Skip to main content

VMware Horizon 8 (2309)

VMware have released a new version of VMware Horizon 8 (2309), and this release is general available from 26th October 2023. This is a major release, so I hope you like this article I put together. VMware have made some huge improvements in this release, which customers/partners are going to benefit from. Lets dig into what is new.

What is new in VMware Horizon 8 (2309)

VMware Horizon 8 2309 provides the following new features and enhancements

  • VMware Horizon Connection Server
  • VMware Horizon Agent for Linux
  • VMware Horizon Agent for Windows
  • VMware Horizon GPO Bundle
  • VMware Dynamic Environment Manager 2309
  • VMware Unified Access Gateway 2309
  • VMware App Volume 2309
  • VMware Horizon Clients 2309 for Android, Linux, iOS, Mac, Windows, HTML Access
  • VMware Horizon Cloud services 2309

VMware Horizon 8 version 2309 is a Current Release (CR), and is supported until 30-03-2026.

VMware Horizon 8 version 2309 includes the following new features and enhancements.

IMPORTANT: Horizon 8 2309 is not supported with vSphere 6.5 or vSphere 6.7, which are both past the end of General Support.  Horizon 8 2309 Instant Clones are incompatible with vSphere 6.5 and vSphere 6.7 so you must upgrade to vSphere 7.0 or later before upgrading to Horizon 8 2309 if you are using Instant Clones.

IMPORTANT: Horizon 8 2309 is not supported with vSphere 6.5 or vSphere 6.7, which are both past the end of General Support.  Horizon 8 2309 Instant Clones are incompatible with vSphere 6.5 and vSphere 6.7 so you must upgrade to vSphere 7.0 or later before upgrading to Horizon 8 2309 if you are using Instant Clones.

NOTE: In FIPS mode, Horizon 8 2309 is compatible with all Horizon Client and Unified Access Gateway releases, including versions earlier than 2309. However, to use a Horizon Client version 2309 or later in FIPS mode, you must use Connection Server version 2309 or later; if using Unified Access Gateway, you must also use Unified Access Gateway 2309 or later. For more information, see VMware Knowledge Base (KB) article 95144.

WARNING: Microsoft security update (KB 5014754) will impact customers using certificate-based authentication such as smartcards. If you have applied this update to your Windows Domain Controllers and if you have not mapped certificates to one of the strong mapping types described in the Microsoft KB, then users will be denied authentication when the full enforcement mode is activated by Microsoft.  See the above KB for details on the full enforcement mode date. To address this issue the Horizon 8 2309 release allows administrators to configure certificate mappings to one of the strong types from the Horizon console. If you are using certificate-based authentication, then we recommend that you upgrade to this release to configure certificate mappings. See KB 91595 for details.

IMPORTANT: Starting with this release, Horizon Agent no longer supports Windows Server 2012 R2 in a guest OS for new and existing deployments. See https://learn.microsoft.com/en-us/lifecycle/announcements/windows-server-2012-r2-end-of-support for details.  The use of Windows Server 2012 R2 will continue to be supported for Horizon Connection Server deployments.

WARNING: Microsoft released security updates KB5008383 and KB5020276.  While VMware has determined that KB5008383 does not impact Horizon Full Clones and Instant Clones, KB 5020276 does if you have selected “Allow Reuse of Existing Computer Accounts”.  See KB 92214 for details.

Cloud Pod Architecture

  • When configuring Session Load Distribution for a CPA Global Entitlement, administrators can now choose to distribute based on Load Index as an alternative to Session Count. For more information, see Cloud Pod Architecture in Horizon 8.

Virtual Desktops & Applications

  • This release supports Windows 10 and 11 Guest Operating Systems. See KB 78714.

  • Windows 10 and Windows 11 Guest OS upgrades can be applied to full clones while leaving Horizon Agent installed in-place.  See KB 2148176 for further details and caveats.

  • Horizon 8 on VMware Cloud on AWS now supports vTPM for both full clones and instant clones. See KB 58539.

  • Administrators have the option to accept the SSL Certificate Thumbprint when adding or editing an App Volumes Manager server through Horizon Console.

