Quick Start
Get up and running in just a few steps:
Double-click HorizonAdvisor.bat or open PowerShell and run:
.\Start-HorizonAdvisor.ps1
The main menu window appears with three options:
- Pre-Check Validations — Validate your infrastructure
- AD LDS Operations — Manage user preference data and partitions
- Manage Secure Gateway — Enable/disable gateway services
Each tool guides you through required inputs and confirmations.
System Requirements
Before you get started, make sure your system meets these minimum requirements:
| Requirement | Details |
|---|---|
| Operating System | Windows (Server or client) with network access to a Horizon Connection Server |
| PowerShell | Windows PowerShell 5.0 or later (5.1 recommended). The graphical interface runs in STA mode automatically. |
| Supported Horizon versions | Pre-Check validates target versions from 2006 through 2606. Partition Migration requires the environment to be upgraded to 2606 or later first. |
| Permissions | A domain user account with local administrator privileges on the Connection Server machine and Horizon Full Administrator role. |
| AD module (RSAT) | The RSAT-AD-PowerShell feature is required only for Active Directory checks and only on the machine that performs them. If you run the tool as a domain user account with local administrator privileges, it can install the feature automatically. |
| Network Access | HTTPS (port 443) to the Horizon Connection Server; ADWS (port 9389) to a domain controller for AD checks; WinRM to target servers for remote/multi-server Pre-Check. |
| Browser (for PDF export) | Microsoft Edge (Chromium) or Google Chrome — optional, used to convert HTML reports to PDF |
Using the Graphical Interface
The Main Menu Window
When you launch Horizon Advisor without parameters, you see the main menu with a dropdown list of three tools. Pick a tool, read its description, then click Launch:
Pre-Check Validations
Validate your environment against Horizon requirements, including Active Directory, vCenter, Server, and LDAP settings.
AD LDS Operations
Clean up stale user preference data and manage Horizon partition migrations.
Manage Secure Gateway
Enable or disable PCoIP and BLAST Secure Gateway services on the Horizon Connection Server.
How to Use the UI
Click the dropdown to see all available options.
The panel below the dropdown explains what the selected tool does.
The tool opens in a new window or console.
Launching Tools Directly from PowerShell
You can skip the main menu and launch tools directly using command-line parameters:
# Open the Pre-Check Validations tool
.\Start-HorizonAdvisor.ps1 -Flow precheck
# Open the AD LDS Operations menu
.\Start-HorizonAdvisor.ps1 -Flow 'ADLDS Operation'
# Open the Secure Gateway Manager menu
.\Start-HorizonAdvisor.ps1 -Flow 'Manage Security Gateway'
Pre-Check Validations
Use Pre-Check to validate that your infrastructure meets all requirements for Omnissa Horizon before you install or upgrade. It checks your Active Directory configuration, vCenter compatibility, server settings, LDAP connectivity, and API access, then generates a detailed report with pass/fail/warning results.
Validation Types
| Type | What It Checks | Required Inputs |
|---|---|---|
| Active Directory | Forest & domain functional levels, AD schema compatibility, DNS settings, and other AD prerequisites | AD FQDN, Target Horizon version |
| vCenter | vCenter version compatibility and configuration requirements | vCenter FQDN, vCenter version, Target Horizon version |
| Server | Local OS version, Connection Server settings, and Horizon-specific server requirements | Target Horizon version |
| LDAP | Authenticates to the Horizon REST API and validates LDAP configuration on the Connection Server | Admin username, domain, password (securely prompted), Target Horizon version |
| Capacity Provider | Validates a capacity provider (e.g. Nutanix Prism Central, Amazon WorkSpaces Core) — DNS resolution, reachability, and, where applicable, provider version. Provider types are data-driven from CapacityProvider.json. |
Provider type, provider FQDN, provider version (when applicable), Target Horizon version |
| Run All | Runs all four validations and produces a single combined report | All of the above |
Execution Modes
Pre-Check can run against the local machine or fan out to other servers. The Execution Mode (top of the form) controls where the checks run:
| Mode | What it does |
|---|---|
| Local Server | Runs all checks on the machine you launched from. This is the default. |
| List of Servers (CSV) | Runs server/AD/vCenter checks on the remote servers listed in a CSV (over WinRM), then merges the results into a single report. |
| Local POD Servers | Discovers the Connection Servers in the local POD and validates each of them. |
| CPA Federation | Discovers every POD in a Cloud Pod Architecture federation (via the global partition) and validates the servers pod-by-pod. |
Active Directory Module (RSAT-AD-PowerShell)
The domain-level AD checks (forest/domain functional level, read-write domain controller, DC operating system) use the ActiveDirectory PowerShell module, which needs RSAT-AD-PowerShell and a Kerberos ticket to reach the domain controller's ADWS endpoint.
