You are on page 1of 24

Deploying Virtual Desktop Pools by Using RemoteApp and Desktop Connection Stepby-Step Guide

Microsoft Corporation Published: June 2009 Updated: February 2011

Abstract
Virtual desktop pools are roups of identically confi ured !irtual "achines that users can connect to by usin either #e"ote$pp and %esktop Connection or #e"ote %esktop &eb $ccess '#% &eb $ccess() *n this uide+ ,e ,ill set up a !irtual desktop pool and connect to the pool by usin #e"ote$pp and %esktop Connection)

Copyright In ormation
-his docu"ent is pro!ided .as/is0) *nfor"ation and !ie,s e1pressed in this docu"ent+ includin U#2 and other *nternet &eb site references+ "ay chan e ,ithout notice) 3ou bear the risk of usin it) -his docu"ent does not pro!ide you ,ith any le al ri hts to any intellectual property in any Microsoft product) 3ou "ay copy and use this docu"ent for your internal+ reference purposes) 4 2011 Microsoft Corporation) $ll ri hts reser!ed) Microsoft+ $cti!e %irectory+ #e"ote$pp+ &indo,s+ and &indo,s 5er!er are trade"arks of the Microsoft roup of co"panies) $ll other trade"arks are property of their respecti!e o,ners)

Contents
%eployin Virtual %esktop Pools by Usin #e"ote$pp and %esktop Connection 5tep/by/5tep 6uide))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 1 $bstract)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 1 Copyri ht *nfor"ation)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 2 Contents)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 7 %eployin Virtual %esktop Pools by Usin #e"ote$pp and %esktop Connection 5tep/by/5tep 6uide))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 8 $bout this uide))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 8 &hat this uide does not pro!ide))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 8 -echnolo y re!ie,))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 9 5cenario: %eployin !irtual desktop pools by usin #e"ote$pp and %esktop Connection in a test en!iron"ent))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) : 5tep 1: 5ettin Up the Contoso %o"ain))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) ; Confi ure the #% Virtuali<ation =ost ser!er '#%V=/5#V()))))))))))))))))))))))))))))))))))))))))))))))))))))))9 Confi ure the #% Connection >roker ser!er '#%C>/5#V())))))))))))))))))))))))))))))))))))))))))))))))))))10 Confi ure the #% &eb $ccess ser!er '#%&$/5#V()))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))17 5tep 2: *nstallin and Confi urin Virtual Machines))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))19 *nstall the !irtual desktop pool co"puters 'V%P1/C2?- and V%P2/C2?-()))))))))))))))))))))))))))))))1: Confi ure the !irtual "achine for #e"ote %esktop 5er!ices)))))))))))))))))))))))))))))))))))))))))))))))))))))19 5tep 7: Confi urin the Virtual %esktop Pool))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))19 5tep 8: Verifyin the Virtual %esktop Pool Functionality))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))21 $ppendi1 $: Confi urin the Virtual Machine Manually)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))22 #elated topics)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) 28

Deploying Virtual Desktop Pools by Using RemoteApp and Desktop Connection Stepby-Step Guide
About this guide
-his step/by/step uide ,alks you throu h the process of settin up a ,orkin !irtual desktop pool accessible by usin #e"ote$pp and %esktop Connection in a test en!iron"ent) %urin this process+ you ,ill create a test deploy"ent that includes the follo,in co"ponents: $ #e"ote %esktop Virtuali<ation =ost '#% Virtuali<ation =ost( ser!er $ #e"ote %esktop Connection >roker '#% Connection >roker( ser!er $ #e"ote %esktop 5ession =ost '#% 5ession =ost( ser!er in redirection "ode $ #e"ote %esktop &eb $ccess '#% &eb $ccess( ser!er -,o !irtual "achines confi ured in a !irtual desktop pool

-his uide assu"es that you pre!iously co"pleted the steps in the *nstallin #e"ote %esktop 5ession =ost 5tep/by/5tep 6uide 'http:@@ o)"icrosoft)co"@f,link@A2ink*dB18;292(+ and that you ha!e already deployed the follo,in co"ponents: $n #% 5ession =ost ser!er $ #e"ote %esktop Connection client co"puter $n $cti!e %irectory %o"ain 5er!ices do"ain controller 5tep 1: 5ettin Up the Contoso %o"ain 5tep 2: *nstallin and Confi urin Virtual Machines 5tep 7: Confi urin the Virtual %esktop Pool 5tep 8: Verifyin the Virtual %esktop Pool Functionality $ppendi1 $: Confi urin the Virtual Machine Manually

-his uide includes the follo,in topics:

-he oal of a !irtual desktop pool is to pro!ide users ,ith a !irtual desktop that is dyna"ically assi ned fro" a pool of identically confi ured !irtual "achines) Users can connect to a !irtual desktop pool and run pro ra"s and consu"e resources as if they ,ere usin a local client co"puter)

!hat this guide does not pro"ide


-his uide does not pro!ide the follo,in : $n o!er!ie, of #e"ote %esktop 5er!ices) 6uidance for settin up $cti!e %irectory %o"ain 5er!ices or an #% 5ession =ost ser!er) -his infor"ation can be found in the *nstallin #e"ote %esktop 5ession =ost 5tep/by/5tep

Important 6uide 'http:@@ o)"icrosoft)co"@f,link@A2ink*dB18;292() For a do,nloadable !ersion of this docu"ent+ see the *nstallin #e"ote %esktop 5ession =ost 5tep/by/5tep 6uide 'http:@@ o)"icrosoft)co"@f,link@A2ink*dB18;297( in the Microsoft %o,nload Center) *f you ha!e pre!iously confi ured the co"puters in the *nstallin #e"ote %esktop 5ession =ost 5tep/by/5tep 6uide+ you should repeat the steps in that uide ,ith ne, installations) 6uidance for settin up and confi urin a personal !irtual desktop) -his infor"ation can be found in the %eployin Personal Virtual %esktops by Usin #e"ote %esktop &eb $ccess 5tep/by/5tep 6uide 'http:@@ o)"icrosoft)co"@f,link@A2ink*dB18;909() For a do,nloadable !ersion of this docu"ent+ see the %eployin Personal Virtual %esktops by Usin #e"ote %esktop &eb $ccess 5tep/by/5tep 6uide 'http:@@ o)"icrosoft)co"@f,link@A2ink*dB18;90C( in the Microsoft %o,nload Center) 6uidance for i"portin a certificate that is used for di itally si nin the #%P file of the !irtual desktop pool) 6uidance for settin up and confi urin a !irtual desktop pool in a production en!iron"ent) Co"plete technical reference for #e"ote %esktop 5er!ices)

#echnology re"ie$
$ !irtual desktop pool is a roup of identically confi ured !irtual "achines installed on an #% Virtuali<ation =ost ser!er and "ana ed throu h =yper/V Mana er) Users can access the !irtual desktop pool throu h #e"ote$pp and %esktop Connection or #% &eb $ccess) >ecause the !irtual "achines are identically confi ured+ the user sees the sa"e !irtual desktop+ re ardless of ,hich !irtual "achine in the !irtual desktop pool the user connects to) -he follo,in are i"portant considerations ,hen deployin a !irtual desktop pool: Dnsure that the #%V=/5#V co"puter "eets the =yper/V installation prereEuisites 'http:@@ o)"icrosoft)co"@f,link@A2ink*dB1221C7() -he !irtual "achines in a !irtual desktop pool "ust be identically confi ured+ includin ,hich pro ra"s are installed) Virtual desktops can only use &indo,sF client operatin syste"s) 3ou cannot install &indo,s 5er!erF 200C #2 on a !irtual "achine and add it to a !irtual desktop pool) $ !irtual "achine can be a "e"ber of only one !irtual desktop pool at a ti"e) 3ou can "ake "ultiple !irtual desktop pools a!ailable throu h #e"ote$pp and %esktop Connection) -he user sees a different icon for each !irtual desktop pool) Users should not sa!e files on a !irtual "achine that is in a !irtual desktop pool) *f a user lo s off fro" a !irtual "achine in a !irtual desktop pool+ the ne1t ti"e that the user lo s on to the !irtual desktop pool+ the user "i ht be connected to a different !irtual "achine in the !irtual desktop pool) $ user is connected to a !irtual desktop pool in the follo,in ,ay:

1) $ user initiates the connection to the !irtual desktop pool by usin #% &eb $ccess or by usin #e"ote$pp and %esktop Connection) 2) -he reEuest is sent to the #% 5ession =ost ser!er runnin in redirection "ode) 7) -he #% 5ession =ost ser!er runnin in redirection "ode redirects the reEuest to the #% Connection >roker ser!er) 8) -he #% Connection >roker ser!er checks to see if an e1istin session e1ists for the reEuestin user account) *f a session already e1ists+ proceed to step :) *f the session does not e1ist+ proceed to step 9) 9) -he #% Connection >roker ser!er sends a reEuest to the #% Virtuali<ation =ost ser!er to locate and start the !irtual "achine) :) -he #% Connection >roker ser!er returns the !irtual "achine na"e to the #% 5ession =ost ser!er runnin in redirection "ode) ;) -he #% 5ession =ost ser!er runnin in redirection "ode redirects the reEuest to the client co"puter that initiated the connection) C) -he client co"puter connects to the !irtual desktop pool)

Scenario% Deploying "irtual desktop pools by using RemoteApp and Desktop Connection in a test en"ironment
&e reco""end that you first use the steps pro!ided in this uide in a test lab en!iron"ent) 5tep/ by/step uides are not necessarily "eant to be used to deploy &indo,s 5er!er features ,ithout additional deploy"ent docu"entation and should be used ,ith discretion as a stand/alone docu"ent) Upon co"pletion of this step/by/step uide+ you ,ill ha!e a !irtual desktop pool that users can connect to by usin #% &eb $ccess) 3ou can then test and !erify this functionality by connectin to the !irtual desktop pool fro" #% &eb $ccess as a standard user) -he test en!iron"ent described in this uide includes ei ht co"puters connected to a pri!ate net,ork usin the follo,in operatin syste"s+ applications+ and ser!ices:
Computer name &perating system Applications and ser"ices

CG?-G5G/%C #%5=/5#V CG?-G5G/C2?#%V=/5#V #%C>/5#V #%&$/5#V

&indo,s 5er!er 200C #2 &indo,s 5er!er 200C #2 &indo,s ; &indo,s 5er!er 200C #2 &indo,s 5er!er 200C #2 &indo,s 5er!er 200C #2

$cti!e %irectory %o"ain 5er!ices '$% %5(+ %?5 #% 5ession =ost #e"ote %esktop Connection #% Virtuali<ation =ost+ =yper/V #% Connection >roker #% &eb $ccess

Important
Computer name &perating system Applications and ser"ices

V%P1/C2?V%P2/C2?-

&indo,s ;

Virtual "achines

-he co"puters for" a pri!ate net,ork and are connected throu h a co""on hub or 2ayer 2 s,itch) -his step/by/step e1ercise uses pri!ate addresses throu hout the test lab confi uration) -he pri!ate net,ork *% 10)0)0)0@28 is used for the net,ork) -he do"ain controller is na"ed CG?-G5G/%C for the do"ain na"ed contoso)co") -he follo,in fi ure sho,s the confi uration of the test en!iron"ent)

Step '% Setting Up the Contoso Domain


-o prepare your !irtual desktop pool test en!iron"ent in the CG?-G5G do"ain+ you "ust co"plete the follo,in tasks: Confi ure the #e"ote %esktop Virtuali<ation =ost '#% Virtuali<ation =ost( ser!er '#%V=/ 5#V( Confi ure the #e"ote %esktop Connection >roker '#% Connection >roker( ser!er '#%C>/5#V( Confi ure the #e"ote %esktop &eb $ccess '#% &eb $ccess( ser!er '#%&$/5#V( Use the follo,in table as a reference ,hen settin up the appropriate co"puter na"es+ operatin syste"s+ and net,ork settin s that are reEuired to co"plete the steps in this uide) >efore you confi ure your co"puters ,ith static *nternet Protocol '*P( addresses+ ,e reco""end that you first co"plete &indo,s product acti!ation ,hile each of your

co"puters still has *nternet connecti!ity) 3ou should also install any a!ailable critical security updates fro" &indo,s Update 'http:@@ o)"icrosoft)co"@f,link@A2ink*%B8;7;0()
Computer name &perating system re(uirement IP settings D)S settings

CG?-G5G/%C

&indo,s 5er!erF 200C #2

*P address: 10)0)0)1 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1

Confi ured by %?5 ser!er role)

#%5=/5#V

&indo,s 5er!er 200C #2 *P address: 10)0)0)2 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1

Preferred: 10)0)0)1

CG?-G5G/C2?-

&indo,sF ;

*P address: 10)0)0)7 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1

Preferred: 10)0)0)1

#%V=/5#V

&indo,s 5er!er 200C #2 *P address: 10)0)0)8 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1

Preferred: 10)0)0)1

#%C>/5#V

&indo,s 5er!er 200C #2 *P address: 10)0)0)9 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1

Preferred: 10)0)0)1

)ote
Computer name

#o install !indo$s Ser"er 3116 R3


&perating system re(uirement

#o con igure #CP0IP properties


D)S settings

IP settings

#%&$/5#V

&indo,s 5er!er 200C #2 *P address: 10)0)0): 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1

Preferred: 10)0)0)1

Con igure the RD Virtuali*ation +ost ser"er ,RDV+-SRV-o confi ure the #% Virtuali<ation =ost ser!er+ you "ust: *nstall &indo,s 5er!er 200C #2) Confi ure -CP@*P properties) Join #%V=/5#V to the contoso)co" do"ain) *nstall the #% Virtuali<ation =ost role ser!ice) -his ,ill also install the =yper/V role ser!ice) First+ install &indo,s 5er!er 200C #2 on a stand/alone ser!er) 1) 5tart your co"puter by usin the &indo,s 5er!er 200C #2 product C%) 2) &hen pro"pted for a co"puter na"e+ type RDV+-SRV) 7) Follo, the rest of the instructions that appear on your screen to finish the installation) ?e1t+ confi ure -CP@*P properties so that #%V=/5#V has an *P!8 static *P address of 10)0)0)8) 1) 2o on to #%V=/5#V ,ith the #%V=/5#VH$d"inistrator account) 2) Click Start+ click Control Panel+ click )et$ork and Internet+ click )et$ork and Sharing Center+ click Change adapter settings+ ri ht/click .ocal Area Connection+ and then click Properties) 7) Gn the )et$orking tab+ click Internet Protocol Version / ,#CP0IP"/-+ and then click Properties) 8) Click Use the ollo$ing IP address) *n the IP address bo1+ type '121212/) *n the Subnet mask bo1+ type 3442344234421) *n the De ault gate$ay bo1+ type '121212') 9) Click Use the ollo$ing D)S ser"er addresses) *n the Pre erred D)S ser"er bo1+ type '121212') :) Click &5+ and then close the .ocal Area Connection Properties dialo bo1) ?e1t+ Ioin #%V=/5#V to the contoso)co" do"ain)

#o <oin RDV+-SRV to the contoso2com domain

#o install the RD Virtuali*ation +ost role ser"ice

1) Click Start+ ri ht/click Computer+ and then click Properties) 2) Under Computer name7 domain7 and $orkgroup settings+ click Change settings) 7) Gn the Computer )ame tab+ click Change) 8) *n the Computer )ame0Domain Changes dialo bo1+ under 8ember o + click Domain+ and then type contoso2com) 9) Click 8ore+ and in the Primary D)S su i9 o this computer bo1+ type contoso2com) :) Click &5+ and then click &5 a ain) ;) &hen a Computer )ame0Domain Changes dialo bo1 appears pro"ptin you for ad"inistrati!e credentials+ pro!ide the credentials for CG?-G5GH$d"inistrator+ and then click &5) C) &hen a Computer )ame0Domain Changes dialo bo1 appears ,elco"in you to the contoso)co" do"ain+ click &5) 9) &hen a Computer )ame0Domain Changes dialo bo1 appears tellin you that the co"puter "ust be restarted+ click &5+ and then click Close) 10) Click Restart )o$) Finally+ install the #% Virtuali<ation =ost role ser!ice by usin 5er!er Mana er) 1) 2o on to #%V=/5#V as CG?-G5GH$d"inistrator) 2) Click Start+ point to Administrati"e #ools+ and then click Ser"er 8anager) 7) Under the Roles Summary headin + click Add Roles) 8) Gn the :e ore ;ou :egin pa e+ click )e9t) 9) Gn the Select Ser"er Roles pa e+ select the Remote Desktop Ser"ices check bo1+ and then click )e9t) :) Gn the Remote Desktop Ser"ices pa e+ click )e9t) ;) Gn the Select Role Ser"ices pa e+ select the Remote Desktop Virtuali*ation +ost check bo1) C) #e!ie, the infor"ation about addin =yper/V+ click Add Re(uired Role Ser"ices+ and then click )e9t) 9) Gn the Con irm Installation Selections pa e+ click Install) 10) $fter the installation is co"plete+ click Close)

Con igure the RD Connection :roker ser"er ,RDC:-SRV-o confi ure the #% Connection >roker ser!er by usin &indo,s 5er!er 200C #2+ you "ust: *nstall &indo,s 5er!er 200C #2) Confi ure -CP@*P properties) Join #%C>/5#V to the contoso)co" do"ain) *nstall the #% Connection >roker role ser!ice)

#o install !indo$s Ser"er 3116 R3 #o <oin con RDC:-SRV igure #CP0IP to properties the contoso2com domain Confi ure a certificate used to di itally si n the #%P file) $dd the thu"bprint of the certificate used to di itally si n the #%P file to the %efault %o"ain Policy by usin 6roup Policy Mana e"ent) First+ install &indo,s 5er!er 200C #2 as a stand/alone ser!er) 1) 5tart your co"puter by usin the &indo,s 5er!er 200C #2 product C%) 2) &hen pro"pted for a co"puter na"e+ type RDC:-SRV) 7) Follo, the rest of the instructions that appear on your screen to finish the installation) ?e1t+ confi ure -CP@*P properties so that #%C>/5#V has a static *P address of 10)0)0)9) *n addition+ confi ure the %?5 ser!er by usin the *P address of CG?-G5G/%C '10)0)0)1() 1) 2o on to #%C>/5#V ,ith the #%C>/5#VH$d"inistrator account or another user account in the local $d"inistrators roup) 2) Click Start+ click Control Panel+ click )et$ork and Internet+ click )et$ork and Sharing Center+ click Change adapter settings+ ri ht/click .ocal Area Connection+ and then click Properties) 7) Gn the )et$orking tab+ click Internet Protocol Version / ,#CP0IP"/-+ and then click Properties) 8) Click Use the ollo$ing IP address) *n the IP address bo1+ type '1212124) *n the Subnet mask bo1+ type 3442344234421) *n the De ault gate$ay bo1+ type '121212') 9) Click Use the ollo$ing D)S ser"er addresses) *n the Pre erred D)S ser"er bo1+ type '121212') :) Click &5+ and then close the .ocal Area Connection Properties dialo bo1) ?e1t+ Ioin #%C>/5#V to the contoso)co" do"ain) 1) Click Start+ ri ht/click Computer+ and then click Properties) 2) Under Computer name7 domain7 and $orkgroup settings+ click Change settings) 7) Gn the Computer )ame tab+ click Change) 8) *n the Computer )ame0Domain Changes dialo bo1+ under 8ember o + click Domain+ and then type contoso2com) 9) Click 8ore+ and in the Primary D)S su i9 o this computer bo1+ type contoso2com) :) Click &5+ and then click &5 a ain) ;) &hen a Computer )ame0Domain Changes dialo bo1 appears pro"ptin you for ad"inistrati!e credentials+ pro!ide the credentials for CG?-G5GH$d"inistrator+ and then click &5) C) &hen a Computer )ame0Domain Changes dialo bo1 appears ,elco"in you to the contoso)co" do"ain+ click &5) 9) &hen a Computer )ame0Domain Changes dialo bo1 appears tellin you that the

