VMware Horizon Community
Cstructure
Contributor
Contributor
Jump to solution

VMware View User Desktop

Hi,

When a user login to VMware View for the first time they are assigned a full virtual machine, but their AD user account is not added to the local administrator group.

Is there a way to automate this?

Also, is there a way to force the sysprep to add this machine to a specific OU in active directory?

Thanks,

CS

0 Kudos
1 Solution

Accepted Solutions
Linjo
Leadership
Leadership
Jump to solution

Hi.

Why would they be added to the local admins group?

I guess the best way of doing this would be to add the users to a AD-group and add that group the local admin group...

// Linjo

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".

View solution in original post

0 Kudos
5 Replies
Cstructure
Contributor
Contributor
Jump to solution

Anyone?

0 Kudos
Linjo
Leadership
Leadership
Jump to solution

Hi.

Why would they be added to the local admins group?

I guess the best way of doing this would be to add the users to a AD-group and add that group the local admin group...

// Linjo

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
nnmansoori
Enthusiast
Enthusiast
Jump to solution

Hi,

I guess Linjo is right, we cannot set the local users and group policies through the VMware View Connection broker server, and for such a purpose, you need to use Active Directory Group Policies.

Nastaran M

0 Kudos
Cstructure
Contributor
Contributor
Jump to solution

Some users will need ADMIN rights to install software etc...

I was hoping there would be an easier way then GPO.

0 Kudos
mittim12
Immortal
Immortal
Jump to solution

I agree with Linjo.   Create an AD Group called "VDI User Admin" or something of that nature.  Stick that group in the local admin of your template or parent image.   Then if you have any users that need admin priv they would simply be added to that group on the AD side.    You shouldn't need a GPO to handle that.

0 Kudos