Horizon Delegate, Omnissa Cloud PC, a hosted MCP server and three new IT agents were the headline demos at Omnissa ONE 2026. Together they show what the company means when it says “autonomous workspace.”
ORLANDO, Fla. – The best demo of the morning involved a sandwich. Huh? Yes, a product manager on the Omnissa ONE 2026 keynote stage typed a request into a chat window: find Acme’s latest sales spreadsheet and list the top 10 accounts. Then she closed her laptop and walked off to order lunch. A few minutes later, she pulled out her phone. The answer was waiting.
It sounds like a party trick, doesn’t it? Closing a laptop lid is the most boring gesture in computing. But the trick wasn’t the point. The point was where the work happened, who it happened as, and what stopped it from wandering off. That’s what this story is about.
Horizon Delegate: a chat window with a desktop behind it
Horizon Delegate is a new way to use a Horizon virtual desktop without looking at the desktop at all. Instead of watching an agent click around a screen, you chat with it. The message is relayed into your virtual machine, where an agent hands it to an AI model and gets on with the job.
At launch it runs in the Horizon web client, so it works in nearly any browser on any device with nothing to install. The first integration is GitHub Copilot, and customers bring their own license. The presenter was blunt about the strategy: Horizon is not in the AI model business, and the model should be swappable. We were told to expect other options later.
Jeff McGrath, vice president of product marketing, gave me two scenarios that made the idea click. In the first, you’re deep in a presentation on your laptop when you remember an email your boss wants about your quarterly pipeline. You tell Delegate to run your Salesforce report and email it. Behind the scenes, your VM wakes up, the agent runs the report, sends the email and shuts the machine down, and every step is logged. You never stopped working.
In the second, you’re on a hike with only your iPhone and suddenly remember the same report.
McGrath said: “I can launch Horizon, click on Delegate and say, can you please run my October Salesforce report and send a pipeline report to my boss via email and copy me. And I just continue on my hike, and when it’s done, I get an alert.”
The connection goes from the phone straight to the virtual desktop, Horizon brokers it, and Omnissa says there’s no cloud service in between and no need to expose the desktop to the public internet.
“Won’t my security team hate this?”
That was my first thought, and I put it to Chief Product Officer Bharath Rangarajan. If work keeps going after you disconnect, what stops the agent from doing things nobody intended? His answer was less dramatic than I expected, and that turned out to be reassuring.
As he put it, “The delegate does nothing different. The security model has already been hardened. It’s tied to enterprise identity, so you can have two-factor authentication, you can have device-based biometric authentication. Delegate inherits that. It just looks like the user.”
The demo on stage during the keynote backed him up. The agent doesn’t run under a special service account. It runs as the user, with the user’s policies and entitlements, and if the user can’t open a file, neither can the agent. Rangarajan did draw a line, though. Delegate itself isn’t the risk. The agent behind it, the Copilot in this case, could be hijacked, and that job belongs to other tools. He pointed to Workspace ONE and Elara, Omnissa’s new AI governance product, to watch for that.
Why a virtual desktop makes a decent cage
Here’s a mild contradiction worth clearing up. Virtual desktops are supposed to be the old guard of enterprise IT, and yet Omnissa spent much of the keynote arguing they’re perfect for the newest workloads. McGrath’s explanation is practical.
“When you manifest a virtual desktop, it’s got your application entitlements. It’s got your security policies, so that agent is running as you. It has no way to elevate its privileges. And that desktop is ephemeral. It can be dissolved and you’re done.”
Add the data loss prevention controls VDI already has, like blocking saves to the local device or copying into another application, and you get a container built for the job. McGrath says some of Omnissa’s regulated customers, banks among them, are already doing this, and they had to tell Omnissa because nobody had marketed it that way. New CEO Amit Singh made the same point from the stage: Omnissa has ephemeral places for endpoints to run, permissioning structures, and a way to tear it all down.
Horizon’s supported platforms keep growing, too, which matters when your agent’s home might not sit on vSphere. McGrath walked me through the list:
- Already in play: Nutanix AHV (which he called a huge success), Amazon WorkSpaces Core, and Windows 365, where Omnissa’s agent on the image enables its Blast protocol to tune Zoom, Teams and Webex.
- Coming over this quarter and next: Red Hat OpenShift, OpenStack and HPE VM Essentials.
- Cloud additions: Google Cloud and Google Distributed Cloud, its on-premises stack.
By his count, that pushes the number of supported platforms to about 15. It’s no longer just vSphere.
Omnissa Cloud PC: the desktop with the compute included
The keynote announcement that drew a noticeable amount of applause from the attendees was Omnissa Cloud PC. It is a desktop as a service where the underlying compute comes with it. Omnissa runs Horizon Cloud behind the scenes, and you buy the desktop you need at a fixed price by size across the Americas, EMEA and APAC. Everything customers like about Horizon comes along: the Blast protocol, client choice, broad peripheral support, and Workspace ONE UEM for device management. Digital employee experience monitoring is built in from day one.
At launch it runs on AWS. McGrath said the close relationship from Amazon WorkSpaces Core work made it the natural first choice. He’s careful not to name the next one, since these are OEM-style negotiations with plenty of legal fine print, but Omnissa is talking to all of the major clouds, and a bring-your-own option would let customers with existing Google Cloud or Azure contracts point the service at them.
I asked whether customers had been demanding this. McGrath compared it to Microsoft’s Windows 365 and said the simplicity is a big part of the appeal.
