Installation

Table Of Contents
2 Add the Create Computer Objects, Delete Computer Objects, and Write All Properties permissions to
the account in the Active Directory container in which the linked-clone computer accounts are created
or to which the linked-clone computer accounts are moved.
The following list shows all the required permissions for the user account, including permissions that
are assigned by default:
n
List Contents
n
Read All Properties
n
Write All Properties
n
Read Permissions
n
Reset Password
n
Create Computer Objects
n
Delete Computer Objects
NOTE Fewer permissions are required if you select the Allow reuse of pre-existing computer accounts
setting for a desktop pool. Make sure that the following permissions are assigned to the user account:
n
List Contents
n
Read All Properties
n
Read Permissions
n
Reset Password
3 Make sure that the user account's permissions apply to the Active Directory container and to all child
objects of the container.
What to do next
Specify the account in View Administrator when you configure View Composer domains in the Add
vCenter Server wizard and when you configure and deploy linked-clone desktop pools.
Configure the Restricted Groups Policy
To be able to connect to a remote desktop, users must belong to the local Remote Desktop Users group of
the remote desktop. You can use the Restricted Groups policy in Active Directory to add users or groups to
the local Remote Desktop Users group of every remote desktop that is joined to your domain.
The Restricted Groups policy sets the local group membership of computers in the domain to match the
membership list settings defined in the Restricted Groups policy. The members of your remote desktop
users group are always added to the local Remote Desktop Users group of every remote desktop that is
joined to your domain. When adding new users, you need only add them to your remote desktop users
group.
Prerequisites
Create a group for remote desktop users in your domain in Active Directory.
View Installation
28 VMware, Inc.