  • VMs are now tagged as “Forensic” and protected in vCenter Server when they are placed on forensic hold. This protection prevents the accidental deletion of VMs from vCenter Server. VMs will be untagged and unprotected once the forensic hold is removed.

  • Customers facing instant-clone customization errors in their multi-site and multi-domain controller environments no longer have to configure site names manually to avoid such errors. The instant-clone provisioning workflow can now leverage Microsoft Sysprep customization to automatically select sites for computer account creation and to perform domain join in multi-site environments. See

    Enabling Sysprep Guest Customization (without pre-created computer account). See KB 2147129 for details of the original issue.

  • Admins can now set pre-shutdown and post-synchronization scripts when using Microsoft Sysprep customization just as they do with ClonePrep customization. See Guest Customization for Windows Instant Clones in VMware Horizon 8 for details.

  • Desktops will now show the status as ‘In progress’ instead of ‘Provisioned’ when undergoing restart/reset operation in Horizon Console. For more on all the status that a desktop goes through during restart/reset please see the Windows Desktops and Applications in Horizon 8 guide.

  • Customers who cannot move to instant clones from linked clones in case the user data is tied to the desktops can now upgrade to Horizon 8 and still continue to use linked clone desktops with restrictions from Horizon 8 console. Linked clone desktops used in Horizon 8 are called ‘salvaged linked clones’. View Composer is not available in Horizon 8 and these desktops cannot be recomposed and new desktops cannot be added to the existing pool. This option enables customers to plan their move to instant clones while using better options for their data persistence needs.

  • Admins can now use the UI to recreate desktops from detached persistent disks. The bulk recreate feature (API only) is also scale-tested for smoother migration of persistent disks from Horizon 7 to Horizon 8 environments. This update also has improved error handling for all persistent disk workflows. See KB 93091 for details.

    Persistent disks are not available for Linux based virtual machines as this feature uses Windows specific APIs.

  • Administrators can select the option Enable Application Launch Limit for an application pool to restrict each user to launching only one instance of that application through Horizon Client.  This option can also be selected for a Global Application Entitlement.

VMware Horizon Connection Server On-Premises

  • Customers now can run Certificate Revocation List checks at Connection Servers for incoming brokering requests.

  • Horizon Universal License customers can now use Workspace One Intelligence to monitor Horizon Connection Servers, UAG, and Horizon Agent.  For more details, see Tracking Monitoring Events. To disable monitoring capability and stop data from flowing to the cloud, contact VMware Global Support.  Note that Horizon Plus licensed customers and non-subscription licensed customers do not have entitlements to Workspace One Intelligence.

VMware Horizon Agent 8 2309 for Linux

  • This release adds support for the following Linux distributions:

    • Debian 12.1

    • SUSE Linux Enterprise Desktop (SLED) 15 SP5

    • SUSE Linux Enterprise Server (SLES) 15 SP5

  • This release drops support for the following Linux distributions:

    • Debian 11.5 and 11.6

    • Red Hat Enterprise Linux Workstation 8.7

    • Red Hat Enterprise Linux Server 8.7

    • SLED/SLES 15 SP3

  • Horizon Agent is now supported on physical Linux machines.

  • By default, Horizon Agent uses the VMware greeter in cases where Horizon 8 SSO is deactivated or SSO credentials fail. Administrators can include the --no-vmwgreeter installation parameter to specify use of the Gnome Shell greeter instead in cases where Horizon 8 SSO is deactivated or SSO credentials fail.

  • In the /etc/vmware/viewagent-custom.conf configuration file, the DEMEnable option is now set by default to true.

VMware Horizon Agent 8 2309 for Windows

  • Media Optimization for Microsoft Teams offers give and take control of individual application sharing in VDI and RDSH desktop sessions for VMware Blast display protocol (Windows clients). Overlapping applications obscuring the content of the shared application appear greyed out over the shared application.

  • If you plan to upgrade the Windows 10 or Window 11 Guest OS while leaving Horizon Agent in place, see KB 2148176 for guidance.

  • For the Storage Drive Redirection feature, you can control read/write permissions of the shared drive on the agent side by setting the string value of the Windows registry key HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc.\VMware VDM\SDR\ReadOnly.

  • For the Location Based Printing feature, you can locate a specific printer by label.

  • Universal Printer Driver (EMF) in VMware Integrated Printing supports specific font types.

  • The UNC Path Redirection feature for Microsoft Office now supports redirection of network links from Word, Excel, and PowerPoint applications.

  • Horizon Agent has new mouse cursor processing optimizations which can increase the number of Horizon sessions that can run on a single virtualization host.

  • You can configure URI redirection to open specific local applications between Windows agents and clients by setting an absolute path for the local application and creating URI parameters to redirect the application in the GPO setting Url Redirection App Path Rule.

  • VMware Horizon Blast Extreme protocol now supports Indirect Display Driver Class Extension version 1.6 and newer. This results in better virtual machine consolidation ratio and improved performance with lower CPU utilization on the Windows operating systems.

  • If you have VMware Horizon Cloud Service – next-gen installed in your environment, you can monitor Horizon Agent on Windows desktops by enabling the Horizon Agent Monitoring Service (hzMonService).

VMware Horizon 8 2309 GPO Bundle

  • Horizon GPO Bundle

    You can now control whether the volume level of the audio output device in the virtual desktop should be forwarded and applied to the physical devices on the client host.

Windows OS Optimization Tool for Horizon

  • Supports Windows 11 22H2.

  • Includes additional built-in functions.

  • This release adds support for MDT Environment Automation that simplifies the process of creating an MDT server and setting up the base image. The tool automates the installation of the required applications and configures the Optimization tool MDT plugin.

  • Optimization Tool MDT plugin includes:

    • Ability to gather optimization result reports.

    • Support for importing customized extension to the optimization template.

    • Support for multiple deployment shares.

Horizon Client

  • For client certificates, Horizon 8 administrators can set the Connection Server enforcement state for Windows Client sessions and specify the minimum desired security setting to restrict client connections.

  • The Unlock a Desktop With True SSO and Workspace ONE feature is now supported on Horizon Mac and Linux clients

Horizon RESTful APIs

  • New REST APIs for Application pool, Application icon, Virtual Center summary statistics, UserOrGroupsSummary, Datastore usage, Session statistics, Machines etcetera are available along with existing API updates to create robust automations. For more details, refer to API documentation

VMware Dynamic Environment Manager 2309

  • Dynamic configuration of Horizon FIDO2 web authentication redirection for users.

  • Dynamic configuration of Horizon storage drive redirection for users.

  • Support for configuring non-policy locations in ADMX-based settings.

  • Ability to apply registry settings without users having access to registry editing tools.

  • Updated Components. This release updates the main product components. Application Profiler, Helpdesk Support Tool, and SyncTool are not updated for the 2309 release.

VMware Unified Access Gateway 2309

VMware Unified Access Gateway 2309 provides the following new features and enhancements:

  • Certified support for deploying UAG on Azure in FIPS mode with Smart Card authentication with the Blast Secure Gateway.

  • Added disk usage statistics to the log archive for troubleshooting purposes.

  • Logging improvements.

  • Updates to Photon OS package versions and Java versions.

Supported versions of Windows 10 and Windows 11 on Horizon Agent Including All VDI Clones (Full Clones, Instant Clones, and Linked Clones on Horizon 8 2306)

  • Windows 11 22H2 GAC (Pro, Education, Enterprise) Full support
  • Windows 11 21H2 GAC (Pro, Education, Enterprise) Full support
  • Windows 10 22H2 GAC (Pro, Education, Enterprise) Full support
  • Windows 10 21H2 GAC (Pro, Education, Enterprise) Full support
  • Windows 10 21H1 SAC (Pro, Education, Enterprise) Full support
  • Windows 10 20H2 SAC (Pro,Education,Enterprise) Full support
  • Windows 10 2004 SAC (Pro,Education,Enterprise) Not Supported
  • Windows 10 1909 SAC (Pro,Education,Enterprise) Not Supported
  • Windows 10 1903 SAC and earlier (Pro,Education,Enterprise) Not Supported
  • Windows 10 LTSC 2021 (Enterprise) Full support
  • Windows 10 LTSC 2019 (Enterprise) Full support
  • Windows 10 LTSB 2016 (Enterprise) Not Supported

For more additional information please read this knowledge article

VMware Cloud Connector

Applicable to customers with VMware Horizon Universal Subscription, Horizon Enterprise Plus Subscription, Horizon Standard Plus Subscription, Horizon Apps Universal Subscription, or Horizon Apps Standard Subscription.

