Preview: Citrix HDX Plus for Windows 365


This feature is in preview and as such it is not officially supported. You can submit your feedback through this form.

Citrix HDX Plus for Windows 365 allows you to integrate Citrix Cloud with Windows 365 to use Citrix HDX technologies for an enhanced and more secure Windows 365 Cloud PC experience in addition to other Citrix Cloud services for enhanced manageability.


Following are the pre-requisites for the solution:


  • Citrix Cloud tenant with HDX Plus for Windows 365 entitlement.
    • Citrix DaaS Premium.
    • Citrix DaaS Premium Plus.
    • Citrix DaaS Advanced Plus.
  • Citrix administrator account with full administrator rights.
  • Cloud PCs must have access to:
    • https://* on TCP 443.
    • https://*.* on TCP 443 and UDP 443 for HDX sessions over TCP and EDT, respectively. If you can’t allow all subdomains in that manner, you can use https://* and https://* instead. For more information, see Knowledge Center article CTX270584.
    • https://* on TCP 443. If you can’t allow all subdomains in that manner, you can use https://<customer_ID>, where customer_ID is your Citrix Cloud customer ID as shown in the Citrix Cloud administrator portal.
  • For hybrid Azure AD joined deployments:
    • The Azure AD domain must be synchronized from the AD domain the machines belong to.
    • Cloud Connectors to allow Citrix Cloud to connect to your Active Directory domain. Refer to Cloud Connectors for details on how to configure.


  • Microsoft Endpoint Manager (MEM) entitlement
  • Azure Active Directory domain in the same tenant as MEM
  • Windows 365 Enterprise licenses in the same tenant as MEM
  • Azure administrator account:
    • Azure AD Global administrator
    • Intune Global administrator

Supported Configurations

Citrix HDX Plus for Windows 365 supports integrating with Windows 365 deployments with pure Azure AD joined Cloud PCs and Hybrid Azure AD joined Cloud PCs. Following are details of the supported configurations for each scenario.

Supported infrastructure

Machine identity Citrix Cloud CVAD On-prem Citrix Workspace Citrix StoreFront Citrix Gateway Service Citrix Gateway
Azure AD joined Yes No Yes No Yes No
Hybrid Azure AD joined Yes No Yes No Yes No

Supported identity providers

Machine identity Azure Active Directory Active Directory Active Directory + Token Okta SAML Citrix Gateway Adaptive Authentication
Azure AD joined Yes No No No No No No
Hybrid Azure AD joined Yes Yes Yes Yes Yes Yes Yes


If using an identity provider other than Active Directory or Active Directory + Token with hybrid AD joined deployments, you need Citrix Federated Authentication Service (FAS) to achieve single sign-on (SSO) to the Cloud PC. Refer to the FAS documentation for details.

Hybrid Azure AD Joined

If you are planning to deploy Cloud PCs that are Hybrid Azure AD joined, you must add Cloud Connectors to your Citrix Cloud environment before you continue with the configuration. This allows your Citrix Cloud tenant to access your Active Directory domain for resource and policy assignments.

You can use either the Windows-based Cloud Connector or the Connector Appliance. Details for configuring these are available in Citrix Cloud Connector and Connector Appliance for Cloud Services.

If you plan to use FAS for SSO into the Cloud PC, consider configuring Azure AD certificate-based authentication to ensure that a Primary Refresh Token (PRT) is generated upon user logon to allow SSO into Azure AD based applications inside the session.

Configuration Overview

To configure W365, complete the following steps in order:

  1. Enable the Citrix connector for Windows 365
  2. Connect Azure Active Directory to Citrix Cloud
  3. Configure Citrix Workspace
  4. Connect Windows 365 to Citrix Cloud
  5. Assign Citrix licenses to your users
  6. Provision Cloud PCs

Once Citrix licenses are assigned to users, Citrix communicates to the Windows 365 service that the selected users are entitled to use Citrix to access their Cloud PCs. If the selected users already have Cloud PCs provisioned, Windows 365 automatically installs the Citrix Virtual Delivery Agent (VDA) on those Cloud PCs and switches the user’s access to Citrix. If the selected users do not have Cloud PCs assigned, the VDA is installed immediately after the Cloud PC is provisioned at the time of Windows 365 license assignment.

After the VDA is installed, it registers with Citrix Cloud and any necessary Machine Catalogs and Delivery Groups are created automatically. Cloud PCs are then available through Citrix Workspace. A Citrix policy is also created for each Windows 365 delivery group to enable required features.

The next sections provide detailed instructions for each of the above configuration steps.

Limitations and Known Issues

  • Citrix HDX Plus for Windows 365 is not available in Citrix Cloud Japan, Citrix Cloud Gov, or CSP tenants.
  • Citrix license assignment can only be done per user currently. Assigning licenses to Azure AD groups is not supported.
  • Performing an in-place Windows version upgrade on the Cloud PC causes the VDA to not register with the Citrix site and users are not able to launch their desktops.
  • Windows Hello is not supported to log into the virtual desktop. For more information, see Provision Cloud PCs.

Additional resources

Preview: Citrix HDX Plus for Windows 365