1Y0-312 Advanced Security and Access Control Practice Question
An administrator is implementing Microsoft Entra ID as the Identity Provider (IdP) for a Citrix environment. Users successfully authenticate via the NetScaler Gateway but are prompted for credentials again when launching their published desktops. Which component must be configured to ensure seamless single sign-on to the VDA in this scenario?
⚠ Common exam trap
Candidates often incorrectly suggest re-configuring the NetScaler or the VDA directly, failing to recognize that FAS is the specific component required to bridge SAML identity to Windows logon.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Federated Authentication Service (FAS).
Implementing Federated Authentication Service (FAS) is essential when using SAML-based identity providers like Microsoft Entra ID, as SAML does not provide the password to the VDA. By leveraging FAS, the environment uses certificate-based authentication to achieve seamless single sign-on. This ensures that users maintain a high-quality experience without redundant authentication prompts while maintaining a robust security posture across the entire delivery infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'Trust requests sent to the XML Service' on the Delivery Controllers.
Why it's wrong here
The XML Trust setting allows the Delivery Controller to trust the credentials sent from StoreFront, but it does not address the lack of a password in a SAML assertion. Even with XML Trust enabled, the VDA requires a valid credential provider to log the user into the Windows session.
- ✓
Configure the Federated Authentication Service (FAS).
Why this is correct
Federated Authentication Service uses virtual smart cards to provide a certificate-based logon for users who authenticate with non-password methods. It integrates with StoreFront to request a certificate on behalf of the user, which the VDA then uses to perform a secure login without requiring a traditional Active Directory password.
- ✗
Set the NetScaler Gateway session profile to use 'Single Sign-on to Web Applications'.
Why it's wrong here
This specific NetScaler setting is designed for passing credentials to web-based applications hosted behind the gateway rather than the virtual desktop session itself. While it helps with the initial StoreFront login, it does not provide the necessary mechanisms to facilitate a secure Kerberos or certificate login at the VDA level.
- ✗
Modify the VDA registry to enable 'Direct Workload Connection'.
Why it's wrong here
Direct Workload Connection, often associated with Workspace Service, optimizes the data path between the client and the VDA but does not handle authentication logic. It focuses on reducing latency and bypassing unnecessary gateways rather than managing the cryptographic exchange required for single sign-on using SAML or other federated identities.
About these practice questions
One of 186 original 1Y0-312 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Citrix exam blueprint
This 1Y0-312 practice question is part of Courseiva's free Citrix certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 1Y0-312 exam.