The Horizon Cloud Connector virtual appliance is a required component for VMware Horizon to support the management of Horizon pods using Horizon Cloud Service.

Horizon 8 Deployed on Public Cloud SDDCs

Horizon 8 Deployed on Azure VMware Solution

For a list of VMware Horizon 8 features supported on Azure VMware Solution (AVS), see Deploying VMware Horizon 8 on Azure VMware Solution.

Horizon 8 Deployed on VMware Cloud on AWS

For a list of VMware Horizon features supported on VMware Cloud on AWS, see VMware Knowledge Base article 58539.

Horizon 8 Deployed on Google Cloud VMware Engine

For a list of VMware Horizon 8 features supported on Google Cloud VMware Engine, see VMware Knowledge Base article 81922

Horizon 8 Deployed on Oracle Cloud VMware Solution

For a list of VMware Horizon 8 features supported on Oracle Cloud VMware Solution, see VMware Knowledge Base article 88202.

 

VMware App Volumes 4 2309

In this release, we are excited to introduce three remarkable enhancements that transform your virtual machine deployment and management experience.

  • Fast Attach for VMDK Packages (vSphere 8.0 Update 2 Required)

    Experience a significant boost in performance and productivity with Fast Attach for VMDK packages. This feature increases attachment speeds for VMDK packages on VMFS and vSAN storage, resulting in faster login times, quicker app launches, and less load on the vSphere components of your environment.

    The following are the key performance improvements:

    • Twice the speed on VMFS

      Fast Attach for VMDK packages speeds up the attachment of VMDK packages on VMFS storage, providing a more efficient and responsive experience.

    • Three Times Faster on vSAN

      For users utilizing vSAN storage, this feature delivers a threefold increase in attachment speed, making your virtual machine operations seamless and efficient.

    For more information about Fast Attach and the system requirements necessary for this feature, see the Configure and Register the Machine Manager section in the VMware App Volumes Administration Guide.

  • Amazon AppStream 2.0 Support

    We have integrated App Volumes Manager with Amazon AppStream 2.0, offering seamless integration and empowering administrators to leverage the benefits of App Volumes with Amazon AppStream 2.0.

  • AWS Marketplace Availability

    App Volumes Manager is now available in the AWS Marketplace, making it even easier to get started with our free trial. It automatically sets up a database and file shares, allowing for a quick Proof of Concept (PoC). When you are ready, you can easily bring your own enterprise license to activate it.

  • Azure Marketplace Availability

    App Volumes Manager is now available in the Azure Marketplace, offering a streamlined way to access our software. This feature provides a convenient, quick setup with an automatically configured database and file shares, allowing for a hassle-free Proof of Concept (PoC) as you explore the capabilities of App Volumes Manager in the Azure cloud. Should you decide to proceed, you can readily apply your own enterprise license to activate it.

  • Deployment Guides

    To help you get started with these powerful integrations and features, we have prepared comprehensive deployment guides. These guides cover essential topics, including deploying and configuring your own App Volumes Manager and using it in conjunction with:

    • Citrix

    • Azure Virtual Desktop

    • Amazon AppStream 2.0

    The deployment guides provide step-by-step instructions, best practices, and tips to streamline your setup process. You can access these deployment guides at the VMware App Volumes documentation page.

Horizon Client 2309 – new features

VMware Horizon Client 2309 for Android

Horizon Client for Android 2309 includes the following new features.

  • Security enhancements for client login

    If an administrator configures a fixed duration for SSO credentials to be cached, and that duration is exceeded, Horizon Client prompts for authentication when the user starts a new desktop or application. Horizon Client then re-caches the credentials.