- Local mode (interactive): if the module is missing, the tool offers to install it (Yes/No). Choose Yes to install it and continue.
- Remote / multi-server modes: the domain-level checks run on the orchestrator (the box you launched from, which has direct AD access) and are installed automatically only when you are an administrator; otherwise those specific rows are skipped with a clear message. Remote target servers do not have RSAT — they run only DNS reachability checks.
TLS Certificate Prompt
For LDAP and API validations, Horizon Advisor connects to the Connection Server over HTTPS. If the server uses a self-signed or untrusted certificate, a prompt shows the certificate details:
Untrusted TLS certificate detected for https://<server>/rest/...
Subject : CN=<server>
Issuer : CN=<server>
Thumbprint: XXXX...
Valid From: ... Valid To: ...
Certificate appears to be self-signed.
[1] Accept this certificate for this run only
[2] Reject and stop the request
-AcceptSelfSignedCertificate in non-interactive mode to suppress the prompt in automation.Understanding Reports
After a validation completes, an HTML report (and PDF if a supported browser is available) is generated automatically.
Summary Section
| Item | Description |
|---|---|
| Validation Type | The type of check performed |
| Target Horizon Version | The version validated against |
| Execution Time | When the validation ran |
| Total Checks | Total number of individual checks performed |
| Passed | PASS Checks that met requirements |
| Warnings | WARN Checks flagged for review |
| Failed | FAIL Checks that did not meet requirements |
| Skipped | SKIP Checks not applicable to this configuration |
Detailed Results Table
| Column | Description |
|---|---|
| Check Key | The specific requirement being validated |
| Status | PASS WARN FAIL SKIP |
| Details | The current detected value or state |
| Recommended | For FAIL and WARNING items — the recommended value or corrective action |
Report Location
%ProgramData%\Omnissa\Horizon\logs\HorizonAdvisor\PreCheckReports\
| Validation | HTML Filename | PDF Filename |
|---|---|---|
| Active Directory | AD_Precheck_Report.html | AD_Precheck_Report.pdf |
| vCenter | vCenter_Precheck_Report.html | vCenter_Precheck_Report.pdf |
| Server | Server_Precheck_Report.html | Server_Precheck_Report.pdf |
| LDAP | LDAP_Precheck_Report-<timestamp>.html | LDAP_Precheck_Report-<timestamp>.pdf |
| Run All | Complete_PreCheck_Report_<timestamp>.html | Complete_PreCheck_Report_<timestamp>.pdf |
AD LDS Operations
Maintain your Horizon AD LDS partition and manage related services. Selecting AD LDS Operations from the main menu opens a submenu with three operations:
| Option | Operation | What It Does |
|---|---|---|
| 1 | Clean Up Stale Client User Preference Data | Removes pae-Prop objects from the Horizon AD LDS partition that have not been modified within a configurable timeframe (default: 3 months). Helps reclaim space and reduce AD LDS bloat. |
| 2 | Partition Migration Operations | Orchestrates Local or Global Partition Migration to the new Horizon 2606+ partition layout, including pre-checks, step-by-step execution, and old-partition cleanup. See Partition Migration. |
| 3 | ADWS State Management | Verify, enable, or disable AD Web Services (ADWS) across the Connection Servers discovered from Horizon LDAP. Unreachable hosts are reported and skipped. See ADWS State Management. |
Cleaning Up Stale User Preference Data
This operation allows you to preview and optionally delete stale user preference objects from AD LDS. Here's how it works:
The tool displays the detected Horizon partition location (DN). Review and confirm it's correct by typing 1.
Option 1 — Preview (Recommended First Step)
See how many stale objects exist without deleting anything. This is safe to run at any time to check the cleanup impact. No changes are made to AD LDS.
Option 2 — Delete
Actually delete the stale objects. You'll need to confirm the number of objects to be deleted before proceeding.
Enter the number of months to use. Any pae-Prop objects not changed within this timeframe are considered stale. Press Enter to use the default of 3 months.
For Preview: You see the total count of stale objects found.
For Delete: Objects are removed in batches, with progress shown on screen. A final total count is displayed when complete.
- Always run Option 1 (Preview) first to see what will be deleted.
- AD LDS operations must be run directly on the Horizon Connection Server.
- Ensure you have an AD LDS backup before deleting user preference data.
- The deletion operation is permanent — deleted objects cannot be recovered.
Partition Migration
Partition Migration updates your Horizon AD LDS application partition from the legacy naming scheme to the new scheme introduced in recent Horizon releases. It is a guided, step-by-step operation you run directly on a Horizon Connection Server.
Before you begin
- Upgrade Horizon to 2606 or later before running.
- If you use Omnissa Access, upgrade the connector so it supports the new partition name.
