A client of mine is using Horizon View 5.2 in a multiple domain design where there is a one-way trust between the account domain (the trusted domain) and the resource domain (the trusting domain). Think of old-school Windows domain trust models. Unfortunately, Horizon View 5.2 is not designed to support this model which requires them to very painfully create duplicate accounts in the resource domain for a large population of users. This is not just an IT burden, but also a poor user experience because when users login with their resource domain credentials to the VDI, they must continually re-authenticate using their account domain credentials when accessing other resources such as SharePoint, file shares, etc.
It is noted that VMware KB article 20070390 currently describes this as an unsupported architecture; however, due to the commonality of this design across organizations (in particular those that undergo a merger or acquisition), we
remain optimistic there is a better way to solve the problem than by using the current workaround described. Perhaps these are in the product's roadmap.
I have described this in more detail in the attached file. I would deeply appreciate any architectural guidance or roadmap perspectives that would solve or lessen this impact of this problem today.
Thank you in advance,
Randy
VMware employees will not generally comment on roadmap questions over the community forums. I think your best bet is to engage your local account representative and a View resource and submit a feature request via the link below.
Thanks for the reply. The account rep angle is being worked, but there has been little progress. The question on architectural guidance and how have others worked around this limitation is still requested.
