Admin cannot login to Cloud account using Azure AD credentials

Admin cannot login to Cloud account using Azure AD credentials

book

Article ID: CTX464002

calendar_today

Updated On:

Description

Citrix Cloud Administrator cannot login to "Test" account using Azure AD. When Admin logs in to Citrix Cloud using Azure AD credentials, it may get connected to their Production Cloud account  instead of the Test Cloud account.   

Two separate Citrix cloud accounts/ Tenants: 

1. Production Account  

This Customer account has only Citrix Identity and no AAD.
Identity used: Citrix Identity 

2. Test Account
Customer account has AAD configured. 
Identity used: Both Citrix and Azure AD. 

Administrator account/ UPN used is same for both AAD and Citrix Identity. 

Resolution

To resolve this issue for “Test” Citrix Cloud account, remove the existing cloud administrator account and invite him using Azure AD from Identity and Access Management.

Note: You may still see symptoms as above after the change. This is because the session data is kept in browser cookies. Please ensure no existing sessions is present is browser cache or try in private/incognito browser.

Problem Cause

Delegated Administration account is set to use Citrix Identity - "identityProviders": ["citrixsts"]. This is how the user was initially invited during onboarding.
HAR files does not show user logging in using  Azure AD.  There is a NO redirect to Microsoft for user login.