Connect Microsoft Entra ID as an identity provider
By default, Citrix Cloud Japan uses the Citrix identity provider to manage the identity information for all users in your Citrix Cloud Japan account. You can change this to use Microsoft Entra ID to authenticate Citrix Cloud Japan administrators as well as workspace subscribers.
By using Microsoft Entra ID with Citrix Cloud Japan, you can:
- Use your own Active Directory so you can control auditing, password policies, and easily disable accounts when needed.
- Configure multi-factor authentication for a higher level of security against the possibility of stolen sign-in credentials.
- Use a branded sign-in page so your users know they’re signing in at the right place.
- Use federation to an identity provider of your choice including ADFS, Okta, and Ping, among others.
Microsoft Entra ID applications and permissions
Citrix Cloud Japan includes an Microsoft Entra ID app that allows Citrix Cloud Japan to connect with your Microsoft Entra ID without the need for you to be logged in to an active Microsoft Entra ID session. For more information about the Microsoft Entra ID applications and permissions that Citrix Cloud Japan uses to connect with your Microsoft Entra ID, see Microsoft Entra ID permissions for Citrix Cloud Japan.
Prepare your Active Directory and Microsoft Entra ID
Before you can use Microsoft Entra ID, be sure you meet the following requirements:
- You have a Microsoft Azure account. Every Azure account comes with Microsoft Entra ID free of charge. If you don’t have an Azure account, sign up at https://azure.microsoft.com/en-us/free/?v=17.36.
- You have the Global Admin role in Microsoft Entra ID. This role is required to give Citrix Cloud Japan your consent to connect with Microsoft Entra ID.
- Administrator accounts have their “mail” property configured in Microsoft Entra ID. To do this, you can sync accounts from your on-premises Active Directory into Microsoft Entra ID using Microsoft’s Microsoft Entra ID Connect tool. Alternatively, you can configure non-synced Microsoft Entra ID accounts with Office 365 email.
Sync accounts with Microsoft Entra ID Connect
- Ensure the Active Directory accounts have the Email user property configured:
- Open Active Directory Users and Computers.
- In the Users folder, locate the account you want to check, right-click and select Properties. On the General tab, verify the Email field has a valid entry. Citrix Cloud Japan requires that administrators added from Microsoft Entra ID have different email addresses than administrators who sign in using a Citrix-hosted identity.
- Install and configure Microsoft Entra ID Connect. For complete instructions, see Integrate your on-premises directories with Microsoft Entra ID on the Microsoft Azure web site.
Connect Citrix Cloud Japan to Microsoft Entra ID
When connecting your Citrix Cloud Japan account to your Microsoft Entra ID, Citrix Cloud Japan will need permission to access your user profile (or the profile of the signed-in user) as well as the basic profiles of the users in your Microsoft Entra ID. Citrix requests this permission so it can acquire your name and email address (as the administrator) and enable you to browse for other users and add them as administrators later.
- Sign in to Citrix Cloud Japan at https://citrix.citrixcloud.jp.
- Click the menu button in the top-left corner of the page and select Identity and Access Management.
- Locate Microsoft Entra ID, click the ellipsis button, and then select Connect.
- When prompted, enter a short, URL-friendly identifier for your company and click Connect. The identifier you choose must be globally unique within Citrix Cloud Japan.
- When prompted, sign in to the Azure account with which you want to connect. Azure shows you the permissions that Citrix Cloud Japan needs to access the account and acquire the information required for connection.
- Click Accept to accept the permissions request.
Add administrators to Citrix Cloud Japan from Microsoft Entra ID
- From the Citrix Cloud Japan management console, from the Identity and Access Management page, click the Administrators tab.
- Select Add administrator/group.
- In Administrator details, select Microsoft Entra ID.
- Type the name of the user you want to add and then click Next. Inviting Microsoft Entra ID guest users is not supported.
- In Set access, configure the appropriate permissions for the administrator.
- Review the administrator details. Select Back to make any changes.
- Select Send invitation. Citrix Cloud Japan sends an invitation to the user you specified and adds the administrator to the list.
After clicking the email link, the user signs in to the company’s Microsoft Entra ID. This verifies the user’s email address and completes the connection between the Microsoft Entra ID user account and Citrix Cloud Japan.
Add Microsoft Entra ID administrator groups to Citrix Cloud Japan
You can add administrators to your Citrix Cloud Japan account using Microsoft Entra ID groups. You can then manage service access permissions for all administrators in the group.