#o add install con the igure the certi a RD certi icate Connection icate thumbprint used :roker to to digitally the role De ser"ice sign ault the Domain RDP Group ile Policy setting co"puter "ust be restarted+ click &5+ and then click Close) 10) Click Restart )o$) ?e1t+ install the #% Connection >roker role ser!ice by usin 5er!er Mana er) 1) 2o on to #%C>/5#V as CG?-G5GH$d"inistrator) 2) Click Start+ point to Administrati"e #ools+ and then click Ser"er 8anager) 7) Under the Roles Summary headin + click Add Roles) 8) Gn the :e ore ;ou :egin pa e+ click )e9t) 9) Gn the Select Ser"er Roles pa e+ select the Remote Desktop Ser"ices check bo1+ and then click )e9t) :) Gn the Remote Desktop Ser"ices pa e+ click )e9t) ;) Gn the Select Role Ser"ices pa e+ select the Remote Desktop Connection :roker check bo1+ and then click )e9t) C) Gn the Con irm Installation Selections pa e+ click Install) 9) $fter the installation is co"plete+ click Close) ?e1t+ confi ure a di ital certificate used to di itally si n the #%P file) 1) Gpen #e"ote %esktop Connection Mana er) -o open #e"ote %esktop Connection Mana er+ click Start+ point to Administrati"e #ools+ point to Remote Desktop Ser"ices+ and then click Remote Desktop Connection 8anager) 2) Under the Virtual Desktops% Resources and Con iguration headin + click Speci y ne1t to Digital Certi icate) 7) Gn the Digital Signature tab+ select the Sign $ith a Digital Certi icate check bo1) 8) Click Select) 9) *n the Con irm Certi icate dialo bo1+ click the certificate that you ,ant to use for si nin the #%P files+ and then click &5) Finally+ you "ust add the thu"bprint of the certificate used to di itally si n the #%P file to the %efault %o"ain 6roup Policy settin ) -his is reEuired so that the trusted publisher ,arnin dialo bo1 is not sho,n to the user each ti"e the personal !irtual desktop is started) 1) 2o on to CG?-G5G/%C as CG?-G5GH$d"inistrator) 2) Gpen 6roup Policy Mana e"ent) -o open 6roup Policy Mana e"ent+ click Start+ point to Administrati"e #ools+ and then click Group Policy 8anagement) 7) D1pand =orest% contoso2com+ e1pand Domains+ and then e1pand contoso2com) 8) #i ht/click De ault Domain Policy+ and then click >dit) 9) ?a!i ate to Computer Con iguration?Policies?Administrati"e #emplates?!indo$s Components?Remote Desktop Ser"ices?Remote Desktop Connection Client)

#o install !indo$s Ser"er 3116 R3

#o <oin con RD!A-SRV igure #CP0IP to properties the contoso2com domain

:) %ouble/click Speci y S+A' thumbprints o certi icates representing trusted 2rdp publishers) ;) 5elect the >nabled option) C) *n the Comma-separated list o S+A' trusted certi icate thumbprints bo1+ type the certificate thu"bprint used to di itally si n the #%P file+ and then click &5)

Con igure the RD !eb Access ser"er ,RD!A-SRV-o confi ure the #% &eb $ccess ser!er by usin &indo,s 5er!er 200C #2+ you "ust: *nstall &indo,s 5er!er 200C #2) Confi ure -CP@*P properties) Join #%&$/5#V to the contoso)co" do"ain) *nstall the #% &eb $ccess role ser!ice)

D1port the 552 certificate and copy it to the CG?-G5G/C2?- co"puter and the !irtual "achines) First+ install &indo,s 5er!er 200C #2 on a stand/alone ser!er) 1) 5tart your co"puter by usin the &indo,s 5er!er 200C #2 product C%) 2) &hen pro"pted for a co"puter na"e+ type RD!A-SRV) 7) Follo, the rest of the instructions that appear on your screen to finish the installation) ?e1t+ confi ure -CP@*P properties so that #%&$/5#V has an *P!8 static *P address of 10)0)0):) 1) 2o on to #%&$/5#V ,ith the #%&$/5#VH$d"inistrator account) 2) Click Start+ click Control Panel+ click )et$ork and Internet+ click )et$ork and Sharing Center+ click Change adapter settings+ ri ht/click .ocal Area Connection+ and then click Properties) 7) Gn the )et$orking tab+ click Internet Protocol Version / ,#CP0IP"/-+ and then click Properties) 8) Click Use the ollo$ing IP address) *n the IP address bo1+ type '121212@) *n the Subnet mask bo1+ type 3442344234421) *n the De ault gate$ay bo1+ type '121212') 9) Click Use the ollo$ing D)S ser"er addresses) *n the Pre erred D)S ser"er bo1+ type '121212') :) Click &5+ and then close the .ocal Area Connection Properties dialo bo1) ?e1t+ Ioin #%&$/5#V to the contoso)co" do"ain) 1) Click Start+ ri ht/click Computer+ and then click Properties) 2) Under Computer name7 domain7 and $orkgroup settings+ click Change settings) 7) Gn the Computer )ame tab+ click Change) 8) *n the Computer )ame0Domain Changes dialo bo1+ under 8ember o + click

