
Virtualization with VMWare Fusion
This is a guide on virtualization with VMWare Fusion.
Check out Audible on Amazon and listen to the newest books!
Introduction to VMware Fusion
VMware Fusion represents a significant advancement in virtualization technology specifically designed for Macintosh computing environments. For organizations that maintain a substantial population of Mac users, VMware Fusion offers a compelling solution that addresses the inherent limitations these users often face when attempting to run operating systems and applications that were not natively designed for the Mac platform. This virtualization product enables multiple operating systems and their associated applications to run simultaneously on a single Mac computer through the use of separate virtual machines, each operating independently within its own isolated environment.
The flexibility that VMware Fusion provides to Mac users cannot be overstated. The product supports an impressive array of over sixty different operating systems, encompassing various versions of Windows, numerous Linux distributions, and a wide range of server operating systems. This extensive compatibility means that organizations can continue to utilize specialized applications that may not have native Mac support by running them within an appropriate virtual machine environment. When a particular application critical to business operations lacks Mac compatibility, VMware Fusion provides the means to deploy that same application through virtualization, thereby eliminating what would otherwise be an insurmountable barrier to productivity.
VMware Fusion holds the distinction of being among the first virtualization products to enable both 32-bit and all major 64-bit operating systems to operate on Mac hardware. The product allows for the strategic allocation of hardware resources from a single physical Mac computer across both the host system, where VMware Fusion itself is installed, and all guest systems running within virtual machines. This resource management capability ensures that each virtual machine receives the computational resources it requires while maintaining the stability and performance of the host operating system.
The architectural similarity between VMware Fusion and VMware Workstation is noteworthy, as both products follow a comparable deployment model. Users begin with their original host operating system, install the virtualization product, and then create virtual machines that can be configured entirely independently from one another according to the specific needs of the organization. However, VMware Fusion distinguishes itself through its design specifically tailored for Mac systems, enhancing compatibility and enabling the seamless operation of operating systems and applications that would otherwise be unavailable to Mac users. Organizations that must support Mac users who require access to otherwise unsupported applications would be well advised to investigate VMware Fusion as a potential solution.
System Requirements for VMware Fusion
Understanding the system requirements for VMware Fusion is essential for ensuring optimal performance and reliability. Like any sophisticated software application, VMware Fusion has specific minimum requirements that must be met to function effectively. Organizations should carefully evaluate their existing Mac hardware against these requirements before deploying the product.
The foundation for running VMware Fusion effectively begins with a 64-bit Intel-based Mac running Mac OS X 10.8 or later. While this represents the minimum requirement, OS X Yosemite is recommended for the best experience and optimal compatibility. The processor should be compatible with Core 2 Duo, Xeon, i3, i5, or i7 processors, or any newer processor that may have been released after these specifications were established. As with any virtualization platform, the general principle applies that higher system specifications yield better performance, particularly when running virtual machines, because the host operating system and all virtual machines must share the resources of a single physical computer. The more resources available, the better the experience will be for all users.
Memory considerations are particularly important when planning a VMware Fusion deployment. A minimum of 2 GB of RAM is required, but 4 GB or higher is strongly recommended. The reasoning behind this recommendation is straightforward: each virtual machine created requires its own memory allocation, and these allocations come from the physical memory installed in the host system. Organizations should plan for memory requirements that account for the host operating system, the VMware Fusion application itself, and each virtual machine that will be running concurrently. More memory is always beneficial in virtualization environments.
Storage requirements must also be carefully considered. The VMware Fusion software itself requires 750 MB of free disk space for installation. Beyond this, each virtual machine requires a minimum of 5 GB of free disk space, though actual requirements will vary based on the operating system and applications installed within each virtual machine. Organizations should plan for generous storage allocations to accommodate current needs and future growth.
Installation media is another essential consideration. To install operating systems on virtual machines, the original source installation files are required. The process involves creating a new virtual machine, allocating resources and defining disk space through the Fusion interface, and then installing the operating system just as one would on a physical computer. This means having access to installation discs or ISO files for each operating system that will be deployed.
