Create application groups
Application groups let you manage collections of applications. Create application groups for applications shared across different delivery groups. Or, applications used by a subset of users within delivery groups. Application groups are optional; they offer an alternative to adding the same applications to multiple delivery groups. Associate delivery groups with more than one application group, and associate an application group with more than one delivery group.
Using application groups can provide application management and resource control advantages over using more delivery groups:
- The logical grouping of applications and their settings lets you manage those applications as a single unit. For example, you don’t have to add (publish) the same application to individual delivery groups one at a time.
- Session sharing between application groups can conserve resource consumption. In other cases, disabling session sharing between application groups can be beneficial.
- You can use the tag restriction feature to publish applications from an application group, considering only a subset of the machines in selected delivery groups. With tag restrictions, you can use your existing machines for more than one publishing task, saving the costs associated with deploying and managing extra machines. A tag restriction can be thought of as subdividing (or partitioning) the machines in a delivery group. Using an application group or desktops with a tag restriction can be helpful when isolating and troubleshooting a subset of machines in a delivery group.
The following graphic shows a Citrix Virtual Apps and Desktops deployment that includes application groups:
In this configuration, applications are added to the application groups, not the delivery groups. The delivery groups specify which machines are used. (Although not shown, the machines are in machine catalogs.)
Application group 1 is associated with delivery group 1. Access the applications in application group 1 by the users specified in application group 1. These groups only appear as long as they are also in the user list for delivery group 1. This configuration follows the guidance that the user list for an application group is a subset (a restriction) of the user lists for the associated delivery groups. The settings in application group 1 (such as application session sharing between application groups, associated delivery groups) apply to applications and users in that group. The settings in delivery group 1 apply to users in application groups 1 and 2, because those application groups have been associated with that delivery group.
Application group 2 is associated with two delivery groups: 1 and 2. Each of those delivery groups is assigned a priority in application group 2, indicating the order in which the delivery groups are checked when an application is launched. Delivery groups with equal priority are load balanced. Access the applications in application group 2 by the users specified in application group 2. However, they must also appear in the user lists for delivery group 1 and delivery group 2.
This simple layout uses tag restrictions to limit which machines are considered for certain desktop and application launches. The site has one shared delivery group, one published desktop, and one application group configured with two applications.
Tags have been added to each of the three machines (VDA 101–103).
The application group was created with the “Orange” tag restriction. Each of its applications is launched only on machines in that delivery group that have the tag “Orange,” VDA 102 and 103.
For more comprehensive examples and guidance for using tag restrictions in application groups (and for desktops), see Tags.
Guidance and considerations
Citrix recommends adding applications to either application groups or delivery groups, but not both. Otherwise, the additional complexity of having applications in two group types can make it more difficult to manage.
By default, an application group is enabled. After you create an application group, you can edit the group to change this setting. See Manage application groups.
By default, application session sharing between application groups is enabled. See Session sharing between application groups.
Citrix recommends upgrading your delivery groups to the current version. This process requires:
- Upgrading VDAs on the machines used in the delivery group.
- Upgrading the machine catalogs containing those machines.
- Upgrading the delivery group.
For details, see Manage delivery groups.
To use application groups, your core components must be minimum version 7.9.
Creating application groups requires the delegated administration permission of the Delivery Group Administrator built-in role. See Delegated administration for details.
This article refers to “associating” an application with more than one application group. It differentiates that action from adding instances of that application from an available source. Similarly, delivery groups are associated with application groups, rather than being additions or components of one another.
Session sharing with application groups
When application session sharing is enabled, all applications launch in the same application session. This saves the costs associated with launching more application sessions, and allows the use of application features that involve the clipboard, such as copy-paste operations. However, in some situations you can clear session sharing.
When you use application groups you can configure application session sharing in the following three ways which extend the standard session sharing behavior available when you are using only delivery groups:
- Session sharing enabled between application groups.
- Session sharing enabled only between applications in the same application group.
- Session sharing disabled.
Session sharing between application groups
You can enable application session sharing between application groups, or you can disable it to limit application session sharing only to applications in the same application group.
An example when enabling session sharing between application groups is helpful:
Application group 1 contains Microsoft Office applications such as Word and Excel. Application group 2 contains other applications such as Notepad and Calculator, and both application groups are attached to the same delivery group. A user who has access to both application groups starts an application session by launching Word, and then launches Notepad. If the controller finds that the user’s existing session running Word is suitable for running Notepad then Notepad is started within the existing session. If Notepad cannot be run from the existing session—for example if the tag restriction excludes the machine that the session is running on—then a new session on a suitable machine is created rather than using session sharing.
An example when disabling session sharing between application groups is helpful:
A configuration with a set of applications that do not interoperate well with other applications that are installed on the same machines. Such as two different versions of the same software suite or two different versions of the same web browser. You prefer not to allow a user to launch both versions in the same session.
Create an application group for each version of the software suite, and add the applications for each version of the software suite to the corresponding application group. If session sharing between groups is disabled for each of those application groups, a user specified in those groups can run applications of the same version in the same session. The user can still run other applications at the same time, but not in the same session. When launching one of the different-versioned applications, or any application that is not contained in an application group, that application is launched in a new session.
