{"id":1634,"date":"2017-10-18T05:30:00","date_gmt":"2017-10-18T05:30:00","guid":{"rendered":"http:\/\/neu.koetzingit.de\/ein-blick-auf-citrix-federated-authentication-service-fas\/"},"modified":"2026-06-02T13:32:49","modified_gmt":"2026-06-02T13:32:49","slug":"ein-blick-auf-citrix-federated-authentication-service-fas","status":"publish","type":"post","link":"https:\/\/www.koetzingit.de\/en\/ein-blick-auf-citrix-federated-authentication-service-fas\/","title":{"rendered":"An Overview of Citrix Federated Authentication Service (FAS)"},"content":{"rendered":"<p><span class=\"dropcapmiddle\">K<\/span>Recently, one of my clients gave me a problem to solve: \u201eCan we authenticate with the Netscaler Gateway using only a username and security token, from a <strong>not a domain member<\/strong> and then access to a full <strong>Have you received a Citrix ICA session?<\/strong>\u201e<\/p>\n<p>This is exactly where the <strong>Citrix Federated Authentication Service\u00a0<\/strong>To the rescue!<\/p>\n<p><!--more--><\/p>\n<p>The customer wants employees to be able to work without passwords, which is why the company uses only smart cards with all domain members. The company devices have no problem accessing the internal network from outside the company. But what about <strong>personal devices<\/strong>? In this case, users receive a security token and nothing else. In the past, users had to enter their password at least once in the web interface and then save it.<\/p>\n<p>In my opinion, this is a good example, and I believe that other Citrix customers have the same or similar requirements. Before I get back to the use cases, let\u2019s first take a look at how the\u00a0<strong>Citrix Federated Authentication Service<\/strong>\u00a0throw.<\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">Citrix Federated Authentication Service<\/span><\/h3>\n<p>To make things easier to understand, I'll keep the explanations simple. FAS is a Windows service that <strong>Smart Card Class Certificates<\/strong>\u00a0(vSmartCards) on behalf of the Active Directory user. To do this, the service must be authorized by your own internal private certificate authority (CA). The Federated Authentication Service primarily interacts with Citrix StoreFront, although other components such as Netscaler, DDC, and VDA are also involved but are not as critical. The created vSmartCard is then sent to the target VDA server, just as the NFuse ticket was previously. Since FAS holds all private keys for the created user vSmartCards, the system must be secured with restricted access, even for administrators.<\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">FAS Setup<\/span><\/h3>\n<p>FAS has been part of XenApp\/XenDesktop Media since version 7.9. Deploying FAS is easy, especially if you have full administrative rights to the private CA. Citrix recommends not using a server on top of another <strong>Citrix Components<\/strong>\u00a0are installed, or another server on the one that already <strong>Port 80 is used<\/strong> For example, IIS. Simply run the setup, which installs a Windows service and a console. Be sure to run the FAS console as an administrator (using runas); otherwise, further configuration will fail. Three tasks must be completed to finish the setup:<\/p>\n<ol>\n<li>Upload (Import) Certificate Templates to the Private CA<\/li>\n<li>Add the templates to the CA and<\/li>\n<li>Authorization of the FAS server to issue certificates, which must be approved on the CA server.<\/li>\n<\/ol>\n<p>1 and 2 are done via remote PowerShell and shouldn't be a problem.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1632\" src=\"http:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-three-tasks.jpg\" alt=\"Blog Fas Three Tasks\" width=\"565\" height=\"392\"  title=\"An Overview of Citrix Federated Authentication Service (FAS)\" srcset=\"https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-three-tasks.jpg 877w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-three-tasks-300x208.jpg 300w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-three-tasks-768x532.jpg 768w\" sizes=\"auto, (max-width: 565px) 100vw, 565px\" \/><\/p>\n<p>If all tasks are \u201eGreen,\u201c a Microsoft Group Policy must be configured to define the FQDN and session settings of the FAS server. The policy must then be assigned to the VDA, DDC, and the FAS