#o e9port install the the RD SS. !eb certi Access icate or role the ser"ice RD !eb Access ser"er and copy it to the C&)#&S&-C.)# computer and "irtual machines Domain+ and then type contoso2com) 9) Click 8ore+ and in the Primary D)S su i9 o this computer bo1+ type contoso2com) :) Click &5+ and then click &5 a ain) ;) &hen a Computer )ame0Domain Changes dialo bo1 appears pro"ptin you for ad"inistrati!e credentials+ pro!ide the credentials for CG?-G5GH$d"inistrator+ and then click &5) C) &hen a Computer )ame0Domain Changes dialo bo1 appears ,elco"in you to the contoso)co" do"ain+ click &5) 9) &hen a Computer )ame0Domain Changes dialo bo1 appears tellin you that the co"puter "ust be restarted+ click &5+ and then click Close) 10) Click Restart )o$) ?e1t+ install the #% &eb $ccess role ser!ice by usin 5er!er Mana er) 1) 2o on to #%&$/5#V as CG?-G5GH$d"inistrator) 2) Click Start+ point to Administrati"e #ools+ and then click Ser"er 8anager) 7) Under the Roles Summary headin + click Add Roles) 8) Gn the :e ore ;ou :egin pa e+ click )e9t) 9) Gn the Select Ser"er Roles pa e+ select the Remote Desktop Ser"ices check bo1+ and then click )e9t) :) Gn the Remote Desktop Ser"ices pa e+ click )e9t) ;) Gn the Select Role Ser"ices pa e+ select the Remote Desktop !eb Access check bo1) C) #e!ie, the infor"ation about addin &eb 5er!er '**5( and the #e"ote 5er!er $d"inistration -ools+ click Add Re(uired Role Ser"ices+ and then click )e9t) 9) Gn the !eb Ser"er ,IIS- pa e+ click )e9t) 10) Gn the Select Role Ser"ices pa e+ click )e9t) 11) Gn the Con irm Installation Selections pa e+ click Install) 12) $fter the installation is co"plete+ click Close) Finally+ e1port the self/si ned 552 certificate on #%&$/5#V and copy it to the CG?-G5G/C2?co"puter) 1) Click Start+ click Run+ type mmc and then click &5) 2) Gn the =ile "enu+ click Add0Remo"e Snap-in) 7) *n the Add or Remo"e Snap-ins dialo bo1+ in the A"ailable snap-ins list+ click Certi icates+ and then click Add) 8) *n the Certi icates snap-in dialo bo1+ click the Computer account option+ and then click )e9t)

9) *n the Select Computer dialo bo1+ click .ocal computer% ,the computer this console is running on-+ and then click =inish) :) *n the Add or Remo"e snap-ins dialo bo1+ click &5) ;) *n the Certificates snap/in console+ in the console tree+ e1pand Certi icates ,.ocal Computer-+ e1pand Personal+ and then click Certi icates) C) #i ht/click the certificate RD!A-SRV2contoso2com+ point to All #asks+ and then click >9port) 9) Gn the !elcome to the Certi icate >9port !i*ard pa e+ click )e9t) 10) Gn the >9port Pri"ate 5ey pa e+ ensure that )o7 do not e9port the pri"ate key is selected+ and then click )e9t) 11) Gn the >9port =ile =ormat pa e+ ensure that D>R encoded binary A241B ,2C>R- is selected+ and then click )e9t) 12) Gn the =ile to >9port pa e+ in the =ile name bo1+ click :ro$se) 17) *n the Sa"e As dialo bo1+ in the =ile name bo1+ enter RD!A-SRV+ and then click Sa"e) 18) Gn the =ile to >9port pa e+ click )e9t) 19) Gn the Completing the Certi icate >9port !i*ard pa e+ click =inish) 1:) $fter the certificate e1port has successfully co"pleted+ a "essa e appears confir"in that the e1port ,as successful) Click &5) 1;) Close the Certi icates snap/in) 1C) Copy the certificate+ located at c%?users?administrator2C&)#&S&?Documents?RD!A-SRV2cer on #%&$/5#V+ to the CG?-G5G/C2?- co"puter and the !irtual "achines) 3ou ha!e set up the Contoso do"ain) ?o, you can proceed to 5tep 2: *nstallin and Confi urin Virtual Machines)

Step 3% Installing and Con iguring Virtual 8achines


-he !irtual "achines are confi ured in a !irtual desktop pool) -he !irtual "achines are dyna"ically assi ned to user accounts as they connect to the pool) *n this step+ you ,ill install and confi ure the !irtual "achines) Use the follo,in table as a reference ,hen settin up the appropriate co"puter na"es+ operatin syste"s+ and net,ork settin s that are reEuired to co"plete the steps in this uide)
Computer name &perating system re(uirement IP settings D)S settings

V%P1/C2?-

&indo,s ;

*P address: 10)0)0);

Preferred: 10)0)0)1

#o install !indo$s C on a "irtual machine


Computer name &perating system re(uirement IP settings D)S settings

5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1 V%P2/C2?&indo,s ; *P address: 10)0)0)C 5ubnet "ask: 299)299)299)0 %efault ate,ay: 10)0)0)1 Preferred: 10)0)0)1

Install the "irtual desktop pool computers ,VDP'C.)# and VDP3-C.)#-o confi ure the !irtual "achines that ,ill be used in the !irtual desktop pool+ you "ust co"plete the follo,in tasks: *nstall &indo,s ; on the !irtual "achines) Confi ure -CP@*P properties) Join the !irtual "achine to the contoso)co" do"ain)

*"port the 552 certificate of the #e"ote %esktop &eb $ccess '#% &eb $ccess( ser!er on the !irtual "achines) Dnable the !irtual "achine to support rollback) 1) 2o on to #%V=/5#V as CG?-G5GH$d"inistrator) 2) *nsert the &indo,s ; product %V% into the %V% dri!e on the #%V=/5#V ser!er) 7) Gpen =yper/V Mana er) -o open =yper/V Mana er+ click Start+ point to Administrati"e #ools+ and then click +yper-V 8anager) 8) #i ht/click RDV+-SRV+ point to )e$+ and then click Virtual 8achine) 9) Gn the :e ore ;ou :egin pa e+ click )e9t) :) *n the )ame bo1+ type "dp'-clnt2contoso2com and then click )e9t) ;) Gn the Assign 8emory pa e+ click )e9t) C) Gn the Con igure )et$orking pa e+ in the Connection bo1+ select the !irtual net,ork that contains the other "achines in the contoso)co" do"ain+ and then click )e9t)

