- Smart card deployments
- Pass-through authentication and single sign-on with smart cards
Pass-through authentication with smart cards to virtual desktops is supported on user devices running Windows 10, Windows 8, and Windows 7 SP1 Enterprise and Professional Editions.
Pass-through authentication with smart cards to hosted applications is supported on servers running Windows Server 2016, Windows Server 2012 R2, Windows Server 2012, and Windows Server 2008 R2 SP1.
To use pass-through authentication with smart cards hosted applications, ensure you enable the use of Kerberos when you configure Pass-through with smartcard as the authentication method for the site.
Pass-through authentication with smart cards is configured on Citrix StoreFront. See Configure the authentication service in the StoreFront documentation for details.
Single sign-on is a Citrix feature that implements pass-through authentication with virtual desktop and application launches. You can use this feature in domain-joined, direct-to-StoreFront and domain-joined, NetScaler-to-StoreFront smart card deployments to reduce the number of times that users enter their PIN. To use single sign-on in these deployment types, edit the following parameters in the default.ica file, which is located on the StoreFront server:
For more instructions on setting these parameters, see the StoreFront or NetScaler Gateway documentation.
The availability of single sign-on functionality depends on many factors including, but not limited to: