VMware Horizon Community
Lieven
Hot Shot
Hot Shot

Restrict Remote Access through UAG - customise error message

 

I want to disallow a number of users the right to access the VMware Horizon View environment from outside the corporate network. To do this I have multiple AD groups defined:

  • VDI_Allow_External_Access
    • ==> contains users that are allowed external access through UAG
  • VDI_Exclude_External_Access
    • ==> contains users that are not allowed external access through UAG
      • this group is not actually necessary but I add it just as a double check so each user is at least in one of the groups VDI_Allow_External_Access or VDI_Exclude_External_Access

 

  • VDI_Pool_01_Access
    • ==> contains users that have access to Pool #01 (used in the pool entitlement)
  • VDI_Pool_02_Access
    • ==> contains users that have access to Pool #02 (used in the pool entitlement)

 

A user which is not allowed to access the VMware Horizon View environment from outside the corporate network is a member of the following groups

  • VDI_Exclude_External_Access
  • VDI_Pool_0x_Access

A user which is allowed to access the VMware Horizon View environment from outside the corporate network is a member of the following groups

  • VDI_Include_External_Access
    VDI_Pool_0x_Access

 

I have added the AD group VDI_Include_External_Access to the Remote Access, which allows all the members of this group to access the environment through the UAG servers which are only used to access the environment from outside the corporate environment

Lieven_0-1655214628776.png

 

This configuration works fine and users that are not in the VDI_Include_External_Access group are not allowed to access the VDI environment from outside the corporate environment but can access it perfectly from inside the corporate environment.

 

However, the error message the user receives is "YOU ARE NOT ENTITLED TO USE THE SYSTEM". This message is actually not entirely true because the user is entitled to use the system, but only when the are accessing it from within the corporate environment.

QUESTION:

is it possible to customise this message or is this something I should ask as a feature request?

Labels (1)
0 Kudos
1 Reply
Lieven
Hot Shot
Hot Shot

I raised a support ticket for this and according to support this is not possible. Therefore I raised a feature request https://wsone.ideas.aha.io/ideas/HZI-I-601 

0 Kudos