This article is designed to describe the account permissions in Citrix Virtual Apps and Desktops.
Purpose | Required Permissions |
---|---|
Install CVAD components | Local administrator and domain user |
Create site and upgrade site | SQL permission ● Server role: dbcreator, securityadmin ● Database role: db_owner |
Join VDI into domain | Create and join computer account on AD |
Delete computer account | Delete computer account on AD |
Reset computer account password | Reset computer account password on AD |
Add user or group into delivery group | Search and read user account or group on AD |
Administrating Citrix site | Configured via Studio > administrator |
Publish certificate template on CA server | "Issue and Manage Certificates" and "Manage CA" under Security tab of CA properties. |
Computer account | Purpose | Permission |
---|---|---|
DDC hostname | Communication with site database | site database role: ADIdentitySchema_ROLE Analytics_ROLE AppLibrarySchema_ROLE chr_Broker chr_Controller ConfigLoggingSiteSchema_ROLE ConfigurationSchema_ROLE DAS_ROLE DesktopUpdateManagerSchema_ROLE EnvTestServiceSchema_ROLE HostingUnitServiceSchema_ROLE Monitor_ROLE OrchestrationSchema_ROLE StorefrontSchema_ROLE TrustSchema_ROLE |
Communication with monitor database | monitor database role: MonitorData_ROLE | |
Communication with logging database | loggingdatabase role: ConfigLoggingSchema_ROLE | |
FAS hostname | Request certificate from CA | Read and Enroll permissions on each certificate template used by FAS Servers. |