VMware Horizon: How It Works, Key Components & Deployment
See Venn first in Google Search
Add as a preferred source on GoogleWhat Is Omnissa Horizon (Previously VMware Horizon)?
VMware Horizon (now rebranded as Omnissa Horizon) is an enterprise-grade Virtual Desktop Infrastructure (VDI) and application virtualization platform. It allows organizations to securely host and centrally manage virtual Windows/Linux desktops and applications in data centers or the cloud, delivering them remotely to end-users on any device.
How it works:
The platform centralizes all computing resources in a secure, remote location. Instead of running heavy applications directly on a local laptop or PC, the user accesses a streaming instance of a desktop. The core logical components include:
- Horizon Connection Server: The broker that authenticates users and directs them to their assigned virtual desktop or remote application.
- Horizon Agent: The software installed on the virtual or physical machine that communicates with the Connection Server.
- Horizon Client: The application or browser-based portal end-users open on their computers or mobile devices to access their digital workspace.
- Unified Access Gateway (UAG): Secure edge services that allow remote users to connect safely without a VPN.
- Horizon Console: A centralized web-based management interface for administering desktop pools, applications, users, policies, monitoring, and troubleshooting across the Horizon environment.
- Horizon Control Plane: A cloud-based management layer that provides centralized administration, monitoring, image management, and brokering across multiple on-premises and cloud Horizon deployments.
Secure Data on Unmanaged Laptops – Without VMware Horizon Complexity
See how Venn enables secure BYOD workforces without the cost, latency, and management headaches of VMware Horizon.

In this article:
Key Benefits of Omnissa Horizon
Omnissa Horizon helps organizations simplify desktop and application delivery while improving security and user access. Its centralized architecture reduces administrative effort and gives IT teams control over virtual environments across on-premises and cloud deployments:
- Centralized management: Manage desktops, applications, policies, and updates from a single platform instead of configuring individual endpoints.
- Secure remote access: Provide users with secure access to virtual desktops and applications from supported locations and devices.
- Consistent user experience: Deliver the same desktop environment across PCs, thin clients, tablets, and smartphones.
- Improved security: Keep applications and data in the data center or cloud rather than on endpoint devices.
- Support for hybrid and cloud deployments: Deploy Horizon on-premises, in public clouds, or in hybrid environments to match business requirements.
- Lower endpoint requirements: Extend the life of existing hardware and support thin clients because most processing happens on centralized infrastructure.
- Simplified scaling: Provision new virtual desktops and applications to support business growth or temporary workforce increases.
- BYOD support: Allow employees to use personal devices while maintaining centralized control over corporate desktops and data.
- Business continuity: Enable users to work from alternate locations during office outages or disruptions.
- Streamlined maintenance: Apply updates, patches, and configuration changes once in the centralized environment instead of managing each endpoint separately.
Key Components of Omnissa Horizon
Horizon Connection Server
Horizon Connection Server is the central connection-brokering and authentication component in a Horizon environment. It:
- Receives connection requests from Horizon Clients
- Authenticates users through Microsoft Active Directory
- Checks which desktops and applications they are entitled to access
- Directs them to the appropriate resource
These resources may include virtual Windows or Linux desktops, published applications, RDS-hosted desktops, or supported physical machines. The Connection Server coordinates desktop pools, application assignments, policies, and session information across the Horizon deployment. Once a user’s session is established, display-protocol traffic typically flows directly between the Horizon Client and Horizon Agent rather than continuing through the Connection Server. This reduces the server’s workload and prevents it from becoming a bottleneck in the user session.
Organizations can deploy multiple Connection Servers in a replicated, load-balanced configuration to improve scalability and availability. If one server becomes unavailable, another can continue authenticating users and brokering connections.
Horizon Agent
Horizon Agent is software installed in the operating system of every desktop or server that Horizon delivers to users. It can be installed on virtual desktop machines, Remote Desktop Session Host servers, Linux systems, and supported physical Windows PCs. The agent enables the machine to register with and be managed by Horizon Connection Servers:
- When a user launches a desktop or application, Horizon Client establishes a display-protocol session with the Horizon Agent on the selected machine. T
- he agent transmits the desktop interface, application display, keyboard input, mouse activity, audio, and other session data between the remote resource and the user’s endpoint.
Horizon Agent enables remote-experience and administrative features. Depending on the deployment and configuration, these can include device redirection, clipboard control, printing, multimedia optimization, USB access, session monitoring, and policy enforcement. Installing and configuring the agent supports desktop management and user experience.