This session sharing between application groups feature is not a security sandboxing feature. It is not foolproof, and it cannot prevent users from launching applications into their sessions through other means (for example, through Windows Explorer).
If a machine is at capacity, new sessions are not started on it. New applications are started in existing sessions on the machine as needed using session sharing.
You can only make prelaunched sessions available to application groups which have application session sharing allowed. (Sessions which use the session linger feature are available to all application groups.) These features must be enabled and configured in each of the delivery groups associated with the application group. You cannot configure them in the application groups.
By default, application session sharing between application groups is enabled when you create an application group. You cannot change this when you create the group. After you create an application group, you can edit the group to change this setting. See Manage application groups.
Disable session sharing within an application group
You can prevent application session sharing between applications which are in the same application group.
An example when disabling session sharing within application groups is helpful:
You want your users to access multiple simultaneous full screen sessions of an application on separate monitors.
You create an application group and add the applications to it.
By default, application session sharing is enabled when you create an application group. You cannot change this setting when you create the group. After you create an application group, you can edit the group to change this setting. See Manage application groups.
Create an application group
To create an application group:
- Select Applications in the Studio navigation pane, and then select Create Application Group in the Actions pane.
- The wizard launches with an Introduction page, which you can remove from future launches of this wizard.
- The wizard guides you through the pages described in the following section. When you are done with each page, click Next until you reach the Summary page.
Step 1. Delivery Groups
The Delivery Groups page lists all delivery groups, with the number of machines each group contains.
- The Compatible Delivery Groups list contains delivery groups you can select. Compatible delivery groups contain random (not permanently or statically assigned) multi-session or single-session OS machines.
- The Incompatible Delivery Groups list contains delivery groups you cannot select. Each entry explains why it is not compatible, such as containing statically assigned machines.
An application group can be associated with delivery groups containing shared (not private) machines that can deliver applications.
You can also select delivery groups containing shared machines that deliver only desktops, if both of the following conditions are met:
- The delivery group contains shared machines and was created with a XenDesktop version earlier than 7.9.
- You have Edit Delivery Group permission.
The delivery group type is automatically converted to “desktops and applications” when the application group creation wizard is committed.
Although you can create an application group that has no associated delivery groups (perhaps to organize applications or to serve as storage for applications not currently used) the application group cannot be used to deliver applications until it specifies at least one delivery group. Also, you cannot add applications to the application group from the From Start menu source if there are no delivery groups specified.
The delivery groups you select specify the machines that are used to deliver applications. Select the check boxes next to the delivery groups you want to associate with the application group.
To add a tag restriction, select Restrict launches to machines with the tag and then select the tag from the drop-down list.
Step 2. Users
Specify application users in the application group. Either allow all users and user groups in the delivery groups you selected on the previous page, or select specific users and user groups from those delivery groups. If you restrict use to specified users, then only the users specified in the delivery group, the application group can access the applications in this group. Essentially, the user list in the application group provides a filter on the user lists in the delivery groups.
Enabling or disabling application use by unauthenticated users is available only in delivery groups, not in application groups.
For information about where user lists are specified in a deployment, see Where user lists are specified.
Step 3. Applications
Good to know:
- By default, new applications you add are placed in a folder named Applications. You can specify a different folder. If you try to add an application and one with the same name exists in that folder, you are prompted to rename the application you are adding. If you agree with the suggested unique name, the application is added with that new name. Otherwise, you must rename it yourself before it can be added. For details, see Manage application folders.
- You can change an application’s properties (settings) when you add it, or later. See Change application properties. If you publish two applications with the same name to the same users, change the Application name (for user) property in Studio. Otherwise, users see duplicate names in Citrix Workspace app.
- When you add an application to more than one application group, a visibility issue can occur if you do not have sufficient permission to view the application in all of those groups. In such cases, either consult an administrator with greater permissions or have your scope extended to include all the groups to which the application was added.
Click the Add from the drop-down menu to display the application sources.
From Start menu: Applications that are discovered on a machine in the selected delivery groups. When you select this source, a new page launches with a list of discovered applications. Select the check boxes of applications to add, and then click OK.
This source cannot be selected if you selected any of the following:
- Application groups that have no associated delivery groups.
- Application groups with associated delivery groups that contain no machines.
- A delivery group containing no machines.
- Manually defined: Applications located in the site or elsewhere in your network. When you select this source, a new page launches where you type the path to the executable, working directory, optional command line arguments, and display names for administrators and users. After entering this information, click OK.
- Existing: Applications previously added to the site. When you select this source, a new page launches with a list of discovered applications. Select the check boxes of applications to add and then click OK. This source cannot be selected If the site has no applications.
- App-V: Applications in App-V packages. When you select this source, a new page launches where you select the App-V server or the Application Library. From the resulting display, select the check boxes of applications to add, and then click OK. For more information, see App-V. This source cannot be selected (or might not appear) if App-V is not configured for the site.
As noted, certain entries in the Add drop-down menu are not selectable if there is no valid source of that type. Sources that are incompatible are not listed at all (for example, you cannot add application groups to application groups, so that source is not listed when you create an application group).
Step 4. Scopes
This page appears only if you have previously created a custom scope. By default, the All scope is selected. For more information, see Delegated administration.
Step 5. Summary
Enter a name for the application group. You can also (optionally) enter a description.
Review the summary information and then click Finish.