Skip to content

Julian Jakob

It's all about EUC

  • Blog
  • About me
  • Privacy Policy

Tag: AzureAD

March 1, 2024 Julian Jakob

Citrix DaaS – Entra ID SSO with PRT and without FAS

Overview This guide provides information for configuring Entra ID Single Sign-on (AAD SSO) for Citrix DaaS without the use of FAS and also getting a PRT – so there are no SSO problems with M365

Continue reading
February 4, 2024 Julian Jakob

NetScaler – How to get rid of SSO / missing PRT Issues using Entra ID Phone Sign-in

Overview You’re using Microsoft Entra ID (SAML or OAuth) as IdP for your OnPrem CVAD or DaaS Environment. Your default is to use Citrix FAS so the User-Logon to the VDA happens with a virtual

Continue reading
November 22, 2023 Julian Jakob

Microsoft Entra – Using Private Access to tunnel Citrix HDX Sessions and giving HDX Direct a Try

Overview Private Access, a Feature of Microsoft Entra’s Global Secure Access Suite, is a simple but powerful Security Service Edge (SSE) network solution for providing secure access to your Cloud / OnPrem Apps without VPN,

Continue reading
September 30, 2023 Julian Jakob

Citrix DaaS – Microsoft Entra ID B2B User Identity Logonmethods

Overview Recently my namesake Julian wrote a great Post about choosing the correct Machine Identity in a Virtual Desktop Infrastructure – which is very important. This post will cover the other Hand – choosing the

Continue reading
July 3, 2023 Julian Jakob

Citrix DaaS – Prevent Session takeover when using NetScaler as IdP followed by SAML

Overview A customer of mine recently came across a way to sign in to Cloud Workspace with any other user, provided you sign up before with some valid credentials – for example your own. The

Continue reading
April 29, 2023 Julian Jakob

Citrix DaaS – NetScaler as IdP with OAuth to Azure AD

Overview This is a Quickpost about a desired architecture with Citrix DaaS, where a NetScaler is acting as OAuth IdP (DaaS Workspace Authentication is set to Citrix Gateway or Adaptive Authentication) and is acting as

Continue reading
March 30, 2023 Julian Jakob

NetScaler – OAuth to Azure AD with login_hint Subject Field

Overview What’s the biggest difference when choosing SAML instead of OAuth as the protocol when using Azure AD as IdP for NetScaler when it comes to User Experience (UX)? You should consider this Question when

Continue reading
February 6, 2023 Julian Jakob

Citrix FAS – Azure AD CBA Single Sign-On (SSO) without a PRT

Overview With Azure AD’s certificate-based authentication (CBA) there is a way to get a Primary Refresh Token (PRT) inside the User’s Citrix Session. I’ve written about the details in Part1. As the most negative requirement

Continue reading
January 5, 2023 Julian Jakob

Citrix FAS – SID Lookup Mismatch with Citrix DaaS

Issue Recently I tried to setup a Citrix DaaS environment with OnPrem VDA’s and FAS for a working Azure AD B2B scenario. Every B2B customer’s UPN suffix is created OnPrem with the matching Shadow Account.

Continue reading
October 15, 2022 Julian Jakob

Citrix FAS – Azure AD CBA with Primary Refresh Token (PRT)

Overview There are several discussions about the missing Primary Refresh Token (PRT) in the User’s Citrix Session when using SAML / oAuth with Azure AD and Citrix FAS – as using Smartcard to authenticate is

Continue reading
Follow @jakob_davidson

Recent Posts

  • NetScaler – Exchange ActiveSync Device-Check
  • Windows Cloud – AVD and Cloud PC GPU Workload
  • Microsoft AVD – Multimedia Workload without a GPU
  • NetScaler – Enhanced Authentication Feedback Template
  • Microsoft AVD – vGPU with and without HDX
Categories
  • AVD
  • DaaS
  • Entra
  • EXCHANGE
  • FAS
  • NetScaler
  • NVIDIA vGPU
  • PVS
  • TERMINAL SERVICES
  • Windows Cloud

Tags

AdaptiveAuthentication (2) ADFS (1) AlwaysOn (1) AVD (3) AzureAD (10) CBA (4) ConditionalAuthentication (1) CSA (1) CSP (1) CVPN (1) DaaS (10) DLS (1) EntraID (6) EPA (1) FAS (4) GRID (3) GUIDE (1) Header (1) HTML5 (2) httpheaders (1) HYBRID (1) IdP (3) KnownIssues (1) M365 (1) NetScaler (30) nFactor (8) NS-Console (1) NVIDIA (3) OAuth (8) OTP (4) PATSET (2) PrimaryRefreshToken (3) PrivateAccess (1) PVS (1) RDS (1) SAML (7) Security (2) SecurityHeaders (1) SP (1) UPGRADE (1) UPN (1) vGPU (6) VPN (6) WAF (2) Windows365 (1) Windows Cloud (1)

Archive
  • June 2025
  • May 2025
  • March 2025
  • December 2024
  • November 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • March 2024
  • February 2024
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • June 2022
  • April 2022
  • March 2022
  • February 2022
  • November 2021
  • October 2021
  • September 2021
  • May 2021
  • December 2020
Tweets by jakob_davidson

Friendly Blogs

  • Julian Mooren
  • René Bigler
  • Johannes Norz
  • Dennis Span
  • Matthias Schlimm
  • Marco Hofmann
  • Sacha Thomet
  • Carl Stalhood
  • David Wilkinson
  • Leee Jeffries
  • James Kindon
  • World of EUC
  • VCBAWUE
WordPress Theme: Wellington by ThemeZee.
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT