-
-
-
-
-
-
User access control
This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
User access control
User Access Control decides two things at platform level: which identity provider authenticates a given user, and what any user is permitted to do regardless of their role.
Find it under System Configuration. Changes here apply to everyone on the platform.
Registered domains and identity providers
Users are routed to an identity provider by the domain of their email address. Register a domain, associate it with a configured provider, and anyone signing in from that domain is authenticated by it.

This is how a deployment supports more than one organization at once. Employees on your own domain can go to your corporate identity provider, while contractors on another domain use a different one.
Two-factor authentication is enabled here, per registered domain.
A domain with no identity provider is the case to watch. Whether those users can sign in at all depends on the platform constraint below that governs registration with an email address and password.
See Identity providers for connecting a provider, and SAML or OpenID Connect for the protocols.
Platform access control and constraints
These settings apply to every user on the platform, whatever role they hold.

| Setting | When enabled |
|---|---|
| Allow login to the platform | Users can sign in. Turning it off closes the platform to everyone, which is a maintenance and incident control rather than an everyday setting. |
| Allow user registration with email and password | Users can register even when no identity provider covers their domain. Leave it off where every user should come through an identity provider. |
| Allow user timezone change | Users may set their own timezone, which drives their working schedule and therefore when workspaces start and pause. |
| Allow user IP location tracking | The user’s IP location is recorded in the logs. |
| Support accessible for all users | Every user can reach the platform Support menu. |
The registration setting is the one with the widest effect. With it on, someone whose domain is not registered can create an account with a password, bypassing the identity provider routing above. Most deployments that have connected an identity provider should turn it off.
Image URL constraints are also part of this area. See Registry access.
Related information
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.