#o con igure #CP0IP properties

#o <oin VDP'-C.)# to the contoso2com domain

9) Gn the Connect Virtual +ard Disk pa e+ in the )ame bo1+ type "dp'clnt2contoso2comJ in the Si*e bo1+ type D1 and then click )e9t) 10) Gn the Installation &ptions pa e+ click Install an operating system rom a boot CD0DVD-R&8 dri"e) 11) *n the Physical CD0DVD dri"e bo1+ select the %V% dri!e that contains the &indo,s ; product %V%+ and then click )e9t) 12) Gn the Completing the )e$ Virtual 8achine !i*ard pa e+ re!ie, the installation options+ and then click =inish) 17) *n the Virtual 8achines area+ ri ht/click "dp'-clnt2contoso2com+ and then click Connect) 18) Click Action+ and then click Start) 19) #epeat these steps for the V%P2/C2?- co"puter) ?e1t+ confi ure -CP@*P properties so that V%P1/C2?- has a static *P address of 10)0)0);) *n addition+ confi ure the %?5 ser!er of CG?-G5G/%C '10)0)0)1() 1) 2o on to V%P1/C2?- as a "e"ber of the local $d"inistrators roup) 2) Click Start+ click Control Panel+ click )et$ork and Internet+ and then click )et$ork and Sharing Center) 7) Click Change adapter settings+ ri ht/click .ocal Area Connection+ and then click Properties) 8) Gn the )et$orking tab+ click Internet Protocol Version / ,#CP0IP"/-+ and then click Properties) 9) Click Use the ollo$ing IP address) *n the IP address bo1+ type '121212C) *n the Subnet mask bo1+ type 3442344234421) *n the De ault gate$ay bo1+ type '121212') :) Click Use the ollo$ing D)S ser"er addresses) *n the Pre erred D)S ser"er bo1+ type '121212') ;) Click &5+ and then close the .ocal Area Connection Properties dialo bo1) C) #epeat these steps for the V%P2/C2?- co"puter) Finally+ Ioin V%P1/C2?- to the contoso)co" do"ain) 1) Click Start+ ri ht/click Computer+ and then click Properties) 2) Under Computer name7 domain7 and $orkgroup settings+ click Change settings) 7) Gn the Computer )ame tab+ click Change) 8) *n the Computer )ame0Domain Changes dialo bo1+ under 8ember o + click Domain+ and then type contoso2com) 9) Click 8ore+ and in the Primary D)S su i9 o this computer bo1+ type contoso2com) :) Click &5+ and then click &5 a ain) ;) &hen a Computer )ame0Domain Changes dialo bo1 appears pro"ptin you for

#o import the SS. certi icate or the RD !eb Access ser"er on the "irtual machines ad"inistrati!e credentials+ pro!ide the CG?-G5GH$d"inistrator credentials+ and then click &5) C) &hen a Computer )ame0Domain Changes dialo bo1 appears ,elco"in you to the contoso)co" do"ain+ click &5) 9) &hen a Computer )ame0Domain Changes dialo bo1 appears tellin you that the co"puter "ust be restarted+ click &5+ and then click Close) 10) Click Restart )o$) 11) #epeat these steps for V%P2/C2?-) ?e1t+ i"port the 552 certificate for the #% &eb $ccess ser!er on the V%P1/C2?- and V%P2/ C2?- co"puters) 1) 2o on to V%P1/C2?- as CG?-G5GH$d"inistrator) 2) Click Start+ in the Start Search bo1+ type mmc and then click &5) 7) Gn the =ile "enu+ click Add0Remo"e Snap-in) 8) *n the Add or Remo"e Snap-ins dialo bo1+ in the A"ailable snap-ins list+ click Certi icates+ and then click Add) 9) *n the Certi icates snap-in dialo bo1+ click Computer account+ and then click )e9t) :) *n the Select Computer dialo bo1+ click .ocal computer% ,the computer this console is running on-+ and then click =inish) ;) *n the Add or Remo"e snap-ins dialo bo1+ click &5) C) *n the Certificates snap/in console+ in the console tree+ e1pand Certi icates ,.ocal Computer-+ and then click #rusted Root Certi ication Authorities) 9) #i ht/click the #rusted Root Certi ication Authorities folder+ point to All #asks+ and then click Import) 10) Gn the !elcome to the Certi icate Import !i*ard pa e+ click )e9t) 11) Gn the =ile to Import pa e+ in the =ile name bo1+ click :ro$se+ and then bro,se to the location ,here you copied the 552 certificate for the #%&$/5#V co"puter) Click &pen+ and then click )e9t) 12) Gn the Certi icate Store pa e+ accept the default option 'Place all certi icates in the ollo$ing store E #rusted Root Certi ication Authorities (+ and then click )e9t) 17) Gn the Completing the Certi icate Import !i*ard pa e+ click =inish) 18) $fter the certificate i"port has successfully co"pleted+ a "essa e appears confir"in that the i"port ,as successful) Click &5) 19) 2o off fro" the V%P1/C2?- co"puter) 1:) #epeat these steps for the V%P2/C2?- co"puter) Finally+ rollback is a feature in #e"ote %esktop 5er!ices that re!erts all chan es "ade by a user to a !irtual "achine ,hen the user lo s off fro" the !irtual "achine)

#o enable rollback on a "irtual machine 1) 2o on to #%V=/5#V as the CG?-G5GH$d"inistrator user account) 2) Gpen =yper/V Mana er) -o open =yper/V Mana er+ click Start+ point to Administrati"e #ools+ and then click +yper-V 8anager) 7) Under Virtual 8achines+ ri ht/click "dp'-clnt2contoso2com+ and then click Snapshot) 8) Under Snapshots+ ri ht/click "dp'-clnt2contoso2com+ and then click Rename) 9) -ype RDVFRollback and then press D?-D#) :) Close =yper/V Mana er) ;) #epeat these steps for the V%P2/C2?- !irtual "achine)

Con igure the "irtual machine or Remote Desktop Ser"ices


3ou can confi ure the !irtual "achine by usin &indo,s Po,er5hell) *f you prefer to confi ure the !irtual "achine "anually+ see $ppendi1 $: Confi urin the Virtual Machine Manually in this docu"ent) -he &indo,s Po,er5hell script does the follo,in on the !irtual "achine: Dnables #e"ote %esktop Dnables #e"ote Procedure Call '#PC( $dds selected users to the #e"ote %esktop Users roup $dds the proper #%P/-CP listener per"issions for the #% Virtuali<ation =ost ser!er $dds a &indo,s Fire,all e1ception for #e"ote %esktop 5er!ices $dds a &indo,s Fire,all e1ception for #e"ote 5er!ices Mana e"ent #estarts the #e"ote %esktop 5er!ices ser!ice

