Customers who use Omnissa Horizon (formerly VMWare Horizon) to deploy VDIs with the Instant-Clone feature must use a different deployment method than the ones listed in our main VDI article. Due to how Omnissa Horizon provisions virtual machines, using the Instant-Clone feature means all virtual machines will check in with the same Computer ID in the ThreatLocker Portal. This could cause issues with your ThreatLocker environment, preventing it from functioning properly.
Instructions for creating the Golden Image can be followed as instructed in our main VDI article: the pk.dat file should be removed, as well as the ComputerId, ComputerAuthKey, and ComputerSettingsV6 registry keys.
Deploying ThreatLocker in a VDI environment | ThreatLocker Help Center
Then, before an image is taken, the machine should be placed into the Disable Tamper Protection maintenance mode.
Disable Tamper Protection | ThreatLocker Help Center
The following services should be stopped and disabled in the following order:
- healthtlservice
- threatlocker service
- threatlocker driver
You will need to create a script and run it after a clone is created. Your script needs to restart the services listed above and set them to automatic. Doing this will ensure that your VDIs behave normally and do not all share the same Computer ID.
Help Center