Desktops and web applications
Besides single applications, the portal can offer two other kinds of resource: a full Windows desktop, and a web application that opens a web address. This page explains when to use each and how to publish them.
Three kinds of resource
| Resource | What the person gets | Use it when |
|---|---|---|
| Application | One program's window, in a tab | People need particular programs and nothing else. See Publishing applications. |
| Desktop | The whole Windows desktop of a host, in a tab, with its Start menu and taskbar | People need the full working environment: many programs, their own files, or tools you would rather not publish one by one. |
| Web application | A web address opened in a new browser tab | You want an intranet site, a web-based system or a cloud service to sit beside the Windows programs, so the portal is the one place people start from. |
All three appear as cards in the portal, can be filed in the same categories, can be starred into Favourites, and use the same access rules.
Publishing a desktop
A desktop resource opens a complete Windows session on one host. Because it is the whole desktop, everything the person's Windows account can reach on that host is available to them, so publish desktops only to people who should have that.
The host's readiness matters even more for desktops than for applications. Without the Remote Desktop Session Host role, a Windows Server host accepts two connections, so a desktop works for two people and then refuses everyone else. The desktop pages show the host's readiness verdict beneath the host list, so you see the warning while you are publishing. See Readiness.
Create a desktop
- Open the Desktops page. In the console, go to Catalog → Desktops.
- Click Add.
- Name the desktop. This is the name on the card, such as "Finance desktop".
- Choose the host. Check the readiness verdict that appears beneath it.
- Choose how people sign in to the host. Pass-Through uses each person's own Windows account; Fixed Credentials uses one saved account for everyone. See Signing in to the host.
- Decide who may see it. In Access Control, choose All Authenticated Users or Only Allowed and add users and groups. The picker offers portal users, portal groups, and directory users and groups.
- Choose an icon. A desktop has no program to read a picture from, so pick one from the icon library. The picker recommends the Desktops group first. Without one, the card shows a plain monitor symbol.
- Set the size, categories, printing and file transfer as needed (see the table below).
- Save. The desktop appears in the portal for the people you allowed.
Desktop settings
| Setting | What it does | Default |
|---|---|---|
| Name | The card's title in the portal. | — |
| Host | The host whose desktop is opened. | — |
| Sign-in to the host | Pass-Through or Fixed Credentials. | — |
| Access Control | Who sees the card. | All Authenticated Users |
| Icon | The card's picture, from the icon library. | A monitor symbol |
| Width and Height | 0 fits the session to the person's browser window. Set both to pin a fixed size. See Display size. | 0 (fit the window) |
| Categories | Which portal folders the card appears in. | None |
| Printing and file transfer | See Printing and File transfer. | As set globally |
Desktops and other devices
Windows normally gives one account one session on a host. If the same person opens a desktop on a second computer while it is open on the first, Windows hands the session to the newer connection and the first computer's view of it ends. This is Windows' own behaviour, not a fault. You can choose what DartRelay does in that situation on the host's page; see Sessions for the same person.
Desktop or applications from the same host?
You can publish both from one host. Published applications from one group share a Windows session, but a desktop always opens a connection of its own. On a host that allows one session per Windows account (the Windows default), opening the desktop as the same account therefore takes over the session the applications were using, and their tabs lose it. If the same people need a desktop and applications at the same time, publish them from different hosts.
Publishing a web application
A web application is a card that opens a web address in a new browser tab. DartRelay does not carry the traffic: the person's browser goes straight to the address, exactly as if they had typed it. That means the site must be reachable from wherever your users are, and any sign-in the site needs still happens on that site.
Use web applications to make the portal the starting point for the working day: the intranet, a web-based HR system, a supplier's ordering site, or a cloud mail service beside the Windows programs.
Create a web application
- Open the Web Apps page. In the console, go to Catalog → Web Apps.
- Click Add.
- Fill in the general details. Give it a name and the web address it opens.
- Choose an icon. The picker recommends the Web apps group, followed by general marks such as Browser, Mail, Calendar, Chat, Database and Code. A web application with no icon of its own shows the library's Web app picture, marked "Default" in the editor.
- Decide who may see it. In Access Control, choose All Authenticated Users or Only Allowed.
- File it in categories in the categories card, if you use them.
- Review the Single Sign-On card, then save.
On the page for a new web application you can choose Only Allowed, but the list of people to allow is not offered until the web application has been saved. Save it once, open it again, and add the users and groups there.
How a web application opens
Clicking the card opens the address in a new browser tab, and the portal stays where it was. If the browser blocks the new tab, the portal shows a short message with a button to open it, so the person is never left wondering why nothing happened. Web applications can also be the target of an automatic launch rule.
Because DartRelay never sees a web application's traffic, the only thing that keeps a person away from a web application they should not use is that it is not shown to them. If the site itself must be protected, protect it at the site.
Example: one portal for a clinic
A clinic wants reception staff to start their day from one page. They publish:
- The appointments program from the clinic's host as an application, for everyone in the Reception group.
- A desktop on the same host for the practice manager only, who needs the full environment.
- The clinic's web-based lab-results service and its intranet as two web applications, both filed with the appointments program in a "Reception" category.
Reception staff see three cards in one folder. The practice manager sees those plus the desktop.
If something goes wrong
| Symptom | Likely cause and fix |
|---|---|
| A desktop works for two people and then refuses everyone else | The host has no Session Host role, or is waiting for a restart. See Install the Remote Desktop Session Host role. |
| Opening a desktop on a second computer ends it on the first | Windows allows one session per account. See Sessions for the same person. |
| A web application does not open | The browser blocked the new tab; use the button in the portal's message, or allow pop-ups for the portal's address. |
| Somebody cannot see a desktop or web application | Check its access rules and whether it is filed only in a restricted category. See Restricted categories. |
Related pages
Publishing applications
Single programs in their own tabs.
Adding and preparing hosts
Readiness and the Session Host role.
Giving people access
Users, groups and directory principals.
Categories, folders and icons
Organise cards and pick pictures.
Automatic launch
Open a resource as soon as someone signs in.
