Description
The Citrix DaaS solution for Microsoft Sentinel provides the capability to ingest configuration audit logs and session activity from [Citrix DaaS](https://www.citrix.com/products/citrix-daas/) (Citrix Virtual Apps and Desktops service) into Microsoft Sentinel using the [Citrix CVAD Manage REST APIs](https://developer.cloud.com/citrixworkspace/citrix-daas/citrix-virtual-apps-and-desktops-service-apis/docs/overview). It provides audit trails for security investigations, compliance monitoring, and operational troubleshooting. Multiple Citrix tenants can be connected from a single data connector, with each record tagged with its Citrix Customer ID for multi-tenant differentiation.
**Underlying Microsoft Technologies used:**
This Solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:
• [Microsoft Sentinel Codeless Connector Framework](https://aka.ms/Sentinel-CCP_Platform)
- Version
- 3.1.0
- Declared author / publisher
- Microsoft - support@microsoft.com
- Support tier
- Microsoft
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-solution-citrixdaas
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC