Citrix Secure Private Access™

Managed profile identity

Google directory identifies every user account by a primary email address. When your organization synchronizes users from Active Directory or Microsoft Entra ID into the Google directory, you choose which source attribute becomes that address. Most organizations map the email address. Organizations that do not populate the email attribute for every user, may map the User Principal Name (UPN) instead, because the UPN is always present in Active Directory.

Secure Private Access must look up each user by the same attribute that your directory synchronization used as the primary address, otherwise it cannot match the user to their account in the Google directory. You can set up the attribute from the Managed profile identity page in the Secure Private Access admin console.

Set up the user attribute type

  1. In the Secure Private Access admin console, navigate to Browser Settings > Managed Profile Identity.
  2. In Google user ID type, select the attribute Secure Private Access uses to identify CEP end users.

    Attribute type

    • Email - Secure Private Access identifies end users by their email address. This is the default value and the one used by existing deployments.

    • User Principal Name - Secure Private Access identifies end users by their User Principal Name (UPN).

  3. Click Save.
  4. In the Update Google user ID type? confirmation window, review the message and click Update.

A confirmation message appears when the setting is saved.

Note:

  • The Google user ID type setting applies to users only. Google groups do not have a User Principal Name, so group identity is unaffected. If your groups have no email address in the source directory, see Domain mapping for user groups without email addresses.

  • The setting is applied tenant-wide. You cannot select a different identity attribute for individual users.

Managed profile identity