Enable Federated Authentication Service for a tenant customer

This article describes the steps to enable Federated Authentication Service (FAS) in multitenant Managed Service Provider (MSP) environments. For more information, see Reference Architecture: Citrix Service Provider DaaS.

Prerequisites

Configure the MSP Customer

  1. Use a Cloud Connector to make active directory domains available to Citrix Cloud.

    Connect the on-prem infrastructure to the Citrix Cloud by installing cloud connectors.

    Verify that the domains associated with the on-prem domain controller are available under Identity and Access Management > Domains.

    Use cloud connector

  2. Federate the domain to the tenant.

    Select the domain and click the drop-down menu () and click Manage Federated Domains.

    Federate the domain to the tenant

    Find the tenant and click +. Then click Apply.

    Add or remove customer

  3. Verify that the domains associated are present in the tenant.

    This step is an optional. Sign in to the console for the tenant customers and verify that the domains are listed under Identity and Access Management > Domains.

    Verify that the domains associated are present in the tenant

    Return to the MSP customer.

  4. Install and register a FAS server with Citrix Cloud.

    Install FAS in the Active Directory (AD) forest where the tenant’s Citrix Virtual Apps and Desktops resources are located. Connect FAS to the cloud resource location associated with that AD forest. To install a FAS server, see Install and configure.

  5. Configure the tenant customer

    Enable FAS for the tenant customer

    • Configure your Identity Provider (IdP)

      Switch to the tenant customer. Go to Identity and Access Management > Authentication. Connect to your IdP and ensure that AD is synchronized with the IdP.

    • Enable FAS for a tenant

      Go to Workspace Configuration > Authentication. Select the authentication that you’ve set up and enable FAS.

      Enable FAS tenant

Known issue

There’s a known problem with deleting a MSP domain before removing the federated domains for tenants. You can still enable FAS for the tenants, but FAS fails since the domain doesn’t exist for MSP anymore.

Enable Federated Authentication Service for a tenant customer