3ou can find the script in the Microsoft -ech?et 5cript Center 'http:@@ o)"icrosoft)co"@f,link@A 2ink*dB1C8C08() -o confi ure the !irtual "achine+ type the follo,in co""ands at the &indo,s Po,er5hell pro"pt: 1) Set->9ecutionPolicy remotesigned E orce+ and then press D?-D#) 2) Con igure-Virtual8achine2ps' ERDV+ost contoso?rd"h-sr" ERDUsers contoso?mskinner+ and then press D?-D#) 3ou ha!e installed and confi ured the !irtual "achines) ?o, you can proceed to 5tep 7: Confi urin the Virtual %esktop Pool)

Step D% Con iguring the Virtual Desktop Pool


*n this step+ ,e ,ill confi ure the !irtual desktop pool) -o do this+ you should do the follo,in :

#o con add RD!A-SRV igure a source to the on RD!A-SRV #S !eb Access #oComputers con igure the group "irtual on RDC:-SRV desktop pool on RDC:-SRV $dd #%&$/5#V to the -5 &eb $ccess Co"puters security roup on #%C>/5#V) Confi ure a source on #e"ote %esktop &eb $ccess '#% &eb $ccess() Confi ure the !irtual desktop pool on the #e"ote %esktop Connection >roker '#% Connection >roker( ser!er '#%C>/5#V() $dd V%P1/C2?- and V%P2/C2?- to the !irtual desktop pool) First+ add the co"puter account obIect of the #% &eb $ccess ser!er '#%&$/5#V( to the -5 &eb $ccess Co"puters security roup on #%C>/5#V) 1) 2o on to #%C>/5#V as CG?-G5GH$d"inistrator) 2) Click Start+ point to Administrati"e #ools+ and then click Computer 8anagement) 7) D1pand .ocal Users and Groups+ and then click Groups) 8) #i ht/click #S !eb Access Computers+ and then click Add to Group) 9) Click Add) :) *n the Select Users7 Computers7 Ser"ice Accounts7 or Groups dialo bo1+ click &b<ect #ypes) ;) *n the &b<ect #ypes dialo bo1+ select the Computers check bo1+ and then click &5) C) *n the >nter the ob<ect names to select bo1+ type rd$a-sr" and then click &5) 9) Click &5 to close the #S !eb Access Computers dialo bo1) ?e1t+ confi ure a source on the #% &eb $ccess ser!er '#%&$/5#V() 1) 2o on to #%&$/5#V as CG?-G5GH$d"inistrator) 2) Click Start+ point to Administrati"e #ools+ point to Remote Desktop Ser"ices+ and then click Remote Desktop !eb Access Con iguration) 7) Click Continue to this $ebsite ,not recommended-) Important -his uide uses a self/si ned certificate for the #% &eb $ccess ser!er) 5elf/ si ned certificates are not reco""ended in a production en!iron"ent) 3ou should use a certificate that is trusted fro" a certification pro!ider ,hen deployin #% &eb $ccess in a production en!iron"ent) 8) *n the Domain?user name bo1+ type C&)#&S&?Administrator) 9) *n the Pass$ord bo1+ type the pass,ord that you specified for CG?-G5GH$d"inistrator+ and then click Sign in) :) Gn the Con iguration pa e+ click An RD Connection :roker ser"er) ;) *n the Source name bo1+ type rdcb-sr" and then click &5) ?e1t+ confi ure the !irtual desktop pool on the #e"ote %esktop Connection >roker '#% Connection >roker( ser!er '#%C>/5#V() 1) 2o on to #%C>/5#V as CG?-G5GH$d"inistrator)

#o con add VDP'-C.)# igure RemoteApp and VDP3-C.)# and Desktop to Connection the "irtual desktop pool 2) Click Start+ point to Administrati"e #ools+ point to Remote Desktop Ser"ices+ and then click Remote Desktop Connection 8anager) 7) *n the $ctions pane+ click Con igure Virtual Desktops !i*ard) 8) Gn the :e ore ;ou :egin pa e+ click )e9t) 9) Gn the Speci y an RD Virtuali*ation +ost Ser"er pa e+ in the Ser"er name bo1+ type rd"h-sr"+ click Add+ and then click )e9t) :) Gn the Con igure Redirection Settings pa e+ in the Ser"er name bo1+ type rdshsr" and then click )e9t) ;) Gn the Speci y an RD !eb Access Ser"er pa e+ click )e9t) C) Gn the Con irm Changes pa e+ click Apply) 9) Clear the Assign personal "irtual desktop check bo1+ and then click =inish) Finally+ add the !irtual "achines 'V%P1/C2?- and V%P2/C2?-( to the !irtual desktop pool) 1) 2o on to #%C>/5#V as CG?-G5GH$d"inistrator) 2) Click Start+ point to Administrati"e #ools+ point to Remote Desktop Ser"ices+ and then click Remote Desktop Connection 8anager) 7) *n the $ctions pane+ click Create Virtual Desktop Pool) 8) Gn the !elcome to the Create Virtual Desktop Pool !i*ard pa e+ click )e9t) 9) Click "dp'-clnt2contoso2com+ hold the C-#2 key+ click "dp3-clnt2contoso2com+ and then click )e9t) :) Gn the Set Pool Properties pa e+ in the Display name bo1+ type C&)#&S& Virtual Desktop Pool) *n the Pool ID bo1+ type C&)#&S&FVDP and then click )e9t) ;) Click =inish) 3ou ha!e confi ured the !irtual desktop pool) ?o, you can proceed to 5tep 8: Verifyin the Virtual %esktop Pool Functionality)

Step /% Veri ying the Virtual Desktop Pool =unctionality


-o !erify the functionality of a #e"ote$pp and %esktop Connection deploy"ent+ you "ust co"plete the follo,in tasks: Confi ure #e"ote$pp and %esktop Connection) Connect to the #e"ote$pp pro ra")

First+ confi ure #e"ote$pp and %esktop Connection) 1) 2o on to CG?-G5G/C2?- as Mor an 5kinner 'CG?-G5GH"skinner() 2) Click Start+ and then click Control Panel)

#o connect to a RemoteApp program by using the Start menu 7) *n the Search Control Panel bo1+ type RemoteApp)

