top of page
Zoeken


The Hybrid Join Cascade: When the PRT Challenge Still Isn’t Done
Over the past few months, I’ve been looking into some of the trickier issues in environments that combine Omnissa Horizon Instant Clones, Hybrid Azure AD Join, App Volumes and even TrueSSO. A true resonance cascade For issues with PRT when federated EntraID to Omnissa Access and when using TrueSSO read my previous post: The Hybrid Join Incident: Recovering the Lost PRT 1. PRT unpredictability and the “Wait for Hybrid Join” setting One of the biggest headaches in Instant Clone
Edwin de Bruin
1 dec 20253 minuten om te lezen


The Hybrid Join Incident: Recovering the Lost PRT
Single Sign-On in modern environments can be a beautiful thing, until it isn’t. You’ve federated Entra ID to Omnissa Access, implemented Hybrid Join, and everything works perfectly when users log in with their username and password. But then you try it externally. TrueSSO is in place to make VDI logins seamless, certificates replace passwords and suddenly the PRT never shows up. Microsoft apps (Teams v2 being the most noticeable) rely increasingly on the PRT for full Single S
Edwin de Bruin
27 nov 20253 minuten om te lezen


Horizon Instant Clones, Imprivata OneSign and the no SSO bug
Recently got involved in designing and building a new awesome blistering fast Omnissa Horizon environment for a hospital. This new environment is based on the latest Horizon ESB, DEM, AppVolumes, Windows 11 etc. And as many hospitals do, they use Imprivata OneSign. We ran into a bug. When logging in to the desktop (either Imprivata Client or Horizon client directly) we got confronted by the Imprivata GINA screen. Once again entering credentials and the desktop continues. Reco
Edwin de Bruin
1 aug 20243 minuten om te lezen


VMware vSphere 8.0 U2 and federated Authentications with Microsoft Entra ID
A new feature available since vSphere 8.0 U2 is federated authentication with Microsoft Entra ID (Azure Active Directory) and provision the users with SCIM. This is really nice since it is now possible to create Single Sign On, leverage Conditional Access policies and Multi Factor Authentication (MFA). In this blog I will explain step by step how to configure this and how to mitigate a in my opinion big fat no no required in the original documentation: Expose vCenter to the
Edwin de Bruin
30 dec 20236 minuten om te lezen


FSLogix and using the “OnPrem” Cloud cache
Recently I had a little challenge with an on Prem VMware Horizon VDI environment and the implementation with FSLogix Office and Profile Containers. Due to restrictions there was only one file server available based on Microsoft. In case of an outage the server is replicated to another datacenter but it would take a short time to be available. This and the fact of course the server needs Windows Patches with their respective reboots gave me a bit of a puzzle. Why? Well if an F
Edwin de Bruin
18 aug 20234 minuten om te lezen


VMware UAG and the NO NETWORKING DETECTED error
On a recent project I had to deploy multiple VMware UAG’s for external access. The UAGS are hosted at a cloud provider and the only access I had was the vCloud director. So no PowerShell deployment or the default OVA deployment trough vCenter. Unfortunately the deployment did not work, the backend team was not available at the time (bigger priorities and Ok fair enough Friday late in the afternoon) so no escape to a regular deployment and of course I gave myself a deadline fo
Edwin de Bruin
15 aug 20232 minuten om te lezen


Citrix Provisioning, WriteCache and the impact of “The After reboot jobs”
A while ago me and my friend and colleague JP Ruitenbeek were “flown in” to investigate performance issues at a customer. We found multiple issues but in this one we focus on a specific one: “The After-reboot jobs.” The Start: Lately a lot of complaints received the IT department of this customer about performance, latencies and login issues. The users were simply losing trust in the environment. Sum up some of the complaints: · Login times very high · Slown
Edwin de Bruin
3 apr 20234 minuten om te lezen


Microsoft November Updates and breaking TrueSSO
First of all happy new year everyone! On 31 december 2022 New Years Eve I got a message from a colleague of mine while eating "oliebollen" with the family at friends of ours. One customer is having issues with external login's to their VMware Horizon environment. They get stuck on the Imprivata login screen. Alltough the user can login by re-entering their credentials it is annoying. The fact Imprivata selected the default domain to be the local machine and the user has to sw
Edwin de Bruin
1 jan 20232 minuten om te lezen


The User overflow and how to solve it with a Backup Global entitlement in VMware Horizon.
Buffer Overflow: [a] condition at an interface under which more input can be placed into a buffer or data holding area than the capacity allocated, With al little creativity and bending we also see this in a VDI environment, I name this a User Overflow: [a] condition at an environment under which more users try to be placed into a pool than the capacity allocated, Of course with VMware Horizon you can make the pools dynamic in size but you will be limited by the available har
Edwin de Bruin
27 sep 20224 minuten om te lezen


The View Agent reports that this desktop source is unable to accept connections.
Last week I was exposing my VMware Horizon environment externally. Of course I wanted the single sign on experience. So enrolled the Workspace One Access tennant, deployed the sync server.. configured directory sync, authentication rules, next Virtual Apps etc . On the connector SAML to required, configured SAML authenticator to Access, connector in Workspace One mode, deployed enrollment server, created TrueSSO template, configured TrueSSO, deployed UAGS etc etc and let the
Edwin de Bruin
17 feb 20222 minuten om te lezen
Script to check if your 2019 Server is vulnerable for CVE-2022-21907
Created a little powershell script to my best effort to check if your 2019 Server is vulnerable for CVE-2022-21907 CVSS base score of 9.8 so action is required More information about the CVE: CVE-2022-21907 - Security Update Guide - Microsoft - HTTP Protocol Stack Remote Code Execution Vulnerability Used some resources found online, put them together with some adjustments in the script (i am not a scripter, google is my friend ;-)) Keep in mind: no guarantee and advise is to
Edwin de Bruin
13 jan 20221 minuten om te lezen
Blog: Blog2
bottom of page