When setting -AzureAdSsoEnabled $true via the Citrix Workspace Remote PowerShell SDK (Set-WorkspaceCustomization), administrators often worry that this global flag will globally disable FAS or break legacy Active Directory-joined VDAs.
How Citrix HDX Session Launch Protocol Handles Both Models:
FAS-Enabled Delivery Groups: When a user launches a resource pointing to a traditional Active Directory-joined VDA assigned to a FAS-enabled Resource Location, Citrix Workspace requests a virtual smart card ticket from the on-premises FAS server. The VDA logs the user in using certificate-based Kerberos authentication.
Entra SSO Delivery Groups (Server 2025 / Win 10/11): When a user launches a resource pointing to an Entra-joined or Hybrid Entra-joined VDA (configured for native Entra SSO without FAS), the Workspace client utilizes the Primary Refresh Token (PRT) and modern authentication tokens via the AzureAdSsoEnabled flag to achieve seamless single sign-on.
Key Takeaway: The
-AzureAdSsoEnabled $trueflag acts as an enabler for non-FAS Entra token passthrough. It does not force FAS VDAs to abandon certificate ticket parsing. FAS continues to handle session launches for any Delivery Groups configured to use it.
| Target VDA Join State | Delivery Group Logon Type | FAS Server Required? | Impact of -AzureAdSsoEnabled $true |
| Domain-Joined (AD) | Standard AD / Kerberos | Yes (for zero-prompt SSO) | No Impact. FAS generates smart card certificates normally. |
| Hybrid Entra Joined (Server 2025 / Win 10/11) | Hybrid / Entra ID | No | Enables SSO. Allows modern token/PRT exchange during HDX launch. |
| Entra Joined (Native) | Entra ID | No | Enables SSO. Allows modern token/PRT exchange during HDX launch. |
Open PowerShell on a management machine and connect to Citrix DaaS:
Add-PSSnapin Citrix*
Get-Credential
Enable Azure AD / Entra SSO for the Workspace store:
Set-WorkspaceCustomization -AzureAdSsoEnabled $true
To ensure the Server 2025 VDAs use native Entra SSO rather than attempting to query FAS:
Open Citrix Web Studio.
Go to Delivery Groups and select your Windows Server 2025 QA group.
Edit the Delivery Group properties, navigate to User Management / Desktops, and ensure the Logon Type is set to Hybrid Entra Joined or Entra ID Joined (rather than standard Active Directory).
For legacy FAS Delivery Groups, ensure the group properties remain set to standard Active Directory with FAS enabled in the Resource Location.
On client endpoints connecting to the hybrid Server 2025 VDAs:
Ensure Citrix Workspace App for Windows is installed.
Verify the client device is registered/joined to Microsoft Entra ID or Hybrid Joined so the Microsoft Cloud AP plugin can exchange the Primary Refresh Token (PRT) during session launch.
Enabling AzureAdSsoEnabled at the Citrix Workspace configuration level does not break or override existing Federated Authentication Service (FAS) workflows. Citrix DaaS evaluates authentication and launch mechanisms at the Delivery Group and VDA level, allowing FAS-backed AD VDAs and native Entra SSO Hybrid/Entra-joined VDAs to safely co-exist within the same Citrix Workspace tenant.