#o enable Remote Desktop

8) Under the RemoteApp and Desktop Connections headin + click Set up a ne$ connection $ith RemoteApp and Desktop Connections) 9) *n the Connection UR. bo1+ type https%00rd$asr"2contoso2com0RD!eb0=eed0$eb eed2asp9+ and then click )e9t) :) Gn the Ready to set up the connection pa e+ click )e9t) ;) Click =inish) Finally+ connect to the #e"ote$pp pro ra" by usin the Start "enu) 1) Click Start+ and then click All Programs) 2) Click RemoteApp and Desktop Connections+ click >nterprise Remote Access+ and then click C&)#&S& Virtual Desktop Pool ,>nterprise Remote Access-) 3ou ha!e successfully deployed and de"onstrated the functionality of a !irtual desktop pool+ by usin the si"ple scenario of connectin to a !irtual desktop pool by usin #e"ote$pp and %esktop Connection) 3ou can also use this deploy"ent to e1plore so"e of the additional capabilities of !irtual desktop pools throu h additional confi uration and testin ) 3ou ha!e co"pleted all the steps) For additional infor"ation+ see $ppendi1 $: Confi urin the Virtual Machine Manually)

Appendi9 A% Con iguring the Virtual 8achine 8anually


Usin the &indo,s Po,er5hell script "entioned in 5tep 7 of this uide is reco""ended) =o,e!er+ the steps can be co"pleted "anually by doin the follo,in : Dnable #e"ote %esktop) $dd the user accounts that ,ill be usin this !irtual "achine to the local #e"ote %esktop Users security roup) $llo, #e"ote #PC) Create a fire,all e1ception to allo, #e"ote 5er!ices Mana e"ent) $dd per"issions to the #%P protocol)

First+ you "ust enable #e"ote %esktop) 1) 2o on to V%P1/C2?- as a "e"ber of the local $d"inistrators roup) 2) Click Start+ ri ht/click Computer+ and then click Properties) 7) Click Remote settings) 8) Under Remote Desktop+ click Allo$ connections only rom computers using Remote Desktop $ith )et$ork .e"el Authentication ,more secure-+ and then click

#o enable add 8organ allo$ Remote the Remote Skinner RPC Ser"ice or toRemote the local 8anagement Desktop Remote Ser"ices Desktop !indo$sUsers =ire$all group e9ception &5) 9) #epeat steps 1 K 8 for the V%P2/C2?- co"puter) ?e1t+ add the user accounts that ,ill be usin this !irtual "achine to the local #e"ote %esktop Users security roup on PV%1/C2?-) *n this uide+ ,e ,ill add Mor an 5kinner) 1) Click Start+ and then click Control Panel) 2) Click System and Security+ click Administrati"e #ools+ and then double/click Computer 8anagement) 7) D1pand .ocal Users and Groups+ and then click Groups) 8) #i ht/click Remote Desktop Users+ and then click Add to Group) 9) Click Add+ and in the Select Users7 Computers7 Ser"ice Accounts7 or Groups dialo bo1+ type contoso?mskinner and then click &5) :) Close the Remote Desktop Users Properties dialo bo1) ?e1t+ allo, #e"ote #PC on V%P1/C2?-) 1) 2o on to V%P1/C2?- as a "e"ber of the local $d"inistrators roup) 2) Click Start+ and in the Search programs and iles bo1+ type regedit2e9e and then press D?-D#) Caution *ncorrectly editin the re istry "ay se!erely da"a e your syste") >efore "akin chan es to the re istry+ you should back up any !alued data on the co"puter) 7) ?a!i ate to =LD3M2GC$2MM$C=*?DH535-DMHCurrentControl5etHControlH-er"inal5er!er) 8) %ouble/click the Allo$RemoteRPC re istry entry) *n the Value data bo1+ type ' and then click &5) 9) Close #e istry Dditor) :) #epeat steps 1 K : for the V%P2/C2?- co"puter) ?e1t+ enable the #e"ote 5er!ice Mana e"ent &indo,s Fire,all e1ception) 1) Click Start+ click Control Panel+ and then click System and Security) 2) Under the !indo$s =ire$all headin + click Allo$ a program through !indo$s =ire$all) 7) 5elect the Remote Ser"ice 8anagement check bo1+ and then click &5) Finally+ you "ust rant the #%V=/5#V co"puter account per"issions to the #%P protocol on V%P1/C2?- and then restart the #e"ote %esktop 5er!ices ser!ice on V%P1/C2?-) -he #%V=/ 5#V co"puter account needs the &*?5-$-*G?MNUD#3+ &*?5-$-*G?M2G6GFF+ and &*?5-$-*G?M%*5CG??DC- per"issions on V%P1/C2?-)

#o add RDP protocol permissions to a "irtual machine 1) Click Start+ point to All Programs+ and then click Accessories) 2) #i ht/click Command Prompt+ and then click Run as administrator) 7) *f the User Account Control dialo bo1 appears+ confir" that the action it displays is ,hat you ,ant+ and then click ;es) 8) $t the co""and pro"pt+ type the follo,in co""ands:
wmic /node:localhost RDPERMISSIONS where TerminalName="RDP-Tcp" wmic /node:localhost RD! O)NT where "*TerminalName=+RDP-Tcp+ or !"" !"" !dd!cco#nt "contoso$rd%h-sr%&"'( TerminalName=+ onsole+, and !cco#ntName=+contoso$$rd%h-sr%&+" Modi-.Permissions /'(

wmic /node:localhost RD!

O)NT where "*TerminalName=+RDP-Tcp+ or !""

TerminalName=+ onsole+, and !cco#ntName=+contoso$$rd%h-sr%&+" Modi-.Permissions 0'(

wmic /node:localhost RD!

O)NT where "*TerminalName=+RDP-Tcp+ or !""

TerminalName=+ onsole+, and !cco#ntName=+contoso$$rd%h-sr%&+" Modi-.Permissions 1'(

Net stop termser%ice Net start termser%ice

9) 2o off the V%P1/C2?- co"puter) -his is reEuired in order for Mor an 5kinner to lo on to the personal !irtual desktop successfully) :) #epeat steps 1 K 9 for the V%P2/C2?- co"puter)

Related topics
5tep 1: 5ettin Up the Contoso %o"ain 5tep 2: *nstallin and Confi urin Virtual Machines 5tep 7: Confi urin the Virtual %esktop Pool 5tep 8: Verifyin the Virtual %esktop Pool Functionality

You might also like