The MSI properties described in this article are for both Citrix®, Azure Virtual Desktop, and Local Environments and can be modified to meet the organization's needs.
Citrix Server or Azure Virtual Desktop
Parameter Name | Registry Name | Registry Keys Affected | Value |
|---|---|---|---|
TFA_USEREMOTE | UseRemote | SOFTWARE\HealthCast\hciepicsessionmgr | False |
Set to “True” to configure TFA to get the current user context from the endpoint, even if XA is installed locally. | |||
TFA_VERTICAL_OFFSET_FOR_LOGIN_SCREEN | VerticalOffsetForLoginScreen | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | 160 |
This setting defines how far down the Hyperspace window the authentication window should be placed. | |||
Citrix Server or Azure Virtual Desktop - Logoff Cleanup
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_LOGOFFCLEANUP | CallLogoffCleanupOnEpicLogoff | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | False | Set to “True” to configure the plugin to call Logoff Cleanup in the published Hyperspace session on the Citrix server when Hyperspace is logged out. This setting is only set on the Citrix Server or AVD. |
TFA_LOGOFFCLEANUP_SEC | CallLogoffCleanupOnEpicSecure | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | False | Set to “True” to configure the plugin to call Logoff Cleanup when Hyperspace is secured. This setting is only set on the Citrix Server or AVD. |
TFA_LOGOFFCLEANUP_ONLOCK | EnableCleanupOnLock | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | False | Set to “True” to configure the plugin to call Logoff Cleanup when “DisableOnBeforeLock" is set to "True". This setting is only set on the Citrix Server or AVD. |
Endpoint - Hyperspace Workflow
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_LOGOFF_XA_ON_EPIC_SECURE_LOGOUT | LogoffXAOnEpicSecureLogout | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | False | Set it to "True" to have the ExactAccess client log off when a user logs off the Hyperspace application, and lock the ExactAccess client when a user secures the Hyperspace application. |
TFA_DISABLE_ONBEFORELOCK | DisableOnBeforeLock | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | False | Set to "True" if you do NOT wish to notify the Epic Session Manager when the ExactAccess client is locked. Use this setting to prevent Secure or Logout of Hyperspace when locking the ExactAccess client. |
TFA_ENABLE_ONBEFORELOCKTIMEOUT | EnableOnBeforeLockTimeout | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | False | This is used to trigger an event that indicates that the OnBeforeLock event was triggered because of user inactivity. If this is the case, then the normal lock behavior is not followed, Hyperspace will not be secured or logged off, no action will be taken, and Hyperspace will remain in its current state. |
TFA_ENABLE_ONBEFOREQUITUSER | EnableOnBeforeQuitUser | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | True | This setting is enabled by default. This triggers an event to log off of Hyperspace when a user interactively logs off XA. In standard mode, this is triggered in a tap-over scenario, but it also shuts down Hyperspace since it doesn’t allow more than one instance from the same workstation name. In Kiosk mode non-locking configurations, this setting must be set to False. |
TFA_HYPERSPACE_SECURE | SecureActive | HKEY_LOCAL_MACHINE\Software\ HeatlhCast\ExactAccess\TFA Settings | False | Indicates the behavior of Hyperspace when a tap-out occurs -- if SecureActive is False (default) - Hyperspace will Log Off. If SecureActive is set to True - then Hyperspace will instead be secured for the current user on Tap Out. |
TFA_VERTICAL_OFFSET_FOR_LOGIN_SCREEN | TFA_VERTICAL_OFFSET_FOR_LOGIN_SCREEN | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | 160 | This setting defines how far down the Hyperspace window the authentication window should be placed. |
Endpoint - Launch Configuration
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_AUTOLAUNCH | AutoLaunch | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | True | (Default) Set to “True” to enable the configured auto-launch functionality. Set to “False” to not auto-launch. |
TFA_LAUNCHTYPE | LaunchType | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | 0 | Set to "1" to launch a locally installed instance of Hyperdrive. Set to "2" to launch Hyperspace via Epic Warp Drive. (deprecated) Set it to "3" to launch Hyperspace, which is published using pubLauncher.exe. Set it to “4” to launch Hyperdrive published from Citrix using pubLauncherSF.exe. Set it to “5” to launch Hyperdrive, which is published as a remote app from Azure Virtual Desktop. Set it to “6” to launch Hyperdrive, which is published as a remote app from Omnissa Horizon. |
Endpoint - Hyperdrive Launched Locally or Using Epic Slingshot
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_HYPERSPACE_PATH | HyperspacePathExeName | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\TFA Settings\HyperspaceConfiguration1 | Not Set | This is the full path to Hyperdrive, Hyperspace, or the Epic version independent launcher. "C:\Program Files (x86)\Epic\Hyperdrive\VersionIndependent\Launcher.exe" |
TFA_HYPERSPACE_PARAMS | HyperspaceParams | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\TFA Settings\HyperspaceConfiguration1 | Not Set | Parameters that may be needed, for example, "id=665 env=slingshot" used to start slingshot. |
TFA_HYPERSPACE_WINDOW_CLASS | HyperspaceWindowClass | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\TFA Settings\HyperspaceConfiguration1 | thunderrt6mdiform | Set to “ Chrome_” for Hyperdrive. Set tp “thunderrt6mdiform” for Classic Hyperspace. |
Endpoint - Hyperdrive Launched via Citrix using pubLauncherSF.exe
