PowerTags are a powerful feature for customizing virtualized application environments. PowerTags are metatags that can be assigned to various entities within a virtualized environment, including users, user groups, apps, servers, clusters, or the entire account (global). For example, you can use a PowerTag to define custom behavior for sessions or to inject environment variables directly into the Windows session.
Custom behavior with PowerTags
PowerTags offer granular control and can be applied at different levels:
- Individual users
- User groups
- Individual apps
- Sessions
- Specific servers
- Server clusters
- Company account
How to use a PowerTag
To use a PowerTag to customize a feature or a component, you locate the relevant option on the Cameyo Admin console and add a line to the PowerTags input field.
In general:
- PowerTags can be placed at application, server, cluster, user, usergroup or company-wide level.
- If there's no value set, the PowerTag is not used (not enabled).
For example: Prevent accidental tab closure
- On the Cameyo Admin console, click Servers
.
- To open the Details page of your chosen server, click the hyperlinked server name.
- Navigate to General > PowerTags.
- On a new line, enter
!CLOSECONFIRM=1to set a server-wide setting. - At the bottom of the screen, click Save.
- Restart your Cameyo server for the new PowerTag value to take effect for apps running on that server.
Once !CLOSECONFIRM is switched on, every time a user closes a tab, a message displays prompting them to click Leave to confirm that they want to close the tab, or Cancel to return to the app.
Supported PowerTags and their functions
These are the supported PowerTags that you can use to control various aspects of the virtualized environment and user sessions.
Users and Cameyo portal| PowerTag | Description |
|---|---|
!AD_ADMIN_GROUPS |
Allows specified Active Directory (AD) user groups to become Cameyo admins. When configured at the company level, users belonging to the specified AD groups are automatically granted Admin privileges in the Cameyo portal. For more details, see Cameyo user roles. Related tags include:
|
|
|
Company-level PowerTag for setting the authentication cache cookie duration after which the user is logged off and re-authentication is necessary (by default 10 days). Note: This takes effect after a sign-in (so if you're already signed in, sign out and sign in again after applying this PowerTag). |
|
|
|
|
|
Changes browser icon from Cameyo icon to an online ICO file, for example, |
|
|
Delete or report inactive users (company-level PowerTag only). For example:
|
|
|
Cameyo logins only passwords expire after X number of days, after which they must be changed. |
|
|
Cameyo logins only regular expression for password strength validation. |
|
|
Report is submitted by email, or 0 for never. |
|
|
Ukraine-supportive theme and colors for the portal, to be applied at the company level. |
|
|
Disables the ability for end users to access My Profile. |
| PowerTag | Description |
|---|---|
|
|
Controls the Cameyo File Dialog. Set to either Adds extra folders or drive mappings to the Cameyo custom file dialog. Controls the Cameyo File Dialog and allows administrators to make additional local directories or drives visible to users within the custom Open and Save file dialog. |
!EXPLORER |
Controls access to built-in Windows Explorer alongside their Cameyo app. Set to either When enabled, users can launch and interact with the Windows Explorer (explorer.exe) inside their virtual session, providing built-in file browsing and management capabilities alongside the virtualized application. |
|
|
Virtual drive letter for the Public directory. |
|
|
Configures fine-grained directory and file inclusion/exclusion rules for User Profile Cloud Sync (UPCS / Session Sync / Data Persistence). Allows administrators to define which files and folders are synchronized to cloud storage between sessions. Controls the data persistence include and exclude filters for user profile synchronization. Related tags:
Controls data persistence and its include and exclude filters. |
!UPCS_FILTERS |
Controls data persistence and its include and exclude filters. |
|
|
Controls data persistence and its include and exclude filters. |
|
|
Defines the minimum hard-drive space when caching data persistence locally ( |
|
|
Virtual drive letter for user profile. |
| PowerTag | Description |
|---|---|
|
|
Client, user, and machine name virtualization. |
|
|
Sets Chrome as the default browser. |
|
|
Substitutes the execution of an app from a specified directory path. For example, if you want to specify to run |
|
|
File handling using PWA's (File Association) |
|
|
Blocks hard-disk Windows Explorer navigation and basic system commands. |
|
Requires |
|
|
Has to be set at the server level (or cluster or company) but cannot be on a single app or user, as it's a server-global security feature and not per-session. |
|
|
Requires service restart to be applied, for the same reason. |
|
|
|
Defines the starting directory for the session app's execution. |
|
|
Block access to specific files and executables. For example: |
|
|
Using SILOs (Persistence) |
|
|
URLs launched by the session's app will be redirected directly as a new tab within the user's browser, outside the session itself. The url_prefix is in the form: |
|
|
Controls whether Cameyo allows file system integration. |
!WEBFS_TOOLBTN |
Adds a WebFS (Web File System) button to the Cameyo HTML5 WebPlay toolbar. When set to 1, a dedicated button appears in the toolbar allowing users to mount their local browser file system into the remote session via the File System Access API. This is a sub-feature of the main |
|
|
USB redirection using WebUSB. |
| PowerTag | Description |
|---|---|
|
|
Enables or disables clipboard support (from session to client - client to session is always permitted) |
|
|
Defines a fixed session width and height. |
|
|
Controls accidental tab closure. |
|
|
Controls user's cloud drives virtualization, if configured. |
|
|
When |
|
|
Controls extra tool bar buttons. Adds custom buttons to the Cameyo HTML5 WebPlay toolbar. For example:
To add multiple buttons, use a semicolon-separated list. Action can be a URL (opens in browser), a Cameyo app execution (#msg-app-AppID), or a keypress emulation (#msg-keybd-KeyCombo). Icon can be a URL to an image or a Material Design icon keyword. |
!GRACEFULDISCOSECSTARTUP_GRACEFULDISCO_PS1 |
See Graceful application closing. |
|
|
When in full screen mode, session will capture all system keyboard keys including the Windows key, Alt-Tab as well as certain reserved control keys. |
|
|
Setting Cameyo keyboard layout. |
!STARTUP_AFTER_xxxx |
Controls session scripting. |
!STARTUP_BEFORE_BAT |
Executes a Windows batch (.bat) script before the session's main application launches. The script runs asynchronously (does not block session startup). For example, if the session launches WordPad.exe, the script writes the current time to a log file in the user's profile directory just before the app starts.
Use inline scripting with ^| as newline delimiter. Maps to CAMEYO_STARTUP_BEFORE_BAT environment variable. |
!STARTUP_BEFORE_SYNC_xxx |
Controls session scripting. |
!STARTUP_BEFORE_SYNC_BAT |
If you need the session to wait for your Useful for setup tasks that must finish before the app starts For example, mapping network drives, or copying files.
Use ^| as newline delimiter in inline scripts. |
!STARTUP_BEFORE_SYNC_CMD |
Executes a custom Windows command ( Functionally similar to Use ^| as newline delimiter in inline scripts. |
!STARTUP_SYSTEM_PS1 |
Executes an inline PowerShell ( Functionally similar to The script runs during session initialization. |
!STARTUP_GLOBAL |
Controls session scripting. |
!TASKBARMODE |
This PowerTag controls the display mode of the Cameyo taskbar in sessions. For more details, see Cameyo's taskbar. Possible values: 0 = Reserved mode (taskbar reserves OS desktop space, pushing app windows above it), 1 = Overlap mode (taskbar overlays application windows without resizing the desktop work area), 2 = Auto-hide mode (taskbar hides automatically and shows on hover/activity). |
|
|
Cameyo's taskbar allows quick launching and switching between applications. For more details, see Cameyo's taskbar. |
|
|
When |
|
|
When all windows are closed within the session, this PowerTag defines the timeout in milliseconds after which a message will appear to the user saying Application was closed. Session will end in X seconds, where X is defined by !WNDGRACESECOND. |
|
|
See also |
| PowerTag | Description |
|---|---|
|
|
Sends a notification email to the technical contacts every time an Admin session is initiated on a Cameyo server, for increased account security. |
|
|
This is an allow-list of countries (a comma separated list of 2-letter ISO country codes) from which sessions can be requested, at a company-wide, application, server, cluster, user, or usergroup level. For example, |
|
|
This is an allow-list of IP addresses, separated by semicolon, from which sessions can be requested. This allow-list takes precedence over !ALLOW_COUNTRY values, so you can use the two PowerTags together to allow specific IP addresses from blocked countries. |
|
|
Switches Cloud Tunneling on or off. |
| PowerTag | Description |
|---|---|
|
|
Hides the session token out of the URL bar. In some cases, users like to hide the token ID, for example, when they project or share their screens. Note: When the session token is hidden, page refresh (F5) cannot reconnect to the session. |
|
|
Revokes a session's token a few seconds after session authentication. |
|
|
Prevents a session's token from being used from an IP different than the initial one. Notes:
|
|
|
Timeout in seconds after which a session's token can no longer be used. Note that this also neutralizes connection resiliency after the timeout expires. |
| PowerTag | Description |
|---|---|
|
Specifies a custom machine type. You can define the CPU and RAM for the instance using the following syntax: For example, to create an instance with 2 CPUs and 12GB of RAM, you would use: Note: This PowerTag cannot be used in conjunction with For more information, see Google Cloud's General-purpose machine family for Compute Engine. |
!CLOUDCPUGEN |
Specifies the CPU generation for the instance, such as 'n2'. This will create a machine type of For example, |
|
|
For Google Cloud Platform (GCP) only: Custom cloud tags and labels, VPC and subnets for created instances. For more details, see Set up BYO-GCP. |
|
|
(For GCP only) Forces Secure Boot to be enabled on newly-created instances. By default, this PowerTag has no value assigned, which means that Secure Boot is not enabled. |
!CLOUDIP |
(For GCP only)
|
!CLOUDREGION |
(For GCP only) Allows you to pin Cameyo virtual machine groups to a specific Google Cloud Platform (GCP) zone, overriding the default zone assigned to that region. You must use a valid string for GCP zone. For more details, see Set up BYO-GCP. For example:
|
!CLOUDSERIES |
Specifies the CPU series type for the instance, such as For example, C4D VMs are available as predefined configurations in |
|
|
Time, in seconds, to keep sessions alive in case of disconnection. Equivalent to Windows RDS MaxDisconnectionTime parameter. Cameyo's default is 120. |
|
|
Maximum idle time in minutes. Overrides the session policy settings. Requires service restart. |
!RDS_SHADOW |
|
!RDSGRACE_RESET |
The RDS (Remote Desktop Services) grace period is typically 120 days. Cameyo's
|
!RDSGRACE_THRESHOLD_DAYS |
When the grace period falls below the default 90 day threshold, RAP attempts to automatically reset the counter. Admins can adjust this threshold using the
|
|
|
Blocks server access to Cameyo's support team.
|
|
|
When using self-hosted Cameyo servers with Cloud Tunneling, the Tomcat web server is not required. You can disable or uninstall Tomcat. In cases where Tomcat is not required, this PowerTag allows you to turn off alerts about Tomcat not running every time the Play server starts. For more details, see Cloud Tunneling on Cameyo. |
|
|
When using self-hosted Cameyo servers with Cloud Tunneling, the Tomcat web server is not required. You can disable or uninstall Tomcat or run a different HTTP local server, for example, Microsoft's Internet Information Services (IIS). In cases where Tomcat is not required, this PowerTag allows you to turn off alerts about Tomcat not running every time the Play server starts. For more details, see Cloud Tunneling on Cameyo. |
Configuration and order of precedence
PowerTags are dynamic, meaning they can vary from one session to another and take effect immediately, without requiring service nor server restart (except server-level PowerTags).
The order of precedence, from highest priority to least, is:
- User
- User group
- App
- Server
- Cluster
- Company (Account)
Example 1:
If a user has the tag 'MY_NAME=John' defined while the server has 'MY_NAME=Server' defined, a session run by this user on that server will have 'MY_NAME' defined as 'John'.
Example 2:
If the server has tag 'MY_NAME=SERVER' defined while the server's cluster has 'MY_NAME=CLUSTER' defined, sessions will run on this server with 'MY_NAME' defined as 'SERVER'.
Example 3:
If an application has tag 'MY_NAME=SomeApp' while the same global Cameyo account's PowerTag is defined as 'MY_NAME=CameyoAccount' then a session running this app will have 'MY_NAME' defined as 'SomeApp'.
Use multiple PowerTags
You can use multiple PowerTags at one time. When multiple PowerTags exist for a given session (for example, cluster + server + user + app), the session will be started with the combination of all relevant tags.
Multiple tags can be defined on each line, for example:
MY_VAR1=Some value
MY_VAR2=Some other value
Custom PowerTags
You use PowerTags to inject custom values into Cameyo sessions as environment variables. For more advanced control, sticky PowerTags can be used to create persistent, server-wide environment variables.
'+' sticky PowerTags: persistent server-wide environment variables (advanced): apply globally to an entire server, including system processes outside of a Cameyo session, and are defined by adding a + prefix.
- Function: To create global system variables. For example, +MY_GLOBAL_VAR=Some value creates a system variable named "MY_GLOBAL_VAR" with the value "Some value" on the affected servers.
- Scope: These tags can be set for servers, clusters, or entire accounts.
- Activation: A sticky PowerTag only takes effect after the server's Cameyo service (re)starts.
- Removal: To remove a sticky tag, you must set it to an empty value (for example, +MY_GLOBAL_VAR=). The removal takes effect after the Cameyo service restarts and the system is rebooted, which is a Windows requirement.