Citrix SecurSpaces™

User access control

User Access Control decides two things at platform level: which identity provider authenticates a given user, and what any user is permitted to do regardless of their role.

Find it under System Configuration. Changes here apply to everyone on the platform.

Registered domains and identity providers

Users are routed to an identity provider by the domain of their email address. Register a domain, associate it with a configured provider, and anyone signing in from that domain is authenticated by it.

register-identity-light-cropped

This is how a deployment supports more than one organization at once. Employees on your own domain can go to your corporate identity provider, while contractors on another domain use a different one.

Two-factor authentication is enabled here, per registered domain.

A domain with no identity provider is the case to watch. Whether those users can sign in at all depends on the platform constraint below that governs registration with an email address and password.

See Identity providers for connecting a provider, and SAML or OpenID Connect for the protocols.

Platform access control and constraints

These settings apply to every user on the platform, whatever role they hold.

platform-compliance-light-cropped

Setting When enabled
Allow login to the platform Users can sign in. Turning it off closes the platform to everyone, which is a maintenance and incident control rather than an everyday setting.
Allow user registration with email and password Users can register even when no identity provider covers their domain. Leave it off where every user should come through an identity provider.
Allow user timezone change Users may set their own timezone, which drives their working schedule and therefore when workspaces start and pause.
Allow user IP location tracking The user’s IP location is recorded in the logs.
Support accessible for all users Every user can reach the platform Support menu.

The registration setting is the one with the widest effect. With it on, someone whose domain is not registered can create an account with a password, bypassing the identity provider routing above. Most deployments that have connected an identity provider should turn it off.

Image URL constraints are also part of this area. See Registry access.

User access control