Overview:
Users may be prompted for additional authentication when navigating to cloud store URLS if StoreFront Cloud is configured to use a federated identity provider.
Example:
Users may be prompted for Azure AD credentials when Using AAD for Authentication to cloud stores, even if the user has a valid Microsoft authentication token.
Scenario
IMPORTANT:
Customers should consult their internal security teams before requesting an exception to determine which settings are best for their environment and security posture.
This behavior can now be modified directly by the following Cloud setting:


Note: This feature alone does not allow Single Sign-On into a Desktop VDA or Published Application session, and Citrix Federated Authentication Service (FAS) will be required to be in place for Single Sign-On to occur. Learn more here.
Users may be prompted for additional authentication when navigating to cloud store URLS if StoreFront Cloud is configured to use a federated identity provider.
Customize security and privacy policies:
https://docs.citrix.com/en-us/citrix-workspace/experience/sessions
Microsoft has documented how Azure AD should be configured for applications that use “prompt=login”:
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/ad-fs-prompt-login
Citrix CTP Contributions:
https://jkindon.com/2019/09/20/azure-ad-and-citrix-workspace-sso/