server itself. The configuration will not proceed until the policy has taken effect. If the system does not have the policy, the following will appear in the event log: <code>No User Credential Service has been configured. Apply the \"Citrix User Credential Service Group\" Policy Object<\/code><\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">User Rules \/ ACL<\/span><\/h3>\n<p>The main task is to configure the Security Access Control List (ACL). By default, all computers are allowed access to StoreFront and VDAs <strong>prohibited<\/strong>. All computers involved must be added to the \u201eallowed\u201c list, and anything that is blocked must be removed. That's all there is to it.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1633\" src=\"http:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-user-acl.jpg\" alt=\"Blog Fas User Acl\" width=\"565\" height=\"392\"  title=\"An Overview of Citrix Federated Authentication Service (FAS)\" srcset=\"https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-user-acl.jpg 878w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-user-acl-300x208.jpg 300w, https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blog-fas-user-acl-768x533.jpg 768w\" sizes=\"auto, (max-width: 565px) 100vw, 565px\" \/><\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">FAS Configuration<\/span><\/h3>\n<p>This is the tricky part, since not everything is currently documented, let alone for every possible scenario. The basic concept and architecture for some cases can be found in the Citrix eDocs (<a href=\"https:\/\/docs.citrix.com\/en-us\/xenapp-and-xendesktop\/7-14\/secure\/federated-authentication-service\/fas-architectures.html\">https:\/\/docs.citrix.com\/en-us\/xenapp-and-xendesktop\/7-14\/secure\/federated-authentication-service\/fas-architectures.html<\/a>), such as using ADFS for a B2B solution, etc., but no specific details on how to configure these, neither for Netscaler nor StoreFront. There is only one thing that is certain: Users must be familiar with the <strong>User Principal Name (UPN)<\/strong>\u00a0Please log in; otherwise, FAS will not be able to issue vSmartCards.<\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">StoreFront FAS Plug-in<\/span><\/h3>\n<p>Currently, FAS cannot be enabled in the StoreFront console and must be configured via PowerShell. I recommend creating a separate store named \u201eFAS\u201c for this purpose. The PoSh commands then use the path Citrix\/FASAuth. This modifies the web.conf file in the folder and is also replicated in a StoreFront cluster. Here are the PoSh commands for a store named \u201eFAS\u201c:<\/p>\n<p><code>&amp; \u201c$Env:PROGRAMFILES\\Citrix\\Receiver StoreFront\\Scripts\\ImportModules.ps1\u201d<\/code><\/p>\n<p><code>$siteId = 1<\/code><br \/><code>$storeVirtualPath = \u201c\/Citrix\/FAS\u201d<\/code><br \/><code>$authenticationVirtualPath = \u201c\/Citrix\/FASAuth\u201d<\/code><\/p>\n<p><code># Use FAS<\/code><br \/><code>Set-DSClaimFactoryName \u2013siteId $siteId \u2013virtualPath $authenticationVirtualPath \u2013factoryName \u201cFASClaimsFactory\u201d<\/code><br \/><code>Set-DSVdaLogonDataProviderName \u2013SiteId $siteId \u2013VirtualPath $storeVirtualPath \u2013VdaLogonDataProviderName \u201cFASLogonDataProvider\u201d<\/code><\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">FAS Use Cases<\/span><\/h3>\n<p>There are many different scenarios possible, some of which can become quite complex, but ultimately, all of them involve accessing a full Citrix ICA\/HDX session. This brings me back to the beginning of the article, though not necessarily to the first use case.<\/p>\n<p>What I see as the first use case for FAS is simply\u00a0<strong>Domain Pass-Through<\/strong> with StoreFront. If domain pass-through is enabled in StoreFront, it applies only to the Web Receiver (RfW) but not to the target VDA server. To make this work, the local receiver must be installed with administrator privileges so that SSO can be registered. Then SSO must still be configured via GPO, and in the end it doesn\u2019t work anyway because additional \u201ecredential providers\u201c that were loaded prevent the feature from functioning. All in all, it\u2019s not exactly simple or error-free.<\/p>\n<p><strong>With FAS, you can simply forget about the SSO part of the receiver! No admin installation, no receiver configuration for SSO!