- Run during a maintenance window — avoid pool changes, entitlement changes, and desktop/app launches while migration is in progress.
- Confirm there are no replication issues (check the Horizon Console dashboard).
- Sign in with a domain user that is a local administrator on the Connection Server and a Horizon Full Administrator.
Using the Partition Migration screen (3 phases)
Choose a Task (Local, Global, or Old Partition Cleanup) and enter your Horizon Administrator Username, Domain, and Password, then click Run Pre-checks.
Results appear in the log area at the bottom. The step buttons stay locked until the pre-checks pass. Changing the Task re-locks the steps so you can't run steps for the wrong task.
Once pre-checks pass, the step buttons appear — run them top to bottom.
The three tasks
| Task | When to use it |
|---|---|
| Local Partition Migration | The standard migration for your POD's local partition. Start here. |
| Global Partition Migration | Only when Cloud Pod Architecture (CPA) is enabled, and only after the new local partition is already in use. |
| Old Partition Cleanup | Run last, after migration is confirmed, to remove the legacy partition data (requires an explicit confirmation checkbox). |
Local Partition Migration steps
Once pre-checks pass for the Local task, the five steps unlock. Run them top to bottom:
| Step | What it does |
|---|---|
| 1. Validate prerequisites and prepare for migration | Runs the prerequisite checks and, when CPA is enabled, sets up the global partition. |
| 2. Prepare current pod for migration and disable pod | Prepares the pod and disables the connection servers — you're asked to confirm because this takes the pod offline for brokering. |
| 3. Initiate pod migration | Creates and populates the new local partition (not yet active). |
| 4. Switch pod to Horizon local partition | Makes the new local partition active. |
| 5. Validate and enable current pod | Confirms the new local partition is in use and re-enables the connection servers. |
Global Partition Migration steps
Global migration is only for environments with CPA enabled, and only after the local migration is complete and in use. The screen groups the forward-migration steps and the recovery (revert) steps under a distinct Revert heading:
| Step | What it does |
|---|---|
| 1. Initiate global partition migration for the federation | Migrates the global partition data. |
| 2. Switch federation to Horizon global partition | Makes the new global partition active. |
| 3. Validate Horizon global partition in use | Confirms the new global partition is in use. |
| Revert (recovery) — run only to undo the global migration; always asks for confirmation first. | |
| 1. Revert federation to the old global partition | Rolls the federation back to the old global partition. |
| 2. Validate the old global partition is in use | Confirms the old global partition is back in use. |
ADWS State Management
This operation verifies, enables, or disables AD Web Services (ADWS) across the Connection Servers discovered from Horizon LDAP. ADWS (port 9389) is what the tool's Active Directory checks rely on. Hosts that can't be reached are reported and skipped rather than failing the whole run.
Manage Secure Gateway Service
Use this tool to enable or disable the PCoIP Secure Gateway and BLAST Secure Gateway services on your Horizon Connection Server. Secure Gateways allow clients to connect securely from untrusted networks.
| Option | Action |
|---|---|
| 1 | Enable PCoIP Secure Gateway |
| 2 | Disable PCoIP Secure Gateway |
| 3 | Enable BLAST Secure Gateway |
| 4 | Disable BLAST Secure Gateway |
| 5 | Enable both PCoIP and BLAST Secure Gateway |
| 6 | Disable both PCoIP and BLAST Secure Gateway |
| 7 | Exit to main menu |
How to Use
-Flow 'Manage Security Gateway').
PCoIP and BLAST are protocols for remote desktop connections. Secure Gateways encrypt these connections when clients connect from outside your trusted network, providing an additional layer of security.
Automation & Scripting (Command-Line Mode)
For automated runs in scripts, scheduled tasks, or CI/CD pipelines, you can run Horizon Advisor entirely from the command line without any interactive prompts using the -Flow precheck option.