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_SF_AUTHTYPE | AuthenticationType | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Storefront Settings\HyperspaceConfiguration1 | 0 | If set to "0", pubLauncherSF.exe will use the eXactACCESS User's Credentials to connect to Storefront. If set to "1", pubLauncherSF.exe will use Windows pass-through credentials. If set to 2, pubLauncherSF.exe will use Community Connect stored credentials. |
TFA_SF_URL | URL | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Storefront Settings\HyperspaceConfiguration1 | Use the Receiver for Web Sites URL found in Citrix Studio > Citrix Storefront > Stores. The correct URL, when placed in a browser, should be resolved to the Citrix Storefront login page. If you are using NetScaler to connect to the Storefront site, the correct URL will resolve to a Netscaler login page that, when logged into, will forward you to the desired Storefront site. | |
TFA_SF_RESOURCE_NAME | ResourceName | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Storefront Settings\HyperspaceConfiguration1 | Resource Name | This is the name of the Citrix resource to be launched. It is the same as the application name that is displayed on the Storefront website. |
TFA_HYPERSPACE_WINDOW_TITLE | AppTitle | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Storefront Settings\HyperspaceConfiguration1 | Not Set | Enter the static portion of the main window’s title for Epic Hyperspace. Note: This setting does not have to match the entire Hyperspace window title, but the text entered needs to be present in the Hyperspace window title. i.e. "Hyperspace" |
Endpoint - Hyperdrive Launched via Azure Virtual Desktop using AVD Remote App Launcher
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_AVD_AUTHTYPE | AuthenticationType | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\AVD Settings\HyperspaceConfiguration1 | 0 | “0” means that passthrough authentication has been configured in the Remote Desktop client. This is currently the only authentication type that is supported. |
TFA_AVD_APPNAME | AppName | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\AVD Settings\HyperspaceConfiguration1 | Hyperspace | Set this to the AVD Remote App published name. |
TFA_AVD_USERNAME | Username | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\AVD Settings\HyperspaceConfiguration1 | user@domain | Set this to the Azure domain account that has been configured to access and launch the Remote App configured. |
TFA_AVD_WINDOW_TITLE | WindowTitle | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\AVD Settings\HyperspaceConfiguration1 | Hyperspace | Enter the static portion of the main window’s title for Epic Hyperspace that is displayed from the Remote App. Note: This setting does not have to match the entire window title, but the text entered must be in the window title. |
TFA_AVD_WINDOW_CLASS | WindowClass | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\AVD Settings\HyperspaceConfiguration1 | RAIL_WINDOW | Enter Epic Hyperspace main window title class name. |
Endpoint - Hyperdrive Launched via Omnissa Horizon Client App Launcher
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_HORIZON_LAUNCHURL | LaunchURL | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Horizon Settings\HyperspaceConfiguration1 | (empty) | Omnissa Horizon URI used to launch the published Hyperdrive application (e.g., vmware-view://server/AppName) |
TFA_HORIZON_WINDOW_TITLE | WindowTitle | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Horizon Settings\HyperspaceConfiguration1 | Hyperspace | Enter the static portion of the main window’s title for Epic Hyperspace that is displayed from the Horizon Client Remote App. Note: This setting does not have to match the entire window title, but the text entered must be in the window title. |
TFA_HORIZON_WINDOW_CLASS | WindowClass | HKEY_LOCAL_MACHINE\SOFTWARE\HealthCast\eXactACCESS\Horizon Settings\HyperspaceConfiguration1 | HorizonUnityHostWndClass | Enter Epic Hyperspace main window title class name used in Horizon Client. |
Endpoint - Community Connect
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_EPICUSERCIID | EpicUserCIID | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\hciepicsessionmgr | Not Set | This setting is used in configurations where a different username and password are needed than the domain user account used to log in to XA. The setting needed is an XA control ID configured for the additional credential. The control ID needed is retrieved when creating an application in the XA administrator. |
TFA_EPICUSERCIID_CAPTION | EpicUserCIIDCaption | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\hciepicsessionmgr | Not Set | This setting is used when the Epic login requires a username and password other than the user account used to log in to XA. Use this setting to change the caption displayed when prompting the user for the username and password needed. |
TFA_EPICUSERCIID_PROMPT | EpicUserCIIDPrompt | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\hciepicsessionmgr | Not Set | This setting is used in configurations where a different username and password are needed when the domain user account is used to log in to ExactAccess. Use this setting to change the prompt displayed when prompting the user for the username and password needed. |
Endpoint - Secondary Authentication
Parameter Name | Registry Name | Registry Keys Affected | Value | Setting Description |
|---|---|---|---|---|
TFA_UITIMEOUTSECONDS | UITimeoutSeconds | HKEY_LOCAL_MACHINE\SOFTWARE\ HealthCast\ExactAccess\TFA Settings | 30 | This setting is the number of seconds the re-authentication prompt waits for a user to tap a badge. This setting doesn’t have an impact when the login device is prompting for login, only when being called for verification or cosign verification. This setting is configured on the device where Hyperspace is installed. |