Can someone give me a reality check. Citrix cloud ...
# citrix-cloud
s
Can someone give me a reality check. Citrix cloud with SAML/FAS should allow single sign on and users should not be prompted with passwords correct?
b
You would need FAS to not be prompted
s
And if we had Fas enables it should not be prompted correct?
b
Correct assuming the PKI works properly
s
I cant believe cirix support. They keep telling me to I have to use AD for Single sign on. Even when I submit articles to them
b
?
r
Are your VMs domain joined or Azure AD Joined?
s
Domain joined, synced with azure via adconect
The bigger issue is the insistence of Citrix saying that if you use SAML\FAS single sign on is not supported. Everything I read says it shoudl be supported and they keep telling me no
r
Can you share the support case?
s
We are using SAML for the authentication part, FAS is involved for SSO. This is fully supported by Citrix..
s
Well, FAS does SSO when launching the VDA. Im talking about just logging into your citrix cloud web page
I dont think FAS plays a part with that. That is your SAML provider and client
b
That definitely is different
s
Yeah, and that's were I and Citrix are at odds. I am under the impression with Azure being my SAML provider, using the Citrix supplied enterprise SAML application in the Microsoft enterprise app area, and all the correct settings on the client, I should be able to go to cloud.domain.com and not be prompted for a password on domain joined machines\synced with AD connect to Azure. (Or open the workspace app and not be prompted for a password) Just like I can when browsing to say outlook.com
r
That would have nothing to do wiht FAS. FAS is SSO into VDAs using eh same credentials you logged into workspace with. SSO into workspace itselft has more to do with how you setup your Idp and workspace integration. If workspace send you to the idp and you already have the appropriate attributes in your browser you shoudl get passed through as long as the idp allows it.
s
@Rody Kossen Thanks, already turned that on.
r
Having that to on (recommended) means prompted for credentials This parameter forces the user to be prompted for authentication whenever there is not a valid Citrix Workspace session.
s
@Rob Zylowski I agree FAS has nothing to do with what I'm asking about. However, as ntoed in the above two articles what im asking is supported with Citrix. Those two articles actaully prove that it should work but in a indirect way
r
I think it will work. I dont think we support it meaning if its not working that you could open a ticket.
s
@Rob Zylowski Citrix is supporting it by have that box in the two articles above to be on or off.
r
Thanks for that i hadnt seen that setting before. But the second part about outlook.com or any m365 app is more complicated. The problem there is that your auth token wont be passed through to the VDA unless you do the proper configurations with EntraID CBA to make that happen and use hybrid joined vdas. There have been many blogs and discussion here on that one.