For Windows Aero support, which provides the 3D graphics experience for Windows, specific graphics card requirements must be met. An NVIDIA 8600M or better, or an ATI 2600 or better, is required. As with other system components, better graphics card specifications will result in improved responsiveness and visual performance. When creating virtual machines, organizations should aim for the highest specifications possible on the host system to ensure that additional virtual machines can run without excessively draining system resources.
Distinctive Features of VMware Fusion
VMware Fusion offers a range of distinguishing features that set it apart from other virtualization solutions. The product enables seamless integration between the Mac OS X operating system and other operating systems running within virtual machines, along with their associated applications. This integration is achieved through a unified window management system that handles both Mac and guest system applications, allowing users to run their Mac applications and virtual machine applications simultaneously and switch between them at will. Users are not forced to choose between running Mac applications or virtual machine applications; both are available concurrently in an integrated environment.
The product supports application sharing, data sharing, and graphic-intensive application support. Any application running within the Mac environment can access and share information with applications running in virtual machines. Additional features enable guest applications from different operating systems to run as if they were created for the Mac, including USB device support, keyboard mapping, and driverless printing. This means that a user can print from a virtual machine-based application to a printer that is physically connected to the Mac. This level of integration ensures that guest-based applications and Mac-based resources work together seamlessly.
VMware Fusion offers a Mac-friendly interface that incorporates characteristic Mac interface features. Virtual machines can be integrated with Mac OS X to provide features such as Quick Look, Cover Flow, Mac OS X Help, and customizable toolbars. The objective is to make virtual machine applications look and feel as though they were installed directly on the Mac itself, providing a consistent and familiar user experience.
Security and reliability are addressed through features that protect guest operating systems. VMware Fusion enables users to take and store multiple snapshots of each virtual machine, allowing reversion to an earlier snapshot if errors or configuration changes cause problems. Reverting to an earlier snapshot discards any errors or issues that may have occurred. The AutoProtect feature automatically takes snapshots and enables management of virtual machine recovery, ensuring that snapshots are created consistently. Additionally, embedded antivirus and antispyware protection for guest virtual machines helps maintain their security.
For power users, VMware Fusion offers extensive configuration options. These include support for large amounts of RAM, multiple displays, a wide range of supported operating systems, multiple virtual CPUs for intensive applications, and command-line control of virtual machines. Organizations can allocate substantial resources to virtual machines as long as those resources are available on the physical Mac host system. The product effectively supports higher-level, resource-intensive applications while maintaining the flexibility to manage virtual machines according to specific requirements.
Common Implementations of VMware Fusion
VMware Fusion finds application in various typical implementations across different organizational contexts. One of the most common uses involves running Windows and Linux applications on a Mac while continuing to run Mac applications. Both can operate simultaneously, with users able to access all inherent Mac applications alongside guest Windows-based or Linux-based applications without difficulty. The virtual machines run the Windows and Linux operating systems, which in turn support their respective applications, all accessible at the same time. This configuration is particularly valuable in environments with a mix of systems and applications where supporting all of them is necessary. Rather than requiring users to operate separate physical Mac and Windows systems, Fusion combines them on a single system.
Migration capabilities allow organizations to convert existing Windows computers to virtual machines. When separate physical systems exist, the migration system converts the physical computer to a virtual machine that can run on the Mac, enabling decommissioning of the original system once everything has been consolidated onto a single computer. This capability simplifies infrastructure management and reduces the physical footprint required to support diverse computing needs.
VMware Fusion can also be used to create new virtual machines from scratch. When organizations prefer not to convert existing physical systems, they can install a brand new, clean operating system and then install applications, import data, and proceed with configuration as needed. Import functionality allows existing virtual machines created with products such as Parallels Desktop or Microsoft Virtual PC for Mac to be imported into Fusion, enabling immediate use on the new system. The product also supports running 64-bit virtual machines, including server operating systems such as Windows Server, Linux Server, and Mac OS X Server within a virtual machine environment.
VMware Player: Features and Functionality
VMware Player represents an accessible entry point into virtualization technology, offering a free download that anyone can obtain for non-commercial use. Upon installation, users specify that they will use the product for non-commercial purposes only, which is why the application is identified as VMware Player (Non-commercial use only). The interface presents a home page where users can choose to create a new virtual machine using the Player only. While typically implemented in a more read-only fashion, the Player does allow for virtual machine creation when the user has the original media for the operating system to be installed or an ISO file of the original disk.