Horizon Client and Horizon Web Client
Horizon Client is the endpoint application users install on a laptop, desktop, tablet, smartphone, thin client, or other supported device to access Horizon-managed desktops and applications. It provides the interface through which users:
- Authenticate
- View entitled resources
- Launch sessions
- Reconnect to sessions
- Interact with remote desktops or applications
After authenticating with a Connection Server, Horizon Client connects to the Horizon Agent running on the selected resource. It supports Horizon display protocols and provides access to features such as local printing, multiple monitors, audio and video redirection, USB devices, and other endpoint integrations, depending on the client operating system and administrator policies.
Horizon Web Client provides an alternative for devices where installing the full client is not practical. Users can open a supported browser, sign in to Horizon, and launch desktops or applications through an HTML-based interface. The browser-based client may offer fewer peripheral-redirection and integration capabilities than the installed Horizon Client.
Unified Access Gateway
Unified Access Gateway is a hardened virtual appliance that provides secure access to Horizon desktops and applications from external networks. It is commonly deployed in a demilitarized zone, or DMZ, between the public internet and the organization’s internal Horizon infrastructure.
- When a remote user connects, Unified Access Gateway acts as a reverse proxy.
- It forwards authentication traffic to the appropriate Horizon Connection Server and routes the display-protocol session to the Horizon Agent on the user’s assigned desktop or application server.
- Only traffic associated with authenticated and authorized users is allowed into the internal environment, while unauthenticated requests are discarded.
Unified Access Gateway can support additional authentication mechanisms and security controls, adding another layer of protection before users reach internal Horizon resources. It encrypts externally initiated Horizon sessions and can remove the need to provide users with broad network access through a traditional VPN. Multiple gateway appliances can be deployed with load balancing or built-in high availability to support larger environments and reduce the risk of service disruption.
Horizon Console
Horizon Console is the web-based administrative interface included with Horizon Connection Server. It gives administrators a centralized location for configuring, managing, monitoring, and troubleshooting the Horizon environment without managing each desktop or server individually.
Through Horizon Console, administrators can:
- Create and maintain desktop pools
- Configure RDS farms
- Publish applications
- Assign users and groups to resources
- Manage authentication settings
- Apply access or session policies
They can also review machine status, inspect active and disconnected sessions, examine events, and perform support actions for end users. The console provides visibility into the environment, helping IT teams identify unavailable machines, provisioning problems, authentication failures, and other issues that may affect users.
Secure Data on Unmanaged Laptops – Without VMware Horizon Complexity
See how Venn enables secure BYOD workforces without the cost, latency, and management headaches of VMware Horizon.

Horizon Control Plane
Horizon Control Plane is a cloud-based management layer that extends Horizon 8 environments with centralized services delivered from the cloud. Organizations can connect on-premises and cloud-hosted Horizon pods to the Control Plane while continuing to run their virtual desktops, applications, Connection Servers, and supporting infrastructure in their chosen locations.
A Horizon Edge Gateway appliance connects each Horizon 8 pod to Horizon Cloud services. This connection allows the organization to use subscription licensing, centralized brokering, image management, monitoring, and other cloud-delivered administrative services without moving the entire Horizon deployment into a software-as-a-service environment.
The Control Plane can simplify the management of multiple Horizon environments distributed across data centers and supported cloud platforms. Administrators can:
- Manage images across locations
- Provide users with access to resources from different pods
- Gain visibility into system health and user experience
This hybrid architecture allows organizations to retain control over workload placement while adopting cloud-based management capabilities.
Omnissa Horizon Deployment Options
Omnissa Horizon supports several deployment models, allowing organizations to place virtual desktops, applications, management components, and supporting infrastructure in environments that match their operational, security, and scalability requirements. The Horizon portfolio includes Horizon 8 for customer-managed deployments and Horizon Cloud for desktop-as-a-service environments. Horizon Agent and Horizon Client technologies are shared across these platforms to provide a consistent user experience.
On-Premises Horizon 8 Deployment
In an on-premises deployment, the organization installs and operates Horizon 8 within its own data center. Horizon infrastructure components, including Connection Servers, Unified Access Gateway appliances, management tools, desktop virtual machines, and RDS hosts, run on customer-controlled infrastructure.
This option provides direct control over data, network architecture, security policies, upgrade schedules, and infrastructure configuration. It can suit businesses with existing virtualization environments, strict data-location requirements, specialized integrations, or workloads that must remain within private facilities. The organization is responsible for purchasing, maintaining, scaling, and protecting the underlying infrastructure.
