Citrix DaaS integrates natively with Microsoft Entra ID (formerly Azure Active Directory) for authentication, device identity, and conditional access — giving organisations that have invested in Microsoft 365 a consistent, unified identity experience across their virtual workspace.
Microsoft Entra Single Sign-On for DaaS
Citrix DaaS supports full Microsoft Entra SSO — users who authenticate to Citrix Workspace with their Entra ID credentials are passed through to their virtual applications and desktops without a second login prompt. The Federated Authentication Service (FAS) issues short-lived, digitally signed user certificates at session launch, eliminating the need for users to re-enter credentials at the Windows logon screen of the VDA. SSO works across Windows, Linux, and macOS VDAs, and with Workspace app for Linux from version 2601.
- Single login — Entra credentials flow through to virtual session
- Federated Authentication Service (FAS) issues session certificates
- Eliminates double-login friction on non-persistent pooled desktops
- Supported on Windows, Linux, and macOS VDAs
- Configurable directly from the Citrix Cloud portal
Entra ID Multi-Factor Authentication
Citrix Workspace uses Entra ID as an identity provider, which means Entra Conditional Access policies and MFA requirements apply natively at the point of Workspace authentication. Users are challenged for MFA (via the Microsoft Authenticator app, SMS, TOTP, or hardware token) before access to any virtual application or desktop is granted. Conditional Access policies can enforce MFA based on user location, device compliance state, or application sensitivity — giving you the same access governance for your virtual workspace as for your Microsoft 365 applications.
- Entra Conditional Access policies enforce MFA at Workspace login
- Microsoft Authenticator, TOTP, SMS, and hardware token support
- Device compliance checks via Entra ID and Microsoft Intune integration
- MFA scope configurable by user group, location, or risk signal
- Entra ID extension attributes supported in MCS for advanced policy filtering
Microsoft Entra Joined VDAs
Citrix DaaS supports machine catalogues where VDAs are Microsoft Entra joined — not domain-joined to on-premises Active Directory. This is particularly relevant for organisations migrating away from on-premises AD, or deploying cloud-native desktop pools in Azure where no domain controller is present. Entra-joined VDAs are provisioned using MCS, managed through Microsoft Intune for device compliance, and support Hybrid Entra join for environments in transition between on-premises AD and cloud-only identity.
- VDAs can be Entra joined, Hybrid Entra joined, or domain-joined
- MCS provisions Entra joined catalogues in Microsoft Azure
- Intune co-management supported for Hybrid Entra joined non-persistent VMs
- Entra ID service accounts manage device objects — separate from provisioning credentials
- Supports organisations migrating from on-premises AD to cloud-only identity
Citrix Gateway Service & Optimal Routing
When users connect from outside the corporate network, HDX sessions are secured and proxied through the Citrix Gateway Service — a globally distributed cloud service that connects users to the nearest point of presence and routes the HDX session to their resource location. The Rendezvous Protocol allows the HDX session to bypass the Cloud Connector and connect directly to the Gateway Service, reducing connector load and data centre footprint. Internal users on the corporate network connect directly to VDAs without traversing the gateway.
- Citrix Gateway Service — cloud-hosted, globally distributed, no on-premises VPX required
- Rendezvous Protocol bypasses Cloud Connector for reduced overhead
- Network Locations define internal vs external routing automatically
- Optional on-premises NetScaler gateway for environments requiring local control
- TLS encryption for all HDX sessions traversing the public internet