  • Support for Android 14

    Horizon Client for Android now supports Android 14.

  • Improved Blast connection failure diagnostic information

    If the Horizon Client for Android is unable to connect to the remote desktop or published application via Blast protocol, a detailed error message is displayed on the user interface. The client log files also include a tag called Blast_Connect_Failure_Alert on lines that contain specific error information about Blast connection failures. For more information about Blast connection failure errors, see VMware KB 91013.

VMware Horizon Client 2309 for ChromeOS

Horizon Client for Chrome 2309 includes the following new features.

  • Security enhancements for client login

    If an administrator configures a fixed duration for SSO credentials to be cached, and that duration is exceeded, Horizon Client prompts for authentication when the user starts a new desktop or application. Horizon Client then re-caches the credentials.

  • Automatically quit Chrome client after a session disconnected in Kiosk mode

    Users operating in Kiosk mode might have pre-configured the Chrome client as an auto-launch app with default servers and applicationId or desktopId. Such users will be immediately transitioned to their selected desktop or application after logging out or disconnecting from a desktop/application, without the need to interact with the server or navigate through the desktops and applications list page.

  • Force enable privacy mode for end users

    You can now enable privacy mode for Horizon Cloud on Azure next-gen. Use this setting to force enable the privacy mode for end users. When this setting is enabled, users must authenticate to login. The user is then directed to the browser logout page when the Horizon client is closed. This setting is disabled when not configured.

  • Support Native Printer redirection

    You can now select printers from the remote desktops and print what you want seamlessly. Printers that do not support PDF printing cannot support native printer redirection on the Chrome client.

  • Support H264 option for Chrome Client

    The Horizon client for Chrome includes a new policy called enableH264 to specify whether the rendering method uses H.264 video mode. This option will only appear in the settings window if you are using a normal display with a ratio greater than 100% and the administrator has not deactivated the feature.

  • Improvements for Real-time audio-video performance

    You can now use the Opus codec to improve the audio performance and enable Discontinuous transmission (DTX) mode to reduce the audio traffic when the participant is silent. The reduction in audio traffic occurs as the audio packet is not transmitted.

VMware Horizon Client 2309 for iOS

Horizon Client for iOS 2309 has the following new features.

  • Security enhancements for client login

    If an administrator configures a fixed duration for SSO credentials to be cached, and that duration is exceeded, Horizon Client prompts for authentication when the user starts a new desktop or application. Horizon Client then re-caches the credentials.

  • Support for iOS/iPadOS 17

    Horizon Client for iOS now supports iOS 17.x and iPadOS 17.x.

  • Improved Blast connection failure diagnostic information

    If the Horizon Client for iOS is unable to connect to the remote desktop or published application via Blast protocol, a detailed error message is displayed on the user interface. The client log files also include a tag called Blast_Connect_Failure_Alert on lines that contain specific error information about Blast connection failures. For more information about Blast connection failure errors, see VMware KB 91013.

  • Multi-monitor mode (external display) on iPad

    You can customize the display topology to make an external monitor serve as an extended display for an iPad.

VMware Horizon Client 2309 for MacOS

Horizon Client for Mac 2309 includes the following new features.

  • Security enhancements for client login

    If an administrator configures a fixed duration for SSO credentials to be cached, and that duration is exceeded, Horizon Client prompts for authentication when the user starts a new desktop or application. Horizon Client then re-caches the credentials.

  • Support for macOS 14

    Horizon Client for Mac now supports macOS 14

  • Added a new Agent GPO for screen-capture blocking

    When the Agent screen-capture blocking GPO is enabled, this new GPO displays so that the user can allow or disallow screen recording of remote desktop or application. This applies to the Mac Client only.

VMware Horizon Client 2309 for Linux

Horizon Client for Linux 2309 includes the following new features.

  • Security enhancements for client login

    If an administrator configures a fixed duration for SSO credentials to be cached, and that duration is exceeded, Horizon Client prompts for authentication when the user starts a new desktop or application. Horizon Client then re-caches the credentials.

  • RPM client installer

    The Horizon Client for Linux installer is now available in .rpm format. The RPM installer supports the installation of core client features only.