In enterprise environments, the typical scenario involves a virtual machine file being supplied by administration. Users can open an existing virtual machine, though they may not be able to make changes to it, as administrators would have configured it in a specific state that they do not want modified. When users create their own virtual machines, they retain the ability to make configuration changes.
The process of creating a virtual machine in VMware Player involves several steps. Users must have either the original installer disc, which the software will read from the physical DVD RW drive, or an installer disc image file (ISO). The software can detect which operating system is included in the ISO file. A third option allows users to install the operating system later, creating a blank virtual hard disk onto which the operating system can be installed subsequently.
During the creation process, users can enter the Windows product key if available, though Windows 7 x64 allows installation without a product key, requiring activation later. Different editions can be selected depending on the media available. Password protection is optional. The virtual machine can be named according to user preference. Virtual hard disk space allocation is specified, with options to store the virtual disk as a single file or split it into multiple files. Splitting the disk makes it easier to move the virtual machine to another computer but may reduce performance with very large disks.
Once the configuration is complete, a summary is displayed, and users can customize hardware settings including memory specifications and processor specifications before clicking Finish to launch the operating system installation. The installation proceeds just like any other operating system installation, but within the virtual environment. Once complete, users have a functioning operating system with standard applications and can work with the virtual machine like any other system.
Power management options for virtual machines include shutting down the guest, suspending the guest to pause it, or restarting the guest. When a virtual machine is powered off, users can edit virtual machine settings, which is not possible while the machine is running. Launching a virtual machine again simply requires clicking the play virtual machine option. VMware Player is a relatively simple application that is free to obtain and allows users to create their own virtual machines or access existing ones. The application includes a link to upgrade to VMware Workstation for those who require more advanced features.
Common Uses for VMware Player
VMware Player supports various common implementations and uses across different scenarios. One typical use involves running a software suite developed for Linux while using a Windows operating system on a PC. Linux can run in a virtual machine on the Windows host, facilitating data sharing between host and guest machines. Applications running in the virtual machine can access data on the host machine, and vice versa. When two different applications are inherently incompatible with each other in terms of running on the same operating system, VMware Player allows the incompatible application to run in its own native operating system within the virtual machine. The reverse scenario is equally valid: running a software suite developed for Windows while using a Linux-based operating system on a PC. In either case, users can access applications developed for their operating system from a separate, inherently incompatible operating system.
Software distribution is another area where VMware Player provides value. Preconfigured software can be distributed in an already set up virtual machine. Because VMware Player is inherently a read-only type of configuration, users would not be able to change or reconfigure the software, which may be exactly what is desired for scenarios such as beta testing or evaluation software. Organizations can prepackage everything, distribute it easily without distributing a very large software package, and provide users with a means to access the application in a much simpler and preconfigured environment. Since VMware Player itself is free, this approach provides a cost-effective means for software distribution.
Features of VMware Workstation
VMware Workstation represents a more robust virtualization solution compared to VMware Player, offering advanced features that appeal to IT professionals and developers. The product is available as an evaluation copy that can be downloaded and tried for 30 days, after which a license key must be obtained to continue using it. Unlike VMware Player, which can continue to be used for free, VMware Workstation requires purchase for ongoing use.
From the home page, users can create a new virtual machine using a wizard that offers both Typical (recommended) and Custom (advanced) options. The Custom option provides additional configuration choices such as SCSI controller types, virtual disk type, and compatibility with older VMware products. The Typical option follows a process similar to VMware Player. Users provide the location of the operating system to install or create a blank virtual machine for later installation. Windows product keys can be entered if available, though Windows 7 allows leaving this blank. Users specify a name, disk properties, and any hardware customizations before launching the operating system installation.
Additional capabilities not available in VMware Player include the ability to open a virtual machine, connect to a remote server to access virtual machines already running in the environment, and connect to VMware vCloud Air. These features make VMware Workstation suitable for more complex enterprise environments.
