Dynamic Environment Manager configuration

Preparing the network resources in DFS Begin the configuration by creating three folders on the selected network resource. The first folder to create is the folder where the configuration will be stored. Monetrax will store the DEM-related files on a Windows server with the DFS service, to add a folder with the configuration, log in…

6 min read

Preparing the network resources in DFS

Begin the configuration by creating three folders on the selected network resource. The first folder to create is the folder where the configuration will be stored.

Monetrax will store the DEM-related files on a Windows server with the DFS service, to add a folder with the configuration, log in to the file server and run the DFS Managment attachment.

DFS Management console with an empty namespace list

Then right-click New Namespace on the left side

Namespaces context menu with New Namespace selected

The first step in the wizard that opens is to indicate the name of the server on which the folder is to be configured, in this case montx-fs-01.

New Namespace wizard — server name montx-fs-01

Next, enter the name of the DEMConfig folder and select Next

New Namespace wizard — namespace name DEMConfig

Leave the option to use the domain name in the path

New Namespace wizard — Domain-based namespace type selected

At the end, the wizard displays a summary, if everything agrees select Create

New Namespace wizard — summary screen before clicking Create

After a while, the folder will be created

DFS Management console showing the created DEMConfig namespace

Repeat this process for folders named DEMProfiles and FolderRedirection.

Once the folders have been created, you should see three folders in the c:DEMSRoot location

C:\DFSRoots folder containing DEMConfig, DEMProfiles and FolderRedirection

NTFS and share permissions

The next step is to assign the appropriate NTFS permissions to the folders:

  • DEMConfig
    • Horizon Admins = Full Control
    • Horizon Users = Read
    • Domain Computers = Read
  • DEMProfiles
    • Horizon Admins = Full Control
    • Horizon Users = Read/Execute, Create Folders – this folder only
    • Creator Owner = Full Control
  • FolderRedirection
    • Admins = Full Control
    • Domain Users = Read/Execute, Create Folders – this folder only
    • Creator Owner = Full Control

To grant permissions, right-click on the folder and select Properties, then Security tab, then Advanced, finally Change permissions.

Four steps to the DEMConfig folder permissions: Properties, Security tab, Advanced and Change permissions

The next step is to disable inheritance of permissions from the parent folder, by selecting Disable inheritance

Advanced Security Settings window with the Disable inheritance button

Two options will be displayed, select Remove all inherited permissions from this object

Inheritance prompt with the Remove all inherited permissions from this object option

All permissions will be removed

Advanced Security Settings with an empty permission list after removing inheritance

Add permissions for individual groups as above, and also add Domain Admins with Full control permissions.

To assign permissions, select Add, then select principal, indicate the group, select the appropriate permissions and confirm.

Permission Entry window with a group chosen via Select a principal

Assign permissions should be repeated for all groups indicated above and folders.

You still need to set permissions for the shared folder, in the sharing tab, go to Advanced Sharing and select Permissons, give Full control permissions for Everyone

Advanced Sharing window granting Full Control to Everyone

Installing the DEM administrative templates

The files are provided as a zip archive, unzip them

Extracted ZIP archive with VMware Dynamic Environment Manager installation files

GPO configuration

At the beginning of the configuration, copy the admx and adml files to the SYSVOL\\PolicyDefinitions folder in the case if a central store is configured, if not then on each domain controller add the files to the C:Windows\PolicyDefinitions location.

admx and adml files copied into the PolicyDefinitions folder in SYSVOL

To configure policies, run the Group Policy Management attachment

Group Policy Management console with the monetrax.corp domain tree

In the next step, you need to prepare a configuration policy for the DEM agent, to do this, select OU and from the context menu select Create a GPO in this domain, and link it here

OU context menu with Create a GPO in this domain, and Link it here

You will be prompted to enter the name of the policy, in this case it will be MONTX-HOR-DEMCONFIG, confirm ok

New GPO window with the policy name MONTX-HOR-DEMCONFIG

Once the policy is created, it will be visible under the given OU

The MONTX-HOR-DEMCONFIG policy linked under the organisational unit

To configure the given policy, select Edit from the context menu

GPO context menu with the Edit option selected

If the administrative templates have been loaded correctly in the User Configuration -> Administrative Templates branch, a folder with Vmware DEM settings will appear

VMware DEM branch in Administrative Templates with FlexEngine, Helpdesk Support Tool, Management Console and SyncTool

Configuring the DEM agent through GPO

The first option you need to configure is Flex config files, you should indicate there the path where the DEM configuration is stored in the form of UNC path \nmonetrax .corp\nDEMconfig\nGeneral, you should also check recursive search.

Flex config files setting with the UNC path \\monetrax.corp\DEMconfig\General and recursive search

The next option for configuration is called Profile archives, this path will store the captured user settings while the user is working. The settings will be kept in zip files. The path ƒmonetrax .corpƒDEMprofiles%username%Archives will be created based on the user’s name, thanks to the Windows system variable %username%.

Profile archives setting with the path \\monetrax.corp\DEMprofiles\%username%\Archives

DEM agent event logging still needs to be set up, this can be done using the FlexEngine logging option. The path for the logs will be \monetrax .corpDEMprofiles%username%Logs, the log level is set to Debug, so that all events will be saved if analysis is needed.

FlexEngine logging setting with the log path and Debug level

The last thing is to set profile backups, this is an option called Profile archive backups. The place to store these files will be the location of ƒmonetrax .corpƒDEMprofiles%username%Backups, the number of backups will be 1, and the backup folder will be hidden.

Profile archive backups setting with the backup path and a limit of one backup

Installing the DEM management console

After the GPO configuration is complete, install the DEM management console, this can be done on any station, preferably it should be an administrator station.

Run the file VMware Dynamic Environment Manager Enterprise 2312 10.12 x64.exe , the installation window will appear. At the beginning, select Next.

Welcome screen of the VMware Dynamic Environment Manager Enterprise 2312 installer

Approve the provisions of the license agreement

DEM installer — accepting the licence agreement

Leave the default installation path

DEM installer — default installation path

Select Custom installation type

DEM installer — Custom setup type selected

Select Vmware DEM Management Console for installation, the other options are not needed during this installation.

DEM installer — only the Management Console selected for installation

Confirm the installation by Install

DEM installer — ready screen with the Install button

Complete the installation process by selecting Finish

DEM installer — final screen with the Finish button

First launch of the console

After the installation for configuration, run the Managment Console application

Launching the VMware Dynamic Environment Manager Management Console

The first time you run the console you will be asked if you want to integrate with Workspace ONE UEM, at this point select No

Workspace ONE UEM integration prompt on first launch of the console

At the first launch, indicate where the configuration will be stored, this will be the previously prepared path \monetrax .corp\DEMconfig

Setting the configuration path \\monetrax.corp\DEMconfig on first launch

A general folder will be created automatically in the indicated location

The General folder created automatically in the DEM configuration location

Deselect the Join the Vmware Customer Experience Improvement Program option, and check the Do not show this message again option

Customer Experience Improvement Program window with the consent unchecked

Application configuration templates

After launching the console, download the application setup templates, this can be done using Download Config Templates.

DEM console ribbon with the Download Config Templates button highlighted

Then select the applications of interest, confirm by selecting Save, and then close the selection window by Close

Window for selecting application configuration templates to download

If Office settings are to be captured, add them using Create Config File

The Create Config File button on the DEM console ribbon

In the wizard, select Use an Application Template

Config file wizard with the Use an Application Template option

Select Microsoft Office 2016/2019/365 from the list

Application template list with Microsoft Office 2016/2019/365 selected

In the last step, give a name to the settings, e.g. Microsoft Office, confirm Finish

Final wizard step with the setting named Microsoft Office

You can use the following options in the application settings capture configuration:

OptionDescription
IncludeFolderTreesIncludes files and subfolders in the specified folder.
ExcludeFolderTreesExcludes files and subfolders in a specified folder.
IncludeIndividualFoldersIncludes only files in the specified folder.
ExcludeIndividualFoldersExcludes only files in the specified folder.
IncludeFilesIncludes the specified file or, if the file name contains wildcards, files.
IncludeFilesRecursivelyIncludes files in a folder and subfolders if they match the specified file name or pattern.
ExcludeFilesExcludes the specified file or, if the file name contains wildcards, files.
IncludeRegistryTreesIncludes values and subkeys of the specified key.
ExcludeRegistryTreesExcludes values and subkeys of the specified key.
IncludeIndividualRegistryKeysIncludes only the values of the specified key.
ExcludeIndividualRegistryKeysExcludes only the values of the specified key. All subkeys of the specified key and their values are not excluded.
IncludeIndividualRegistryValuesIncludes the specified value.
ExcludeIndividualRegistryValuesExcludes the specified value.

Example configuration using selected values for Chrome

Chrome DirectFlex config file with IncludeRegistryTrees, IncludeFolderTrees and ExcludeFolderTrees sections

For folders, you can use the following tokens, which are references to folders in Windows:

  • (the equivalent of the %APPDATA% folder in Windows),
  • ,
  • ,
  • ,
  • (the equivalent of the %LOCALAPPDATA% folder in Windows), ,
  • (the user’s documents folder),
  • ,
  • ,
  • ,
  • ,
  • ,
  • (the Startup folder in the user’s start menu),
  • (the equivalent of the %USERPROFILE% folder in Windows).

User folder redirection

As a final step in the initial configuration of the DEM, redirect the user settings to the previously prepared location .corpFolderredirection>

To do this, go to the User Envirnoment tab , go to Folder Redirection, select Create Folder Redirection settings from the context menu.

User Environment tab with the Create Folder Redirection settings option

In the window, enter the name of this setting, and provide the path with the username variable \monetrax .corp\Folderredirection%username%, add Desktop and Favorites to the selected folders.

Folder Redirection window with the path \\monetrax.corp\Folderredirection\%username% and the Desktop and Favorites folders

The initial configuration of the DEM is now complete.

The full series

Leave a Reply

Your email address will not be published. Required fields are marked *