  • Full feature support in Debian installer

    The Debian installer for Horizon Client now allows you to install all of the following remote experience features:

    • Real-Time Audio-Video

    • VMware Integrated Printing

    • USB redirection

    • Smart card redirection

    • Multimedia redirection

    • Client drive redirection

    • File type association

    • URL redirection

    • HTML5 multimedia redirection

    • Browser content redirection

    • Microsoft Teams Optimization

  • Horizon Client can monitor the network quality during remote sessions and display a notification message if it detects network instability due to high latency. You can turn off these notifications using the Disable network state display setting in the VMware Blast configuration screen.

VMware Horizon Client 2309 for Windows

Horizon Client for Windows 2309 includes the following new features:

  • Security enhancements for client login

    If an administrator configures a fixed duration for SSO credentials to be cached, and that duration is exceeded, Horizon Client prompts for authentication when the user starts a new desktop or application. Horizon Client then re-caches the credentials.

  • Privacy mode for VMware Horizon Cloud Service – next-gen

    Administrators can now configure privacy mode for end users in a VMware Horizon Cloud Service – next-gen environment. With privacy mode enabled, users must authenticate to log into Horizon Client and are redirected to the identity provider (IDP) logout page upon disconnecting from the current server or exiting the client.

  • Updated OS support

    • Beginning with this release, Horizon Client is supported on Windows 11 2023 Update (also known as Windows 11, version 23H2).

    • Beginning with this release, Horizon Client is no longer supported on Windows Server 2012 R2.

  • Support for Windows 11 ARM64 devices

    Horizon Client for Windows is supported on Windows 11 ARM64 devices with ARM64EC (Emulation Compatible). For more information about ARM64EC, refer to Arm64EC – Build and port apps for native performance on Arm. The following ARM64-based devices were tested:

    • Lenovo ThinkPad x13s

    • Microsoft Surface Pro X

    The following client features are supported on Windows 11 ARM64 devices with Emulation Compatible for this release:

    • VMware Integrated Printing (VIP)

    • Real-Time Audio-Video

    • USB Redirection

    • Fast Identity Online (FIDO2)

    • URL Content Redirection

    • Terminal Services Multimedia Redirection

    • UNC Path Redirection

    • Clipboard or DND or Feature Pack Redirection

    • TSDR

    • Scanner Redirection

    • Storage Drive Redirection

    • RDE plugin

    • Horizon client

    • Blast networking

  • End of support for Windows 10 ARM64 devices

    Beginning with this release, Horizon Client is no longer supported on ARM64 devices running Windows 10. Horizon Client continues to be supported on ARM64 devices running Windows 11.

  • Enable Keylogger blocking

    You can now configure the keylogger blocking feature on your Windows Client device to secure and block any malware from capturing your keystrokes when you are using a remote desktop or application.

  • Enhancements to speaker configuration

    You can now handle multiple audio output devices on your Horizon Windows Client device. Use the Preferred Speakers option to select the preferred speaker. When you select All you can use multiple speakers and when you select Default you can use only the default speaker of the client.

  • Primary monitor for remote desktops

    In a multiple-monitor configuration, Horizon Client now honors the primary monitor in the client configuration when displaying remote desktops. If the Horizon Client monitor selection includes the client system’s primary monitor, that monitor is used as the primary monitor for the remote desktop. If the monitor selection does not include the client system’s primary monitor, the top left monitor in the client configuration is used as the primary monitor for the remote desktop.

  • Echo cancellation in audio/video meetings

    To cancel any echo that might be present while using a microphone in an audio or video meeting, you can enable Acoustic Echo Cancellation (AEC) from the client registry.

VMware Horizon Client 2309 for HTML5

HTML Access 2309 includes the following new features:

  • Improvements for Real-time audio-video performance

    You can now enable Discontinuous transmission (DTX) mode to reduce the audio traffic when the participant is silent. The reduction in audio traffic occurs as the audio packet is not transmitted.

Source

Leave a Reply

Your email address will not be published. Required fields are marked *

Turn on pictures to see the captcha *