One of the most significant differences between VMware Player and VMware Workstation is the Snapshot feature. Snapshotting allows users to mark the state of a particular virtual machine at a specific point in time. Any changes made to the virtual machine after a snapshot can be discarded by reverting to that previous snapshot. This feature is particularly valuable for testing and development because any undesirable changes can simply be discarded. Whether the change involves installing software, encountering an error, or copying files, reverting to the snapshot undoes everything. Even deliberately causing system failure by deleting registry entries can be reversed by reverting to the original snapshot. This capability makes VMware Workstation an exceptionally useful tool for testing scenarios where problems might otherwise require reinstalling an entire physical computer.
Common Implementations of VMware Workstation
VMware Workstation supports a wide range of virtualization scenarios suited to its feature set. IT professionals can use the application from a single PC to create and test computing environments as virtual machines. Testing is one of the most common implementations of VMware because virtual machines are essentially software files that support features like snapshots. Users can create virtual machines, take snapshots, and then perform any testing or configuration changes without concern for permanent consequences. If something breaks or becomes misconfigured, reverting to the snapshot resets everything to the original state.
Running legacy applications on virtual machines is another very common use case. VMware Workstation provides broad support for a wide range of operating systems, allowing incompatible applications to run in their natively supported operating system. When an application does not run on the current operating system, running it in a virtual machine with the appropriate operating system eliminates compatibility issues.
IT professionals can use VMware Workstation to reduce PC equipment costs, potentially by 50 to 60 percent, depending on the environment and how many virtual machines can be supported on each physical host system. The product helps with application compatibility and migration issues, particularly when upgrading to new operating system versions. When an older version of Windows supported a particular application that is no longer supported after upgrading to a newer version, running a virtual machine with the old operating system provides continued access to that application until it can be upgraded.
Various groups within IT staff can benefit from VMware Workstation. Desktop administrators can test software patches, updates, and hot fixes in an isolated environment before rolling them out, ensuring they will not cause harm before distribution. Helpdesk technicians can create virtual machine libraries to replicate and resolve user issues quickly without affecting their own physical systems. Software developers and testers can streamline their efforts by using virtual machines to work with multiple development and testing environments on a single PC, creating a complete development lab environment without multiple physical computers.
Quality assurance teams can use VMware Workstation to enable quick and efficient testing of a large number of cases and configurations. System engineers and technical sales professionals can demonstrate complex multitier applications. The Teams feature can simulate an entire virtual network environment on a single PC, which is valuable for distributed applications that require a client and multiple servers. Teachers and trainers can quickly create virtual machines for students, including all required lessons and labs. Students can experiment with multiple operating systems while avoiding potential risks to the host machine or the external physical network. A significant benefit is that mistakes or misconfigurations can always be reverted to the starting point through snapshots, allowing users to start over from square one.
VMware ThinApp: Application Virtualization
VMware ThinApp is an application virtualization suite created to package conventional applications and enable their use as portable applications. This means that applications do not need to be installed on a target system. Instead, everything necessary to execute the application is packaged together by virtualizing resources such as environment variables, files, registry settings, and other configuration elements. The packaged application can be delivered and run on a target system without installation.
This approach eliminates the need for device drivers, preinstalled components, or prerequisites. The application is effectively streamed to the desktop environment or any other system, much like streaming a video file. This provides tremendous performance and scalability benefits, using low resources and minimal runtime CPU overhead. Applications can be streamed to hundreds of desktops with no additional server infrastructure or hardware required. The application is effectively self-executable, greatly reducing total cost of ownership and reducing or eliminating costs, management time, and effort related to deployment, security, and installation.
Organizations that invest significant time, effort, and money into deploying applications to hundreds or thousands of desktop systems can achieve the same goal more cost-effectively. Applications can be delivered to systems without local installation, supporting business agility and rapid growth. New users can be added quickly, centrally managed applications can be instantly updated and run from anywhere in an isolated per-user, per-application, or sandbox environment with minimal impact on the host PC. Security can be maintained because locked-down computers do not require administrative credentials to install applications since nothing is being installed. Applications can run in restricted user accounts without system changes, and system crashes and security vulnerabilities associated with device drivers are greatly reduced or eliminated.