Syntax
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation <type> -TargetHorizonVersion <version> [options]
Parameters
| Parameter | Required? | Description |
|---|---|---|
-Flow | Yes | For automated pre-check, must be precheck. Also accepts 'ADLDS Operation' and 'Manage Security Gateway' to open those console menus. |
-Validation | Yes (precheck) | activedirectory, vcenter, server, ldap, capacityprovider, or all |
-TargetHorizonVersion | Yes (except ldap-only) | Target Horizon version, e.g. 2606 |
-ExecutionMode | No | Local (default), Remote, LocalPOD, or CPACluster — controls where checks run |
-AdFqdn | For activedirectory / all | Active Directory FQDN |
-VCenterFqdn | For vcenter / all | vCenter FQDN |
-VCenterVersion | For vcenter / all | vCenter version, e.g. 8.0.2 |
-CapacityProviderType | For capacityprovider | Provider type from CapacityProvider.json, e.g. Nutanix_PrismCentral, Amazon_WorkSpaces_Core |
-CapacityProviderFqdn | For capacityprovider | FQDN of the capacity provider endpoint |
-CapacityProviderVersion | When applicable | Provider version (omit for providers that have no version check) |
-HorizonAdminUsername | For ldap / all | Horizon Administrator username |
-HorizonDomain | For ldap / all | Horizon domain |
-HorizonAdminPassword | For ldap / all (automated) | Horizon Administrator password as a SecureString. If omitted, the password is securely prompted at runtime. |
-AcceptSelfSignedCertificate | No | Suppresses the TLS certificate prompt — accepted without user interaction |
-Help | No | Displays command-line help and examples |
Examples
Server validation:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation server -TargetHorizonVersion '2503'
Active Directory validation:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation activedirectory `
-AdFqdn 'dc.corp.example.com' -TargetHorizonVersion '2503'
vCenter validation:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation vcenter `
-VCenterFqdn 'vcenter.corp.example.com' -VCenterVersion '8.0.2' -TargetHorizonVersion '2503'
LDAP validation — password prompted securely at runtime:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation ldap `
-HorizonAdminUsername 'admin' -HorizonDomain 'corp'
LDAP validation — accept self-signed certificate without prompt:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation ldap `
-HorizonAdminUsername 'admin' -HorizonDomain 'corp' -AcceptSelfSignedCertificate
Run all validations:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation all `
-AdFqdn 'dc.corp.example.com' `
-VCenterFqdn 'vcenter.corp.example.com' -VCenterVersion '8.0.2' `
-TargetHorizonVersion '2503' `
-HorizonAdminUsername 'admin' -HorizonDomain 'corp'
Capacity Provider validation (Nutanix Prism Central):
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation capacityprovider `
-CapacityProviderType 'Nutanix_PrismCentral' -CapacityProviderFqdn 'prism.corp.example.com' `
-CapacityProviderVersion 'pc.7.5' -TargetHorizonVersion '2606'
Run all validations against remote servers (over WinRM):
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation all -ExecutionMode Remote `
-AdFqdn 'dc.corp.example.com' `
-VCenterFqdn 'vcenter.corp.example.com' -VCenterVersion '8.0.2' `
-TargetHorizonVersion '2606' `
-HorizonAdminUsername 'admin' -HorizonDomain 'corp'
Open AD LDS Operations menu:
.\Start-HorizonAdvisor.ps1 -Flow 'ADLDS Operation'
Open Secure Gateway Manager menu:
.\Start-HorizonAdvisor.ps1 -Flow 'Manage Security Gateway'
Password Handling for Scheduled/Automated Tasks
When running Horizon Advisor automatically (in a scheduled task or CI/CD pipeline), you usually can't provide an interactive password prompt. Use the -HorizonAdminPassword parameter with a PowerShell SecureString to automate password entry.
SecureString objects using your organization's credential management solution (e.g., password vault, secrets manager, Azure Key Vault, etc.).Example: If you have a SecureString stored in a variable called $securePassword, run:
.\Start-HorizonAdvisor.ps1 -Flow precheck -Validation ldap `
-HorizonAdminUsername 'admin' -HorizonDomain 'corp' `
-HorizonAdminPassword $securePassword
Getting Help & Troubleshooting
Getting Command-Line Help
To see all available command-line options, parameters, and examples directly from PowerShell:
.\Start-HorizonAdvisor.ps1 -Help
Where to Find Logs and Reports
When Horizon Advisor runs, it creates detailed logs and saves reports to:
%ProgramData%\Omnissa\Horizon\logs\HorizonAdvisor\
This folder contains:
- PreCheckReports/ — HTML and PDF validation reports
- Logs/ — Operation logs and debug information
Common Issues
❌ "Horizon Connection Server installation not detected"
You're trying to run AD LDS or Secure Gateway operations on a non-Connection Server machine. These tools must be run directly on the Connection Server.
❌ "Certificate verification failed" during LDAP validation
The Connection Server is using a self-signed or untrusted certificate. This is normal in lab/test environments. When prompted, select option [1] Accept this certificate. To suppress the prompt in automated runs, use the -AcceptSelfSignedCertificate flag.
❌ "Access denied" or permission errors
Horizon Advisor requires administrative privileges on the local machine. Run PowerShell as Administrator and try again.
❌ PowerShell execution policy blocks the script
If you see a "cannot be loaded because running scripts is disabled" error, run this command in PowerShell (as Administrator):
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
Questions or Issues?
For additional help:
- Consult the logs in
%ProgramData%\Omnissa\Horizon\logs\HorizonAdvisor\ - Review the
-Helpoutput for command-line usage - Check the Omnissa documentation or support resources