# Horizon Agent Unreachable and Pending Desktops: Fixes

Source: https://srvscripts.com/guides/horizon-agent-unreachable/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

In short: Open a console to the affected desktop and confirm the “VMware Horizon View Agent” (wsnm) service is running, that the guest can resolve the Connection Server FQDN and reach it on TCP 4001 with Test-NetConnection, and that its clock is…

In the Horizon console, a desktop that shows “Agent Unreachable” is one where the Connection Server cannot talk to the Horizon Agent inside the guest, and a desktop stuck in “Pending”, “Provisioning” or “Customizing” is one that never completed the pairing after being created. The two share most of their causes: the agent service is not running, the machine cannot resolve or reach the Connection Server on the JMS port, the guest clock is wrong, or an instant-clone parent is unhealthy. The steps below apply to Horizon 8 (2306 through the current 2506-series releases) on ESXi 7, 8 and 9, with Windows 10 and Windows 11 desktops.

**Short answer:** Open a console to the affected desktop and confirm the “VMware Horizon View Agent” (wsnm) service is running, that the guest can resolve the Connection Server FQDN and reach it on TCP 4001 with `Test-NetConnection`, and that its clock is within a few minutes of the domain. If a single desktop is affected, restarting the agent or the VM usually clears it; if a whole pool is stuck in Pending or Provisioning, check the instant-clone parent VMs (cp-parent, cp-template, cp-replica) in vCenter, remove failed ones with the IcCleanup tool, and push the image again. For pools built from linked clones after a datastore move, look for redo-log corruption instead.

## Check the agent on the desktop

Open a vSphere console to the VM (not a Horizon session) and run:

```
Get-Service wsnm, WSNM, "VMware Horizon View Agent" -ErrorAction SilentlyContinue | Format-Table Name, Status
Get-Service | Where-Object DisplayName -like "*Horizon*" | Format-Table DisplayName, Status
Restart-Service wsnm
```

If the service will not start, the agent install may be damaged or a recent Windows update changed something the agent hooks; check Application and System logs and the agent log at `C:\ProgramData\VMware\VDM\logs\debug-*.txt` for the startup error. Reinstall the agent from the current Horizon Agent installer for your Connection Server version, in the correct order (VMware Tools first, then the agent, then any App Volumes or DEM agents).

## Check name resolution, time and port 4001

The agent pairs with the Connection Server over JMS on TCP 4001 (and 4002 for enhanced security mode). From the desktop:

```
Resolve-DnsName cs01.corp.example
Test-NetConnection cs01.corp.example -Port 4001
w32tm /query /status
Get-ItemProperty "HKLM:\SOFTWARE\VMware, Inc.\VMware VDM\Agent\Configuration" | Format-List Broker
```

A failed DNS lookup or a blocked port is the answer for desktops in a new subnet or behind a changed firewall. Clock skew over five minutes breaks Kerberos and therefore the pairing; fix the domain time source and resync. The Broker value must match the Connection Server the pool was created on. If the desktop was cloned or restored from a snapshot, the pairing key is stale; remove the desktop from the pool and let Horizon recreate it, or for manual pools, uninstall and reinstall the agent so it re-pairs.

## Pools stuck in Pending or Provisioning

Instant-clone pools depend on a chain of internal VMs per host and datastore. In vCenter, look in the pool’s folder and in the “ClonePrepInternalTemplateFolder” and related folders for cp-template, cp-replica and cp-parent VMs. A cp-parent that is powered off, orphaned or on a host in maintenance mode blocks provisioning on that host. Also check the Connection Server’s Events tab for “Provisioning error” messages that name the cause (out of datastore space, customization failure, Sysprep timeout).

To reset a broken chain, disable provisioning on the pool, remove stale internal VMs with the IcCleanup utility on the Connection Server:

```
cd "C:\Program Files\Omnissa\Horizon\Server\tools\bin"
IcCleanup.cmd -vc vcenter.corp.example -uid administrator@vsphere.local
```

Inside the utility, `list` shows the internal VMs, and `unprotect` followed by `delete` removes those belonging to the affected pool. Then push a new image or re-enable provisioning so Horizon rebuilds the chain.

For linked-clone pools after a storage migration, the “Agent Unreachable” state often hides a power-on failure from a corrupt redo log; see [Fix “The redo log of .vmdk is corrupt”](/guides/redo-log-of-vmdk-is-corrupt/).

## Check the Connection Server side

On the Connection Server, review `C:\ProgramData\VMware\VDM\logs\log-*.txt` for the desktop name; lines mentioning “MACHINE_UNREACHABLE” or JMS authentication failures explain the console state. Confirm the Connection Server’s own health under Settings » Servers, and that the vCenter and the instant-clone domain account credentials are valid (an expired domain account password stops customization and leaves desktops in Customizing).

## Verify

After the fix, the desktop should move to “Available” within two minutes of the agent connecting, visible in the Machines tab. Launch a test session from a client, and for pools, watch several desktops provision through Customizing to Available to confirm the chain is healthy.

## Common pitfall

Rebooting the Connection Server as the first response is tempting but rarely helps, because the pairing failure is almost always on the desktop or network side. It also disconnects every user with a session brokered through that server. Work from the desktop outward, and reboot the Connection Server only if its own logs show it failing.

## Horizon Agent Unreachable at a glance

**Official documentation:** [Broadcom TechDocs (VMware)](https://techdocs.broadcom.com/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Fix “The redo log of .vmdk is corrupt” on ESXi and Horizon linked clones](https://srvscripts.com/guides/redo-log-of-vmdk-is-corrupt/) · [Proxmox VE 9 vs ESXi 9 for hosting providers: licensing, storage, backup and migration realities](https://srvscripts.com/guides/proxmox-vs-esxi-9-hosting/) · [Fix “Another task is already in progress” in vCenter with vim-cmd task_info](https://srvscripts.com/guides/vcenter-another-task-is-already-in-progress/).

## Frequently asked questions

### Does Agent Unreachable also occur with RDS desktop pools and published apps?

Yes. RDS hosts run the same Horizon Agent and pair the same way, so the service, DNS, time and port 4001 checks apply. A stuck RDS host takes every session on it out of the pool, which is why it shows more visibly.

### How long does an instant-clone pool take to reprovision after cleanup?

The parent chain rebuilds in a few minutes per host, and desktops then clone at a rate of roughly a few per second across the cluster. A 300-desktop pool typically returns to Available within 15–30 minutes of the image push.

### Can I undo an IcCleanup deletion?

No, but nothing valuable is lost: the internal VMs are regenerated from the golden image snapshot when the pool is next provisioned. Keep the golden image and its snapshot untouched, and the pool can always be rebuilt.