Key Features of VMware ThinApp
VMware ThinApp offers several key features that distinguish it as an application virtualization solution. It provides agentless application virtualization, meaning nothing needs to be installed to connect to a management server to access applications. Applications are available for download regardless of other software or agents. Improved data security and performance are achieved by running virtualized applications directly from their compressed states. Applications are not cached to the user's local hard drive, saving disk space and leaving no footprint on the system.
Virtualized applications run in secure user accounts and are virtually isolated. Multiple user accounts on a single system can each run in a secure user account environment without seeing each other's applications. In terminal services environments where users connect to a remote server to run applications, VMware ThinApp runs applications in a sandbox environment where users work independently without affecting each other, even when connecting to the same terminal server.
Block-by-block network streaming loads applications more quickly, allowing applications to launch as soon as streaming begins rather than waiting for the entire application to load. Virtualized applications run completely in user mode, avoiding kernel mode access that could cause driver issues or security problems. The solution can be used on both managed and unmanaged computers. Simplified application packaging allows snapshots of system state before and after application delivery. Custom applications can be delivered to customers and users throughout an extranet, allowing anyone to gain access to applications if desired. Applications only need to be tested and packaged once regardless of the operating systems that exist, and once packaged correctly, they are ready to be delivered and should run on any system.
ThinApp enables linking of application packages, allowing multiple applications to run separately while sharing resources and running interdependently on user systems. Applications can access the same information or even information within each other's packages if necessary. Conflict-free application delivery includes portable profiles and user settings, enabling critical applications to run from a USB key or CD without security risks or compatibility issues. The solution integrates with various third-party application management solutions. Mobile users and third parties on a corporate extranet can easily access applications and updates. Existing software distribution systems can be used to distribute updates via HTTP or HTTPS over LAN or WAN. ThinApp operates independently from distribution streaming and activation servers or agents, and uses Active Directory and various open protocols for identity and authentication.
Common Uses for VMware ThinApp
Various types of users can benefit from VMware ThinApp. Software vendors can deliver products to customers without compromising the security of customers' operating systems. Virtualized application packages require no local installation, and everything needed to support the application is included within its configuration, so the local installation of the system is not changed. Virtualized applications have minor resource requirements and can bundle an application with all associated registry keys and DLLs into a single executable file, providing an efficient delivery method. Vendors can demonstrate products to potential customers without worrying about compromising or affecting the customer's local operating systems.
Developers can speed up development time using the latest runtimes, frameworks, and components. ThinApp virtual applications can be linked to key components such as Java or .NET. Virtual applications can run on restricted user accounts, avoiding conflicts with other applications, and traditional applications can be quickly and easily converted to virtualized applications, eliminating concerns about support on particular target systems.
IT directors can overcome a variety of integration issues, reduce regression testing costs and costs of maintaining secure desktops, and enable staff to be more mobile. Applications can run from any external media without a network, facilitating the ability to package applications and everything required to support them into a portable format with minimal resource requirements and minimal effect on the target system. These benefits make ThinApp a valuable tool for organizations seeking to simplify application deployment and management.
VMware Workspace Suite: An Integrated Platform
In today's computing environments, many users are highly mobile, and administrators seek to centralize control and management of applications. The VMware Workspace Suite addresses these needs through an integrated platform that provides unified access and identity management. The suite includes AirWatch, AirWatch Content Locker, VMware Horizon, VMware Identity Manager, and VMware Horizon FLEX. Together, these components enable easy and seamless access to applications and Single Sign-On (SSO), providing mobile device users access to Windows, the web, and applications.
Single Sign-On means that once users have identified themselves and signed on, they can access all their services, features, and applications using that same identity. They do not need to be prompted for additional sign-ons or credentials each time they access a different application from a different location or device. A single authentication allows access to everything needed.
The Workspace Suite also provides secure collaboration through the AirWatch Content Locker, a self-service console used to publish files securely in the workspace. Users can protect content they are using from anywhere on any device using a single set of credentials, keeping their activities secure from others using the same application. Complete application delivery is provided through AirWatch Enterprise Mobility Management and Horizon, which deliver current and future applications. Administration can deliver new apps and services to devices and ensure compliance is met. Access can be based on application sensitivity or combined with policies such as user, device, and location, allowing control over access to applications based on specific conditions.
