Setting Up Desktop and Application Pools in View

Table Of Contents
When users log in through a tagged View Connection Server instance, they can access only those desktop
pools that have at least one matching tag or no tags.
NOTE You cannot configure the restricted entitlements feature to restrict access to remote applications.
n
Restricted Entitlement Example on page 139
This example shows a View deployment that includes two View Connection Server instances. The first
instance supports internal users. The second instance is paired with a security server and supports
external users.
n
Tag Matching on page 140
The restricted entitlements feature uses tag matching to determine whether a View Connection Server
instance can access a particular desktop pool.
n
Considerations and Limitations for Restricted Entitlements on page 141
Before implementing restricted entitlements, you must be aware of certain considerations and
limitations.
n
Assign a Tag to a View Connection Server Instance on page 141
When you assign a tag to a View Connection Server instance, users who connect to that View
Connection Server can access only those desktop pools that have a matching tag or no tags.
n
Assign a Tag to a Desktop Pool on page 141
When you assign a tag to a desktop pool, only users who connect to a View Connection Server
instance that has a matching tag can access the desktops in that pool.
Restricted Entitlement Example
This example shows a View deployment that includes two View Connection Server instances. The first
instance supports internal users. The second instance is paired with a security server and supports external
users.
To prevent external users from accessing certain desktops, you could set up restricted entitlements as
follows:
n
Assign the tag "Internal" to the View Connection Server instance that supports your internal users.
n
Assign the tag "External" to the View Connection Server instance that is paired with the security server
and supports your external users.
n
Assign the "Internal" tag to the desktop pools that should be accessible only to internal users.
n
Assign the "External" tag to the desktop pools that should be accessible only to external users.
External users cannot see the desktop pools tagged as Internal because they log in through the View
Connection Server tagged as External, and internal users cannot see the desktop pools tagged as External
because they log in through the View Connection Server tagged as Internal. Figure 12-1 illustrates this
configuration.
Chapter 12 Entitling Users and Groups
VMware, Inc. 139