Citrix Workspace
Citrix Workspace is the Citrix Cloud service and client app that provides a unified portal and native clients for accessing virtual desktops/apps (Citrix DaaS/Virtual Apps and Desktops) plus SaaS and web apps with single sign-on.
Key Capabilities
-
Standards-based SSO to Workspace: Citrix Cloud workspaces support SAML 2.0 IdPs for both administrators and subscribers.
-
OIDC with supported IdPs: Citrix documents Workspace sign-in using OpenID Connect with Okta.
-
Use Citrix Gateway as IdP: Organizations can connect an on-prem Citrix Gateway (NetScaler/ADC) as the identity provider for Workspace subscribers.
-
SaaS app SSO patterns: For SaaS like Microsoft 365, Citrix Secure Private Access provides SAML-based SSO brokering with Citrix Gateway when needed.
Limitations
-
Service-provider role (not an IdP): Workspace relies on external IdPs for authentication. It does not function as a general SAML/OIDC identity provider for third-party apps.
-
SAML certificate rotation operational note: Updating the IdP signing certificate for Workspace requires a disconnect/reconnect workflow; plan a maintenance window or alternate IdP during the change.
-
Multi-component architecture: Advanced SaaS/app SSO often involves adjacent Citrix components (Citrix Gateway / Secure Private Access / NetScaler), adding design and operational complexity versus a single-product IdP.
-
Directory prerequisites for SAML: Citrix’s SAML setup commonly assumes on-premises Active Directory with Cloud Connectors—an extra moving part for hybrid environments.