a new tab in the Google Chrome browser.
    • Click the bookmark on the bookmark bar for vcenter-01.
  2. Log in to the vCenter admin console.
  3. Power on the golden image VM and open a console.
    • Browse to and select the VM W11PreBuilt.
    • From the ACTIONS > Power menu at the top, select Power On.
    • When the VM is powered on, select the Summary tab and click LAUNCH WEB CONSOLE.
    • At the top right, select Send Ctrl-Atl-Delete to log in to Windows.
    • Windows will login automatically with buildadmin.
  4. Open an elevated command prompt.
    • Right-click the Windows Start icon and select Terminal (Admin).
    • Click Yes on the UAC Prompt
  5. Install the Intelligent Hub with the deferred enrollment parameters.

For this command, verify that you are installing Intelligent Hub in the Golden Image VM and not installing on the ControlCenter VM.

Use the Type Text feature below for easier text input of this long command line string.

Msiexec.exe /i "\\fs\resources\Software\UEM\AirwatchAgent.msi" /qb! DEFERENROLLMENT=Y PROVISIONHUB=Y
Click to copy
  1. You will see the Intelligent Hub installer progress Window appear. This process takes about 2-3 minutes.
  2. After the Intelligent Hub installer completes, confirm that Intelligent Hub is installed.
    • Wait for the installer to complete and give some time for Hub services to start up.
    • Check for a Intelligent Hub icon in the System Tray.
  1. Shut down the golden image.
    • Use Windows Start > Power button > Shut down.
  2. Take a snapshot of the golden image.
    • In Google Chrome, switch to the vSphere tab.
    • Browse to and select the VM W11PreBuilt.
    • Confirm that the Power Status is Powered off.
    • Select the Snapshots tab and click TAKE SNAPSHOT.
    • Clear the default Name, then enter Hub-Installed.
    • Click CREATE.

Note in your list of Snapshots for W11PreBuilt you will see Hub-Installed+AVAgent this snapshot is pre-staged for use in Task 2.

Only three things are strictly required on the golden image: Windows operating system, Horizon Agent, and Intelligent Hub installed with these two parameters.

Everything else applications, policies, configurations, optimizations can be delivered by Workspace ONE and App Volumes afterward. That is what lets you collapse a sprawl of special-purpose golden images down to one or two vanilla ones.

Expand or collapse content Task 2: Configure the Horizon desktop pool for automated Workspace ONE enrollment

Historically, this integration meant embedded installers, PowerShell scripts, and a scheduled task that had to delete itself so that staging credentials were not left on disk. You now configure it on a tab in the pool wizard, and the credentials never touch the endpoint.

  1. Open the Horizon admin console.
    • On your ControlCenter desktop, open a new tab in the Google Chrome browser.
    • Click the bookmark for horizon-02a.
  2. Log in to the Horizon admin console.
    • Username: administrator
    • Password: Pa$$w0rd
    • Domain: OmnissaTraining
  3. Edit the desktop pool.
    • Navigate to Inventory > Desktops.
    • Select Win11-Site2 to view details of the existing desktop pool.
    • Select Maintain and click Promote Secondary Image.
    • On the Promote Secondary Image box, select OK.

This starts the process for deploying a pre-staged secondary image that is already staged as part of this lab. Using the pre-staged snapshot will avoid having to sit through an Instant clone priming process that takes about 20 minutes in this lab environment.

This process deploys the Intelligent Hub Agent to the current desktop pool and has it up and running in about 3 - 4 minutes. If you have an extra 20 minutes, you could use the snapshot that you just created to deploy Intelligent Hub to the pool.

While this process runs in the background, you configure the pool for Workspace One UEM enrollment.

  1. Enable Workspace ONE UEM management for the pool.
    • Click Edit for the Win11-Site2 desktop pool.
    • On the UEM Enrollment tab, enable the Manage with UEM toggle to manage this pool with Workspace ONE UEM.
    • Select Add New.
  2. Enter the enrollment details.
    • In the Name field, enter UEM-VDI
    • In the UEM Device Services URL field, enter https://ds1605.awmdm.com
    • In the Organization Group field, enter [email protected]
    • In the Staging username field, enter [email protected]
    • In the Password field, enter Pa$$w0rd.

The UEM Device Services URL is the device services address, not the address you use to administer the console. The value you need is https://ds1605.awmdm.com. Entering the console address here is the most common reason enrollment silently fails, and it produces no useful error.

Make sure you use the Org Group ID, [email protected] (no dash), and not the Org Group name, which is Horizon-VDI.

  1. Complete the wizard.
    • Click OK.
  2. Confirm that the pool is marked as managed.
    • Navigate to Inventory > Desktops.
    • Select the pool Win11-Site2.
    • Confirm that UEM Managed shows Yes in the Pool Summary General section.

Automated enrollment from the pool wizard is available on Horizon Cloud, and on Horizon 8 2512 for persistent pools only. Horizon 8 2603 extends it to non-persistent pools as well.

On Horizon 8 2506 and earlier you must fall back to the legacy scheduled-task method, which creates a task that deletes itself so that staging credentials are not left on disk.

Expand or collapse content Task 3: Launch a desktop and verify that enrollment flips to the logged-on user

The staging account initially enrolls the virtual machine, but the device record does not stay with the staging account. When a user logs in through Horizon, the Intelligent Hub reassigns the device to that user with no action from the user or the administrator. This is the mechanism behind per-user policy and application assignment on a shared golden image, and it is worth watching happen.

  1. Wait for the pool to finish provisioning.
    • In the Horizon admin console, select the pool Win11-Site2.
    • Select the Machines (Instant Clone Details) tab.
    • Wait until the Status column shows Available for all three VMs in the pool.
    • Wait for UEM Managed to show NotStarted or Cached.
    • You may need to refresh the list while the Hub registers with UEM.
  2. Launch the Omnissa Horizon Client.
    • From the ControlCenter desktop, double-click the Omnissa Horizon Client icon.
    • If the pod is not already listed, click Add Server, enter https://horizon-02a.omnissatraining.com, and click Connect.
  3. Log in and launch the desktop.
    • Username: Student1
    • Password: Pa$$w0rd
    • Click Login.
    • Double-click the tile for Win11-Site2.
  4. Observe enrollment completing inside the desktop.
    • Wait for the Windows desktop to finish loading.
    • Open the Workspace ONE Intelligent Hub application from the System Tray.
    • Confirm that the Hub now reports the device as enrolled and managed.
    • It can take a few minutes for the Hub to fully enroll.
    • Click Exit Fullscreen on the Horizon Toolbar.
  5. Confirm the device record in the Workspace ONE UEM console.
    • Return to the ControlCenter desktop and connect to the the Workspace ONE UEM console.
    • Navigate to Devices > Devices.
    • Locate the new device record, if the record has not appeared yet, refresh the page.
    • Confirm that the User column shows Student1, not [email protected].
  6. Confirm smart group membership.
    • Select the device record to open Device Details.
    • Confirm that the device is a member of the Horizon-Win11-Desktops smart group.
    • Note the organization group shown for the device.

If a second student logged in to a different clone from this same pool, they would get their own device record and their own assigned policies and applications, from the same golden image. One image, per-user configuration.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.