The unified platform ensures that service-level agreements are met by monitoring usage patterns and performance metrics, allowing organizations to identify and address any performance issues. Easy management from the administrative perspective is provided through VMware Horizon FLEX, which maintains security and compliance through centrally managed desktops. Layering technology provides management, backup solutions, and updates to virtualized desktops. The entire Workspace Suite allows organizations to deliver applications to mobile users in a unified, seamless manner while enabling administration to control management of the entire environment using a single suite of applications.
AirWatch: Enterprise Mobility Management
AirWatch is an enterprise mobility management platform that allows administration to control what users can do with their devices, particularly mobile devices. The platform is highly scalable and allows integration with existing enterprise systems, enabling organizations to integrate various mobile devices into their existing IT infrastructure. All devices can be managed from a central console regardless of type, platform, or ownership.
Bring Your Own Device (BYOD) has become increasingly common, and AirWatch addresses the challenges this presents. The platform provides mobile device management functionality, allowing administrators to view and manage mobile devices using a centralized console. Administrators can manage internal, public, and purchased applications from this central console regardless of whether the device is company-owned, employee-owned, or shared among several employees.
Users often have their own devices and are comfortable using them to access work-based content and applications, but administration has typically been hesitant due to an inability to control the device. Work-based content or data on personal devices is exposed to potential security risks if users do not manage it as securely as administration would like. AirWatch allows devices to be configured to a certain degree using the administrative console to configure and apply secure browsing policies. Multiuser management capabilities and mobile container management help keep corporate and personal data separate, addressing security and privacy concerns and helping regulate enterprise security and data loss prevention for mobile devices. Management can control what users can do with their personal devices for work-related activities while users can still use their comfortable and familiar devices for personal purposes.
AirWatch Content Locker
The AirWatch Content Locker component of the Workspace Suite helps protect sensitive content. It is a central application used for accessing, storing, updating, and distributing documents securely from mobile devices. Mobile devices can be taken anywhere and connected to virtually any network, making security of information on those devices more difficult to maintain compared to entirely internal organizations. The Content Locker provides enterprise security policies and data loss prevention.
Users can be authenticated using Active Directory, Lightweight Directory Access Protocol, Kerberos tokens, and certificates. These standard protocols are used by Windows environments to authenticate users and access content, and all are supported by the AirWatch Content Locker. Content being transmitted is encrypted using Advanced Encryption Services (AES) and Federal Information Processing Standard (FIPS) encryption methods. Advanced data loss prevention restrictions can be configured to ensure that data is not lost if a device is compromised, lost, or stolen.
Content storage options are flexible and include mobile devices, cloud services, hybrid combinations, and on-premises data. Administration determines how users can access content, but the AirWatch Content Locker helps ensure that the means by which data is accessed remains secure. Content sharing is provided through self-service portals, allowing collaboration for shared files, feedback, and editing. Content dashboards display content inventory so users can select which content is important and which data they need to access. The overall challenge is ensuring that mobile users can access content while administration ensures that content is kept secure, and the AirWatch Content Locker facilitates both goals.
VMware Horizon: Virtual Desktop Infrastructure
The VMware Horizon 6 component of the Workspace Suite uses Virtual Desktop Infrastructure (VDI) to provide virtual or hosted desktops and applications. Rather than installing virtualization software on every computer and creating individual virtual machines for each user, VDI centralizes virtual machines on servers. Users access these virtual machines from their desktop systems, possibly through Remote Desktop Services. This approach is known as Virtual Desktop Infrastructure.
Centralizing virtual machines on a server or collection of servers creates a single workspace, giving users access to virtual desktops, needed applications, and possibly other online services. Access to desktops and applications is provided through a unified workspace, commonly using Remote Desktop Services apps and ThinApps. These utilities allow end users to connect remotely to servers and access virtual desktops or applications.
Horizon provides workspace environment management, allowing control, automation of delivery, and protection of resources from a centralized collection of servers. Performance can be monitored more easily, and alerts can be configured to help resolve infrastructure, desktop, and application issues such as running out of resources. Resources can be dynamically allocated with multiple servers, simplifying management and reducing costs. Virtual storage, virtual computing, and virtual networking can be configured to pool available resources and dynamically allocate them where needed. End users do not notice any difference as long as they can access their applications with adequate performance. Horizon allows organizations to set up virtual desktop infrastructure and control and manage applications and virtual machines centrally from servers rather than managing virtual machines on hundreds or thousands of independent desktop systems.