“If you’re a Dell Market customer and you need 50 desktops, you can just take one of their t-shirt sizes, scan a credit card, and off you go. But when you get to Windows 365 Enterprise, you go through a six-month architecture planning cycle. A lot of people don’t realize that,” explained McGrath.
Sizes run from task worker to power user and include GPUs. The pitch to existing Horizon shops is that they can hand cloud PCs to the users who don’t need a custom build, augment what they already run, and stay with a vendor they trust rather than answering their Microsoft rep’s question about Azure Virtual Desktop.
Meet Jack, the agentic admin
Users get Delegate. Admins get the hosted Omnissa MCP server, which might be the most quietly useful announcement of the day. It lets an administrator connect the AI tool they already use, whether that’s Claude, Copilot or Gemini Enterprise, to services across the platform: UEM, Horizon, intelligence, DEX, Hub and access.
The keynote demo followed a fictional admin named Jack. A super admin first decides who gets which permissions. Jack generates an access token scoped service by service, in this case full scope for intelligence, UEM and Hub, and read-only for Horizon and access. Then he starts asking Claude questions.
Of nearly 10,000 devices, 219 were out of compliance, mostly Windows. When Jack asked why, Claude looked through policies and found that 30 percent of the R&D department’s Windows machines were failing one policy because of an outdated version of 7-Zip. Claude offered to publish the current version through a phased deployment template. Since an agent was pushing the change, dual approval kicked in, and a second admin had to sign off.
The second scenario was even better. Users couldn’t launch a Horizon desktop from the app, yet Horizon reported the pool healthy with zero errors. Claude spotted that concurrent users had climbed and the pool sizing hadn’t been touched in years. It couldn’t change anything, because Jack’s token for Horizon was read-only, so it offered to open a change ticket instead. The presenter’s point was that a separate MCP built on a single product’s APIs would have shown a healthy pool and stopped there.
McGrath’s shorthand was the one I’ll borrow.
“It’s almost like a super API to the entire platform.”
Tools only see what the admin’s role and token allow, and McGrath noted that the agent can touch what a person can touch, but nothing more.
Three agents (and a fourth still on the bench)
Talking to a platform is one thing. Having it fix problems is another. Omnissa announced three agents for IT, all in beta or headed there, built on the idea that management, security and experience should be one conversation instead of three consoles.
The DEX agent
This is the one I’d most want on my own team. The demo opened at nine in the morning with logons running 68 seconds against a 55-second baseline and 340 sessions affected. The agent checked the entire login path, correlated other data sources, and produced six possible causes, with the top answer at roughly 80 percent confidence: a profile update landed right before logons slowed. It proposed a remediation script, the admin approved, and all 340 sessions recovered. Then the agent kept watching for half an hour before closing the case itself.
In the second example, OneDrive kept failing to reinstall and no playbook existed. The agent went looking at how the team had solved it before, found 103 Workspace ONE Assist sessions with the same fix (orphaned registry keys), and wrote a new playbook from scratch. A ticket became a reusable fix.
The Vulnerability Defense agent
Workspace ONE Vulnerability Defense, which uses CrowdStrike exposure data, is generally available now. McGrath says the tool weighs severity, exploitability and accessibility to build a risk-ranked list and recommends the fix. The new agent, in beta, goes further: it scores vulnerabilities on CVSS severity, whether an exploit exists in the wild, likelihood of exploitation in the next 30 days, and how many devices are affected. In the demo it found a GlobalProtect flaw, located the fixed version across three organization groups, and rolled it out in phases. A human approves every step, and the presenter noted that vulnerabilities can now be exploited in less than a day.
The app packaging agent
Anyone who has packaged Windows applications knows the drill of installers, silent switches and dependencies, followed by a new version that starts it all over. The agent spotted a new Acrobat release, saw that more than 4,000 devices were behind, and presented a plan before doing anything. The admin chose to send it to user acceptance testing first. Meanwhile, it packaged a Notepad++ update on its own, because trusted apps don’t always need a person’s review. This agent is planned to enter beta by the end of the year.
McGrath also mentioned an onboarding agent that would cut down the laptop-unboxing routine IT teams know too well. That one is still TBD.
So, what is an autonomous workspace?
I asked Rangarajan for a definition, since it’s the theme of the whole show. He said:
“It boils down to three defining characteristics: self-configuring, self-healing and self-securing. But I’d rather define it by the outcome, which is almost like bliss and peace of mind. Bliss from an end user perspective, and peace of mind from an IT perspective.”
The bliss reference wasn’t lost on him; he hadn’t realized until CEO Amit Singh mentioned it on stage that Singh’s meditation app carries the same name. Self-securing is the hardest of the three, he said, and Omnissa is chipping away at it with vulnerability defense.
There’s some muscle behind the claim. Omnissa cites about 50 TB of endpoint data a day and 150 million workflow executions a month across tens of millions of endpoints. Its press materials add that Gartner’s 2026 report on endpoint management tools ranked the company highest in all four use cases, including autonomous endpoint management. A new reseller relationship with 2Pint Software for bare-metal imaging adds a fast way to wipe and rebuild a device after ransomware, or simply onboard a new laptop straight from the box.
Not everything is finished. Delegate, the DEX agent and the vulnerability agent are early, the packaging agent hasn’t started beta, and Cloud PC is AWS-only for now. The pieces are real, though, and they connect in a way I didn’t expect from a company I have long filed under “the Horizon people.”
Rangarajan closed the keynote by telling attendees that managing and securing endpoints is their next hero moment, and that reaching it is “completely actionable.” My advice is simpler: ask your Omnissa account team which of these you can put in front of real users, and try it on something small. Slides only get you so far.
##






