Blog
2 September, 2026
August 12, 2026
Organizations are continually seeking ways to modernize their end-user computing environments while maintaining the management, security, and user experience capabilities they already rely on.
One approach is to combine Omnissa Horizon 8 with Amazon WorkSpaces Core, bringing Horizon’s enterprise VDI management capabilities together with AWS-hosted desktop infrastructure.
While the concept is straightforward, implementing the solution requires several technologies to work together correctly. AWS networking, identity services, IAM permissions, Windows licensing, image management, Horizon infrastructure, and desktop provisioning all become part of the same architecture.
At TeraSky, we recently implemented Omnissa Horizon 8 on Amazon WorkSpaces Core for a customer, giving our team hands-on experience with the complete deployment lifecycle and the integration points between Omnissa Horizon and AWS.
Bringing Horizon and AWS Together
The solution combines multiple architectural layers.
The AWS infrastructure provides the networking and compute foundation, including VPCs, subnets, routing, NAT connectivity, Security Groups, and the supporting EC2 infrastructure.
Directory services connect the environment to Active Directory via AWS Directory Service and the AD Connector, enabling WorkSpaces and Horizon components to integrate with the organization’s existing identity infrastructure.
The Horizon management layer includes the Horizon Connection Server running on Amazon EC2 and, where external access is required, Unified Access Gateway (UAG).
Finally, Amazon WorkSpaces Core provides the underlying desktop capacity that Horizon uses to provision and deliver virtual desktops to users.
Getting these layers to work together requires careful planning around networking, DNS, Active Directory, security policies, IAM permissions, and communication between Horizon and AWS services.
Integrating Amazon WorkSpaces Core with Horizon
One of the key stages of the implementation is connecting Amazon WorkSpaces Core to Horizon as a Capacity Provider.
This enables Horizon to use AWS-hosted WorkSpaces infrastructure while administrators continue to manage desktop pools, assignments, images, and user access through the familiar Horizon management layer.
The integration also introduces several important infrastructure considerations.
For example, the Horizon Connection Server requires the appropriate AWS IAM permissions and network connectivity to communicate with the required AWS services. Directory integration must also be configured correctly so that desktops can authenticate against Active Directory and Horizon can manage the environment successfully.
These dependencies make network design, routing, DNS resolution, Security Group configuration, and IAM architecture critical parts of the deployment rather than secondary infrastructure tasks.

Building the Windows 11 BYOL Image Lifecycle
Another major part of the project involved creating the Windows 11 BYOL golden image used by the Horizon desktop pools.
The image lifecycle spans both AWS and Horizon.
The process begins with an eligible Windows 11 Enterprise image and the appropriate AWS BYOL configuration. The operating system image is brought into AWS and prepared through the AWS image workflow before being converted into an Amazon WorkSpaces-compatible BYOL image.
From there, a WorkSpaces bundle can be created and used to launch a desktop that serves as the basis for the Horizon golden image.
The Horizon Agent is then installed and configured, the desktop is paired with the Horizon environment, and the resulting image and bundle can be used to provision Horizon-managed desktop pools.
This workflow requires coordination between Microsoft licensing requirements, AWS BYOL capabilities, image preparation, Amazon WorkSpaces, and Horizon itself. Understanding the complete image lifecycle is therefore an important part of designing a maintainable production environment.
From Golden Image to Automated Desktop Pools
Once the image lifecycle is established, Horizon can use the Amazon WorkSpaces Core capacity to create Automated Desktop Pools.
Administrators can define the pool configuration, select the appropriate WorkSpaces Core capacity provider and Horizon-enabled bundle, configure provisioning behavior, and choose the required assignment and billing models.
Users or Active Directory groups can then be entitled to the pool and access their desktops through the Horizon Client or browser-based access, depending on the architecture.
For external access, Unified Access Gateway can be incorporated into the design, while internal environments and initial testing scenarios can use direct connectivity to the Horizon infrastructure where appropriate.
The result is an environment where AWS provides the underlying desktop infrastructure while Horizon remains the management and access layer for the VDI environment.
Beyond the Initial Deployment
A production EUC platform is about more than simply provisioning desktops.
During the implementation, we also worked through additional components and operational considerations surrounding the environment, including Omnissa App Volumes, Dynamic Environment Manager (DEM), image management, AWS and Horizon connectivity, and ongoing administrative operations.
App Volumes can extend the architecture with dynamic application delivery, while DEM can provide user environment and personalization management. In an AWS-based design, DEM configuration and profile data can also be hosted using SMB-based storage such as Amazon FSx for Windows File Server, depending on the organization’s architecture.
Operational tooling is equally important. AWS CLI and PowerShell can be used to inspect WorkSpaces, monitor image import processes, verify resources, and automate administrative tasks around the environment.
Real-World Troubleshooting Matters
One of the most valuable aspects of implementing a solution like this in a real customer environment is understanding what happens when the individual components do not behave as expected.
A deployment can involve troubleshooting across several technology domains.
Directory Service failures, for example, may ultimately be caused by DNS, LDAP, Kerberos, or Security Group configuration. Capacity Provider registration problems can originate from IAM permissions or missing outbound connectivity from the Horizon Connection Server.
Similarly, a Horizon Agent that does not register correctly may require investigation across desktop networking, Horizon services, and communication between the WorkSpaces desktop and Connection Server.
The Windows 11 BYOL process introduces its own requirements around licensing, image preparation, AWS configuration, and compatibility.
These are exactly the areas where hands-on implementation experience becomes valuable. The challenge is often not understanding an individual product but understanding the dependencies between all of them.
What We Learned
Deploying Omnissa Horizon 8 on Amazon WorkSpaces Core is ultimately a cross-platform architecture.
A successful implementation requires Horizon, AWS infrastructure, Active Directory, networking, security, Windows image management, and licensing to be treated as parts of a single solution.
Our experience implementing the environment reinforced several important principles: design the network and identity architecture early, validate AWS and Horizon communication before moving into desktop provisioning, understand the complete BYOL image lifecycle, and treat operational troubleshooting as part of the architecture from the beginning.
It also demonstrated how organizations can combine their existing Horizon knowledge and operational model with AWS-based desktop infrastructure rather than treating cloud-hosted desktops as an entirely separate EUC platform.
Planning Horizon on Amazon WorkSpaces Core?
For organizations already using Omnissa Horizon, evaluating a move toward AWS-hosted desktop infrastructure, or exploring Amazon WorkSpaces Core as part of their EUC strategy, the architecture introduces significant opportunities, but also requires experience across both technology stacks.
At TeraSky, we now bring hands-on experience from implementing the solution in a real customer environment, covering the architecture from AWS infrastructure and identity through Horizon integration, Windows 11 BYOL, golden image creation, desktop pool provisioning, application and user environment considerations, and troubleshooting.
If your organization is evaluating Omnissa Horizon 8 on Amazon WorkSpaces Core, planning a proof of concept, or looking to extend an existing Horizon environment into AWS, TeraSky can help you design, validate, and implement the solution.
Contact TeraSky to discuss how Omnissa Horizon on Amazon WorkSpaces Core can fit into your organization’s EUC and cloud strategy.