VMware Identity Manager
VMware Identity Manager is a solution for identity management, offered as a cloud service known as Identity as a Service (IDaaS). Identity management comes down to the user's identity and identifying who the user is. While everyone does this when signing in to any system, Identity Manager also provides application provisioning, self-service catalogs, conditional access controls, and Single Sign-On based on the user's identity. This applies to mobile applications, web-based apps, cloud services, and native applications.
The goal of identity management is to allow users to sign in to existing infrastructure, such as a Windows Active Directory environment, and have that user ID accepted by other applications, providers, and solutions. Users do not need to provide additional credentials to access other services and applications. Single Sign-On makes it easier for users by requiring only one set of credentials.
Identity Manager functionality includes enterprise-level Single Sign-On, avoiding the need for multiple login credentials. It can integrate with other existing identity providers, allowing integration with other identity solutions already in place. Access to apps can be turned off instantly for security purposes if a person's identity is suspected or discovered to be compromised. Self-service access to a multitude of applications is provided, functioning with on-premises legacy Windows and web-based applications, cloud services such as Software as a Service, and native mobile applications.
Identity Manager provides enterprise-grade hybrid cloud infrastructure and offers identity management used with vCloud Air and vCloud Suite. vCloud Air is VMware's public cloud platform built around vSphere, making it highly compatible with on-premises vSphere deployments. vCloud Suite is a collection of VMware applications used to build private clouds. Identity Manager supports and integrates with multiple Active Directory domains and forests and can configure conditional access policies based on security group identifiers, local network, and authentication type. The overall goal is to manage user identities and have those identities be as compatible as possible with various applications, services, and components while using a single set of credentials.
VMware Horizon FLEX
VMware Horizon FLEX is a relatively new release designed primarily to make it easier for administration to onboard new staff, with particular attention to traveling or remote users, temporary contract workers, and users who want to use their own devices. While Horizon is part of the virtual desktop infrastructure allowing users to access virtual desktops hosted on servers or installed locally, Horizon FLEX uses a similar approach but is geared toward traveling users and BYOD scenarios.
Horizon FLEX is a policy-based, containerized desktop solution that extends the abilities of Horizon for virtual desktop infrastructure into a policy. Administrators can specify collections of settings and applications available to particular users categorized and identified by their needs. Containers are created, settings are applied to those containers, and security control and compliance are maintained from the IT administration perspective. This is particularly valuable when dealing with contract workers and temporary workers using their own devices, as maintaining corporate security can be challenging.
The solution provides flexibility to accommodate end users such as Mac users who need to run Windows-based applications or Windows itself, users who want to bring their own PC (BYOPC), and users who travel frequently. Local virtual desktops are provided to Mac and PC users with ease, whether they are using a Mac and need to run Windows or using Windows and need to run a Mac. Unlike remote virtual desktop infrastructure where users connect remotely to a server to access virtual machines, these virtual desktops are available locally. Users can sign into a server and download the desktop or receive it on a USB key, allowing access from anywhere whether connected or disconnected. Traveling users still get the full rich desktop experience.
Simplified desktop management is provided through a central web console to control and secure virtual desktops. If a user leaves the organization, the desktop can be locked down so they can no longer access it. Backup and patching of Windows virtual desktops can be easily managed, either with Mirage for Horizon FLEX or various other Windows image management tools, keeping virtual desktops safe, secure, and up to date. Costs are reduced because users can use their own Mac or PC, eliminating the need to purchase additional hardware, particularly for short-term contractors. The simple interface for users decreases the need for training, further reducing total cost of ownership.
Conclusion
VMware offers a comprehensive suite of virtualization solutions addressing a wide range of organizational needs. From VMware Fusion for Mac users requiring access to non-Mac applications, to VMware Workstation for IT professionals needing advanced testing and development capabilities, to VMware ThinApp for application virtualization, to the VMware Workspace Suite for mobile workforce management, these products provide flexibility, security, and efficiency. Organizations can leverage these solutions to reduce costs, improve productivity, and maintain security while accommodating diverse computing requirements.