QuestionQ50

Authentication and Authorization

A Delivery Group was created to publish APP_A, APP_B, and APP_C to an AD group named “HR.” The AD group contains 10 users (HR1–HR10). It was determined that one particular user, HR10, must not have access to APP_A. What must be done to ensure that the HR group can access the applications while HR10 cannot access APP_A?

Explanation

Limiting APP_A’s visibility to HR1–HR9 preserves the HR Delivery Group’s access to the published applications while applying an application-specific restriction that excludes HR10 from APP_A. Removing HR10 from the Delivery Group would also affect access to APP_B and APP_C. Citrix documents application-level visibility restrictions separately from Delivery Group membership; in current releases, visibility controls whether the app is shown in Citrix Workspace, and an invisible application can still be started, so a separate application group or assignment rule is required when an absolute launch denial is required.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!