Horizon 8 2606 | Security, management & performance updates
- Last updated 09/04/2026
-
Horizon 8 2606 introduces updates across end user experience, Horizon administration, security, and platform support. These enhancements address common deployment and management challenges while expanding the environments and authentication methods Horizon supports.
Here’s a closer look at what’s included and what it means for Horizon customers.
Support more devices and environments
Deploy Horizon Agent on physical Macs
Horizon Agent for macOS is now generally available, extending Omnissa Horizon support to physical Mac hardware. Organizations can securely enable remote access to managed Mac devices for iOS and macOS development, build and test environments, provide remote administration, and smooth out other enterprise workflows.
The release adds support for multi-monitor displays, Real-Time Audio-Video (RTAV), and clipboard redirection. Clipboard redirection now supports configurable payload sizes of up to 64 MB, making it easier to transfer larger amounts of content between local and remote environments.
Support FIPS mode on RHEL 9.6 Linux Agent desktops
Horizon now supports Federal Information Processing Standards (FIPS) mode on Red Hat Enterprise Linux (RHEL) 9.6. Organizations can adopt the newer RHEL release while maintaining FIPS-compliant Linux virtual desktop environments.
Preview Wayland support for Linux virtual desktops
Horizon 8 2606 introduces early support for the Wayland display protocol on Linux virtual desktops. Customers can evaluate Wayland-based environments with core capabilities including audio, clipboard redirection, USB, printer redirection, and keyboard support.
Wayland support for RHEL 10.0 on Horizon 8 on vSphere is added as Beta. For more details, please check beta.omnissa.com.
Open web links locally from Linux virtual desktops
URL redirection for Linux virtual desktops can now open links clicked in applications such as email and Slack in the user’s local Chrome or Microsoft Edge browser. This allows organizations to keep supported browser sessions on the endpoint rather than inside the virtual desktop.
Preview updates to Horizon Client for Chrome IWA
The Horizon Client for Chrome Interactive Web Access (IWA) beta includes expanded kiosk-mode support, new session management controls, and updates to authentication and multimedia experiences.
If you're interested in participating in Horizon beta programs, contact your Omnissa representative and access beta.omnissa.com to learn more.
Simplify client protocol selection
Horizon 8 2606 removes PCoIP as a selectable display protocol from Horizon Client, leaving Blast as the supported client protocol. PCoIP is still available as an option for Horizon Agent installs but is not installed by default. Existing virtual deployments retain their current PCoIP configuration during upgrades, allowing administrators to transition to Blast at their own pace.
Improve graphics performance in HTML Access
Blast Codec is now enabled by default for HTML Access, improving graphics performance for users accessing Horizon desktops and applications through a web browser. This delivers a better browser-based access experience without requiring additional configuration.
Microsoft Teams VDI 2.0 now generally available
Horizon now supports Microsoft Teams Virtual Desktop Infrastructure (VDI) 2.0, also known as New SlimCore, with the latest Horizon Windows Client. This helps organizations stay current with ongoing Microsoft Teams client updates while continuing to deliver an optimized Teams experience in Horizon virtual desktops.
Improve login reliability during policy updates
Horizon now waits for configuration changes from tools such as Group Policy and Dynamic Environment Manager to stabilize before applying them. Preventing repeated configuration reloads during sign-in helps reduce session interruptions and login issues such as black screens.
Control browser cache growth on Linux endpoints
Administrators can now set separate maximum cache sizes for Browser Content Redirection and HTML5 Multimedia Redirection on the Linux Horizon Client. Horizon manages cache usage while preserving user data such as login sessions, cookies, and browsing history, helping prevent excessive disk consumption on storage-constrained endpoints.
Horizon 8 2606 also gives administrators more control over Agent deployments, image creation, certificates, and access to multiple environments.
Reduce day-to-day management effort
Update Nutanix Golden Images more efficiently
Administrators can now modify or upgrade the Horizon Agent on Nutanix golden images without renaming the virtual machine or disrupting existing desktop pools. This reduces the effort required to maintain images and keep Agent components current.
Simplify image optimization with a guided SCCM workflow
OS Optimization Tool (OSOT) now includes a guided interface for creating optimized Windows images with Omnissa agents installed through Microsoft System Center Configuration Manager (SCCM). Administrators can configure OSOT settings and import task sequences with fewer manual steps.
Manage device encryption settings in OSOT
OSOT now includes options to disable device encryption and BitLocker in managed virtual desktop environments where they are not required. This gives administrators greater control over encryption settings and the resources used by their Windows images.
Update UAG certificates with less disruption
Administrators can now update secure sockets layer (SSL) server certificates on Unified Access Gateway with less disruption to Horizon users. Existing sessions remain connected whenever possible, while new connections use the updated certificate.
Connect to multiple environments with SAML on macOS
Horizon Client for Mac now supports launching multiple simultaneous Horizon Client instances using a uniform resource identifier (URI) command. Each launch can use security assertion markup language (SAML) authentication. Administrators and power users can access more than one Horizon environment without interrupting their existing sessions.
Strengthen authentication and access
Extend True SSO desktop unlock to Ping
Horizon now supports Ping for desktop unlock with True Single Sign-On (SSO). Users can reauthenticate through their organization’s identity provider when unlocking a virtual desktop instead of relying on a password. This feature is available with the Horizon Client for Windows.
Extend FIDO2 authentication to UWP applications
WebAuthn redirection now supports Universal Windows Platform (UWP) applications, including the new Microsoft Outlook. Users can continue using FIDO2 security keys to authenticate within more applications running in their virtual desktops.
Improve FIDO2 and U2F support on Linux
Horizon now automatically configures the required device permissions for redirected FIDO2 and U2F hardware security keys in Linux virtual desktops. This improves authentication reliability while reducing the manual configuration required from administrators.
Strengthen Horizon Recording deployments
Horizon Recording improves the handling of default administrative credentials in new deployments. This reduces the risks associated with default credentials and supports a more secure initial configuration.
Enforce conditional access for mobile users
Horizon on mobile now consistently enforces Workspace ONE conditional access during application launches from Horizon Cloud. Users are directed through the required authentication flow in Omnissa Access before gaining access to their desktops and applications.
Want to learn more?
These highlights represent a selection of the updates included in Horizon 8 2606. Review the Horizon 8 2606 release notes for the complete list of features, supported platforms, resolved issues, known issues, and changes to platform support.