Citrix DaaS - Microsoft Entra single sign-on might not work because of Citrix policy configuration

book

Article ID: CTX696795

calendar_today

Updated On:

Description

After configuring Microsoft Entra ID SSO by following the Citrix documentation, users are still prompted to enter their credentials when signing in to a virtual desktop instead of being signed in automatically.

Cause

Microsoft Entra ID SSO to the Virtual Delivery Agent (VDA) does not work when the Auto client reconnect authentication policy is configured to Require authentication.
The default value for this policy is Do not require authentication, which is compatible with Microsoft Entra ID SSO.

Resolution

Review the Citrix policy configuration and verify the Auto client reconnect authentication setting.
If the policy is configured as Require authentication, change it to Do not require authentication.

 

image.png

If Require authentication is required for specific VDAs, create a separate policy and apply an appropriate filter (such as a Delivery Group or Organizational Unit) so that the setting only affects the intended VDAs and not those using Microsoft Entra ID SSO.

Issue/Introduction

This article explains how to resolve an issue where Microsoft Entra ID Single Sign-on (SSO) does not work when launching a Citrix DaaS virtual desktop.

Additional Information

Documentation: https://docs.citrix.com/en-us/citrix-daas/install-configure/session-authentication/entra-sso.html