Horizon 8 on a Supported Cloud Platform
Horizon 8 can also be deployed on supported public cloud infrastructure and cloud-based VMware environments. Omnissa provides architecture guidance for platforms such as VMware Cloud on AWS, Azure VMware Solution, Google Cloud VMware Engine, Oracle Cloud VMware Solution, and Alibaba Cloud VMware Service. The Horizon components remain largely the same as in an on-premises deployment, but they run on infrastructure hosted by the cloud provider.
This model allows organizations to use Horizon and VMware technologies without purchasing additional data center hardware. It can support use cases such as data center expansion, regional desktop delivery, disaster recovery, temporary capacity increases, and cloud migration. Depending on the platform, Horizon components can be deployed inside the cloud software-defined data center or divided between native cloud infrastructure and the cloud-based VMware environment.
All-in-SDDC Architecture
With an all-in software-defined data center architecture, the Horizon management components and user resources are deployed within the same cloud SDDC. This includes Connection Servers, Unified Access Gateway appliances, supporting services, virtual desktops, and RDS hosts used to deliver published applications.
Placing the complete Horizon environment inside the SDDC can simplify deployment because the management and workload components share the same environment. However, scalability, network routing, gateway placement, and platform-specific limits must be considered.
Federated Cloud Architecture
In a federated architecture, Horizon management components and user workloads are placed in different parts of the cloud environment. For example, Connection Servers and Unified Access Gateway appliances may run on native cloud virtual machines, while virtual desktops and RDS hosts run inside a cloud-based VMware SDDC.
Separating the management layer from the desktop capacity can provide architectural flexibility and support deployments that span multiple SDDCs. This approach requires planning for connectivity, identity services, firewall rules, latency, and communication between the management and workload environments.
Hybrid Horizon Deployment
A hybrid deployment combines Horizon resources in a private data center with resources running on supported cloud platforms. Organizations can retain on-premises capacity while adding cloud-hosted pods to support expansion, disaster recovery, geographic distribution, or variable demand.
Cloud Pod Architecture can connect independent Horizon pods running on-premises, in public clouds, or across mixed environments. Users can receive global entitlements that give them access to desktops and applications across connected pods. Each pod remains a distinct Horizon deployment, which avoids stretching individual Connection Server groups across geographically distant networks.
Horizon Cloud Deployment
Horizon Cloud is a desktop-as-a-service deployment model managed through the Horizon Control Plane. It provides a global administrative view of virtual desktops and applications distributed across supported cloud and on-premises environments. Administrators can use cloud-based services to provision, manage, monitor, and broker access to desktop and application resources.
This option reduces the need to deploy and maintain many traditional Horizon management components independently. It can suit organizations that want a SaaS-oriented management experience, rapid cloud deployment, multi-cloud visibility, and consistent administration across locations. The underlying desktop and application capacity can still be placed close to users or business data to address performance and regulatory requirements.
Multi-Pod and Multi-Site Deployment
Large organizations can deploy multiple Horizon pods across data centers, regions, or cloud environments. A pod is an independently managed Horizon environment containing one or more Connection Servers and associated desktop or application resources.
Multiple pods can be connected through Cloud Pod Architecture to create a pod federation. This allows administrators to define global entitlements and direct users to available resources across sites. A multi-pod design can improve scalability, support geographic expansion, provide disaster-recovery options, and reduce the impact of a failure affecting a single site. Network latency, replication requirements, load balancing, identity infrastructure, and capacity planning should be evaluated when designing the federation.
Omnissa Horizon Pricing Example
Omnissa Horizon pricing varies according to the licensing model, number of users, deployment architecture, support level, and infrastructure consumed. As one example, an AWS Marketplace listing sold by BYNET offers Omnissa Horizon as an Amazon Machine Image that organizations can deploy within their own AWS virtual private cloud. The listing combines Horizon licensing with usage-based marketplace charges, while the customer remains responsible for underlying AWS infrastructure costs.
The listing provides the following example prices for one-year Omnissa Horizon 8 Enterprise Term licenses:
- 10 concurrent users (c4.2xlarge): $2,508 for a one-year term, including production support and subscription services.
- 10 named users (c4.4xlarge): $1,567.50 for a one-year term, including production support and subscription services.
Concurrent-user licensing is based on the maximum number of users accessing Horizon at the same time. Named-user licensing assigns licenses to specific individuals.