This feature is supported for use only with Citrix DaaS™ (formerly Virtual Apps and Desktops service). Administrators in the group don’t have access to manage any other services in the Citrix Cloud Japan account.
For more information, see Manage administrator groups.
Sign in to Citrix Cloud Japan using Microsoft Entra ID
After the Microsoft Entra ID user accounts are connected, administrators can sign in to Citrix Cloud Japan using one of the following methods:
- Navigate to the administrator sign-in URL that you configured when you initially connected the Microsoft Entra ID identity provider for your company. Example:
https://citrix.citrixcloud.jp/go/myorganization - From the Citrix Cloud Japan sign-in page, click Sign in with my company credentials, type the identifier you created when you initially connected Microsoft Entra ID, and click Continue.
Enable Microsoft Entra ID authentication for workspaces
After you connect Microsoft Entra ID to Citrix Cloud Japan, you can allow your subscribers to authenticate to their workspaces through Microsoft Entra ID.
Important:
Before enabling Microsoft Entra ID workspace authentication, review the Microsoft Entra ID section for considerations for using Microsoft Entra ID with Citrix Workspace.
- From the Citrix Cloud Japan menu in the upper-left corner, select Workspace Configuration.
- Select the Authentication tab and then select Microsoft Entra ID.
- Click Confirm to accept the workspace experience changes that will occur when Microsoft Entra ID authentication is enabled.
Enable advanced Microsoft Entra ID capabilities
Microsoft Entra ID provides advanced multi-factor authentication, world-class security features, federation to 20 different identity providers, and self-service password change and reset, among many other features. Turning these features on for your Microsoft Entra ID users enables Citrix Cloud Japan to use those capabilities automatically.
Reconnect to Microsoft Entra ID for the updated app
In April 2022, the Microsoft Entra ID app used in Citrix Cloud Japan was updated to use the GroupMember.Read.All permission, which replaces the Group.Read.All permission.
If you connected your Microsoft Entra ID to Citrix Cloud Japan before April 2022 and you want to use the latest updated app, you need to disconnect your Microsoft Entra ID from Citrix Cloud Japan and then reconnect it. Using the latest app is optional. If you choose not to update the app, your existing connection still functions normally.
Requirements
Before you reconnect your Microsoft Entra ID, verify that you meet the following requirements:
- You must be a Global Admin in Microsoft Entra ID. When reconnecting your Microsoft Entra ID, you grant application-level permissions to Citrix Cloud Japan through the Global Admin role in Microsoft Entra ID. This allows Citrix Cloud Japan to reconnect to Microsoft Entra ID on your behalf. For more information, see Microsoft Entra ID Permissions for Citrix Cloud Japan.
- You must be an administrator with full access permissions under the default Citrix identity provider. If you are signed in to Citrix Cloud Japan with your Microsoft Entra ID credentials, the reconnection fails. If you don’t have any administrators using the Citrix identity provider in your account, you can temporarily add one and delete it after reconnecting your Microsoft Entra ID. For instructions, see Invite individual administrators.
- If you are using Microsoft Entra ID to authenticate workspace subscribers, select a different identity provider temporarily. Citrix Cloud Japan doesn’t allow you to disconnect your Microsoft Entra ID if it’s also used as an authentication method for Citrix Workspace. For more information, see Choose or change authentication methods in the Citrix Workspace documentation.
To reconnect Microsoft Entra ID
- Sign in to Citrix Cloud Japan as an administrator with full access permissions under the Citrix identity provider.
- From the Citrix Cloud Japan menu, select Identity and Access Management and then select Authentication.
- Locate Microsoft Entra ID and select Disconnect from the ellipsis menu at the far right of the page.
- From the ellipsis menu, select Connect.
- When prompted, sign in to your Azure account using your Global Admin credentials. Azure shows you the permissions that Citrix Cloud Japan needs to access the account and acquire the information required for the connection.
- Select Accept to accept the permissions request.
In this article
- Microsoft Entra ID applications and permissions
- Prepare your Active Directory and Microsoft Entra ID
- Connect Citrix Cloud Japan to Microsoft Entra ID
- Add administrators to Citrix Cloud Japan from Microsoft Entra ID
- Add Microsoft Entra ID administrator groups to Citrix Cloud Japan
- Sign in to Citrix Cloud Japan using Microsoft Entra ID
- Enable Microsoft Entra ID authentication for workspaces
- Enable advanced Microsoft Entra ID capabilities
- Reconnect to Microsoft Entra ID for the updated app