Citrix DaaS™

Web sign-in

You can use the Citrix web sign-in credential provider to enable the use of Entra ID based Windows authentication. This allows users to log into or unlock their virtual desktops using any authentication method that is enabled in Entra ID.

IMPORTANT

Web sign-in is currently in preview. This feature is provided without support and is not yet recommended for use in production environments.

System requirements

The following are the system requirements for using web sign-in:

  • Virtual Delivery Agent
    • Windows: single session version 2607 or later
  • Citrix Workspace app
    • Windows: version 2607 or later
  • Session host identity: Entra joined or Entra hybrid joined
  • Session host OS:

How to configure web sign-in

Citrix web sign-in is disabled by default. To enable it, follow these steps:

  1. Complete the Azure and Microsoft Entra ID configuration described in the Microsoft Entra single sign-on documentation. If you have Microsoft Entra single sign-on enabled in your environment, you can continue to the next step.

    The relevant steps are:

    1. Register the Citrix resource and client applications.
    2. Enable the Microsoft Entra ID Remote Desktop Services authentication protocol for the Citrix resource application.
    3. Hide the user consent prompt.
    4. Approve the client application.
    5. Create a Kerberos server object (Microsoft Entra hybrid joined environments only).
    6. Review Microsoft Entra Conditional Access policies.
  2. Enable the Web sign-in setting in a Citrix policy and apply the policy to the appropriate delivery groups.

NOTE

  • It is not necessary to use Microsoft Entra single sign-on to use web sign-in.

  • If the policy setting is not yet available in your tenant, you can enable web sign-in via the registry:

    • Key: HKLM\SOFTWARE\Policies\Citrix\ICAPolicies
    • Value type: DWORD
    • Value name: AllowWebSignIn
    • Value data: 1

How to use web sign-in

To use Citrix web sign-in to log in or unlock your virtual desktop:

  1. Select the Citrix tile from the logon methods available.

    Windows logon options

  2. Click on Citrix Web Sign-in.

    Web sign-in button

  3. Once the authentication prompt pops up, authenticate with the required authentication method.

NOTE

The authentication methods available to the user are determined by what is enabled in Microsoft Entra ID.

Web sign-in