Citrix DaaS™

Government Cloud prerequisites for VDA upgrades (VUS)

This article documents customer-side prerequisites for upgrading VDAs through the VDA Upgrade Service (VUS) in the Production Government environment.

Use this guidance when outbound firewall or proxy controls are enforced and egress is restricted.

Pre-requisites

These prerequisites apply to Government customers who use VUS to upgrade persistent VDAs and need to allow required outbound connections for package download, schedule retrieval, and version reporting.

This guidance is in addition to the standard VUS prerequisites in Prerequisites for upgrading VDAs using VUS.

Required outbound endpoint access

Allow outbound HTTPS (TCP 443) from the following sources:

  • VDAs that run the VDA Upgrade Agent.
  • Cloud Connectors, when traffic is connector-routed.

Allow-list the following destination patterns:

  • Prod Government VUS release CDN endpoint pattern: https://prod-us-gov-vus-release-endpoint-.z01.azurefd.us/prod-us-gov-vus-release-container/
  • Per-customer Government DDC REST endpoint pattern: https://[customerId].xendesktop.us/citrix/vdaupdateservice/*

Why these endpoints are required

Endpoint pattern Purpose Used by
https://prod-us-gov-vus-release-endpoint-.z01.azurefd.us/prod-us-gov-vus-release-container/ Downloads VDA installer packages for scheduled upgrades. VDA Upgrade Agent download flow
https://[customerId].xendesktop.us/citrix/vdaupdateservice/* Gets VUS schedules and posts VDA version report calls. VDA Upgrade Agent control plane calls

If either endpoint is blocked by firewall, proxy, SSL inspection policy, or DNS filtering, upgrades can fail.

Government storage and KeyVault pre-requisites

Government storage account and KeyVault resources used by the VUS release pipeline are managed on the service side.

Customer action is typically limited to network egress policy configuration for VDAs and Cloud Connectors. If your organization applies additional outbound controls or private routing constraints, coordinate validation with your Citrix support and security teams before scheduling production upgrades.

FedRAMP boundary considerations

  • Review your FedRAMP boundary controls for outbound HTTPS to Azure Government Front Door endpoints (*.azurefd.us) and customer-specific xendesktop.us endpoints.
  • Document approved destination patterns and control rationale in your SSP and change records.
  • If TLS inspection is mandatory, validate that certificate handling does not break VDA installer download or API communication.

Pre-upgrade verification checklist

  • Confirm DNS resolution and TCP 443 reachability from each VDA subnet to the required *.azurefd.us endpoint.
  • Confirm DNS resolution and TCP 443 reachability from each VDA subnet to https://[customerId].xendesktop.us.
  • Confirm the same reachability from Cloud Connectors for connector-routed traffic paths.
  • Run a pilot VUS upgrade on a small machine set and verify package download and version report success.
Government Cloud prerequisites for VDA upgrades (VUS)