The AWS Marketplace listing also displays hourly software usage charges based on the selected Amazon EC2 instance type. At the time of publication, the listed charges include:
- c4.4xlarge: $0.18 per hour
- c4.xlarge: $0.18 per hour
- c4.2xlarge: $0.29 per hour
- c4.large: $0.29 per hour
These figures represent charges associated with this marketplace product and seller, rather than the complete cost of operating a Horizon environment. AWS notes that additional infrastructure expenses may apply, including EC2 compute, storage, networking, load balancing, backups, and data transfer. Organizations may select usage-based billing or an upfront 365-day contract, with the listing advertising savings of up to 1% for the annual contract option.
Why Look for Omnissa Horizon Alternatives?
Omnissa Horizon is a mature virtual desktop and application delivery platform, but it may not be the best fit for every organization. Its architecture, licensing, infrastructure requirements, and operational complexity can make alternative platforms more suitable for businesses seeking a simpler, more flexible, or more cost-effective approach to remote work.
Common reasons to evaluate Omnissa Horizon alternatives include:
- High total cost of ownership: Horizon deployments may involve licensing, server infrastructure, storage, networking, cloud consumption, support, and specialist administration costs.
- Complex deployment and management: Designing and operating Connection Servers, gateways, desktop pools, agents, identity integrations, and supporting infrastructure can require significant VDI expertise.
- Infrastructure requirements: Traditional Horizon environments often depend on substantial virtualization and data center infrastructure.
- Lengthy implementation projects: Large Horizon deployments can require detailed capacity planning, image design, networking changes, security configuration, testing, and user migration.
- Cloud-first strategy: Organizations standardizing on AWS, Microsoft Azure, Google Cloud, or SaaS platforms may want a solution designed for their chosen cloud.
- Changing licensing and vendor relationships: Organizations may reassess Horizon when contracts expire, pricing changes, or procurement priorities shift.
- Limited internal VDI expertise: Horizon environments require administrators who understand virtualization, desktop images, application delivery, networking, identity, performance tuning, and troubleshooting.
- Need for simpler endpoint security: Some organizations do not need to virtualize an entire desktop. Secure workspace, browser isolation, application streaming, or endpoint-container solutions may provide controlled access to business data.
- Performance and user experience concerns: The quality of a virtual desktop session can depend on network latency, bandwidth, protocol configuration, workload sizing, and proximity to infrastructure.
- Support for contractors and BYOD users: Delivering a complete virtual desktop may be excessive for users who only need access to a few corporate applications.
- Scalability and seasonal demand: Businesses with temporary workers, acquisitions, call centers, or fluctuating workforce requirements may prefer services that can scale without purchasing and maintaining permanent infrastructure.
- Application compatibility requirements: Some workloads, peripherals, graphics applications, or legacy systems may require specialized configurations.
- Desire to reduce administrative overhead: Organizations may want to automate image management, patching, capacity allocation, user provisioning, monitoring, and updates.
How to Move Beyond VMware Horizon VDI with Blue Border
VMware Horizon (Omnissa Horizon) delivers desktops and applications by hosting them centrally and streaming them back to the user, which brings the infrastructure, cost, and latency challenges outlined above. Venn offers a VDI alternative built on a fundamentally different approach: instead of hosting applications and data remotely, it protects work directly on unmanaged and BYOD computers.
Installing Blue Border on a Mac or PC creates a company-controlled secure enclave directly on that device. All business activity inside the enclave – company data, applications, networking, and AI workflows – is protected and isolated from any other use on the same computer. Work applications run locally, with no performance tradeoffs, visually marked by a blue line wrapped around those application windows. With Blue Border™, users work locally, resulting in seamless security, a far better user experience, and dramatically lower overhead than traditional virtual desktops.
Key capabilities of Blue Border:
- Local, native performance: Unlike virtual desktops, Blue Border keeps users working locally on natively installed applications, eliminating the latency and lag associated with remotely hosted VDI sessions.
- Company-controlled secure enclave: Work lives inside a secure enclave on the user’s own computer that protects and isolates business activity from any personal use on the same machine.
- Security without remote hosting: Blue Border™ protects apps, data, and network access on unmanaged and BYOD computers without hosting applications and data in a data center or the cloud.
- Targeted firewall protection: Venn extends corporate firewall protection to business activity only, rather than taking control of the entire device.
- Lower overhead and cost: By removing the need for connection servers, gateways, desktop pools, and supporting infrastructure, Venn reduces the administrative burden and cost that come with running a full VDI environment.
To see how Venn secures remote and BYOD work without the cost and complexity of VMware Horizon, explore Venn’s VDI alternative.