<\/strong> Don't forget: this requires a client in the domain, and RfW must be in the Intranet zone in Internet Explorer.<\/p>\n<p>Back to the \u201eToken Only\u201c use case, a good example of FAS. Let\u2019s assume that all employees in the company use smart cards and do not know their Active Directory password. When employees work from home and do not use a company-issued device, <strong>How can they authenticate themselves without a password?<\/strong>? Token authentication using a UPN as the username is all that is required with FAS. This allows employees to work securely\u2014without a password\u2014both inside and outside the company.<\/p>\n<p>\u00a0<\/p>\n<h3><span class=\"label label-success\">FAS Improvements<\/span><\/h3>\n<p>Citrix will and should continue to develop FAS, and by that I don\u2019t just mean FAS itself, but more importantly its integration with StoreFront and Netscaler. StoreFront needs better front-end error messages (simply saying \u201erequest cannot be completed\u201c isn\u2019t helpful), and FAS should be included as an authentication option in the console. Netscaler should include FAS options for SSO in the session profiles. FAS itself should get a \u201cfacelift\u201d for the console, along with better error messages, tracing, and logging functionality.<\/p>\n<p>That said, FAS is very stable and easy to configure. Identity management is becoming increasingly important, and FAS serves as a bridge to enable users to access an HDX session.<\/p>\n<p>\u00a0<\/p>\n<p><strong>My thanks go to Andrew Innes (FAS) and his team, as well as to Simon Frost (StoreFront)<\/strong>\u00a0\u00a0<\/p>\n<style>.urwz3,.urwz3 a{color:#fff}<\/style>\n<div class=\"urwz3\">Learn all about the <a href=\"https:\/\/crazytimelive-game.com\/\">Crazy Time Tracker<\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>K\u00fcrzlich hat mir einer meiner\u00a0Kunden eine Aufgabe zur L\u00f6sung gegeben: &#8222;K\u00f6nnen wir uns gegen das Netscaler Gateway nur mit Benutzernamen [&hellip;]<\/p>\n","protected":false},"author":1755,"featured_media":1631,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[12],"tags":[108,220,27,70,217,111,219,218,221,222,109,28,83,51],"class_list":["post-1634","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles-de","tag-adfs","tag-b2b","tag-citrix","tag-domain","tag-fas","tag-idp","tag-joined","tag-non","tag-secureid","tag-smartcard","tag-sso","tag-storefront","tag-xenapp","tag-xendesktop"],"uagb_featured_image_src":{"full":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas.png",360,360,false],"thumbnail":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas-150x150.png",150,150,true],"medium":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas-300x300.png",300,300,true],"medium_large":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas.png",360,360,false],"large":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas.png",360,360,false],"1536x1536":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas.png",360,360,false],"2048x2048":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas.png",360,360,false],"trp-custom-language-flag":["https:\/\/www.koetzingit.de\/wp-content\/uploads\/2017\/10\/blogs-logo-fas.png",12,12,false]},"uagb_author_info":{"display_name":"Thomas K\u00f6tzing","author_link":"https:\/\/www.koetzingit.de\/en\/author\/thomas-koetzing\/"},"uagb_comment_info":0,"uagb_excerpt":"K\u00fcrzlich hat mir einer meiner\u00a0Kunden eine Aufgabe zur L\u00f6sung gegeben: &#8222;K\u00f6nnen wir uns gegen das Netscaler Gateway nur mit Benutzernamen [&hellip;]","_links":{"self":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/users\/1755"}],"replies":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/comments?post=1634"}],"version-history":[{"count":1,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1634\/revisions"}],"predecessor-version":[{"id":1877,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/posts\/1634\/revisions\/1877"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/media\/1631"}],"wp:attachment":[{"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/media?parent=1634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/categories?post=1634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.koetzingit.de\/en\/wp-json\/wp\/v2\/tags?post=1634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}