When setting up a Citrix Cloud connection in ControlUp within an MSP environment, an issue can arise where unassigned machines—those not part of any Delivery Group—are still appearing in client views even when the “Include Unassigned Machines” checkbox is unchecked. This behavior can cause security and privacy concerns, especially in a Citrix CSP (Cloud Solution Provider) model where multiple clients share the same CSP tenant but must not see each other’s resources.
The key insight is that the “Include Unassigned Machines” checkbox does not control whether unassigned machines are collected in ControlUp; rather, it controls ownership assignment. Unchecking this box only indicates that a particular connection does not own those unassigned machines. If no other connection claims ownership, ControlUp will assign all unassigned machines for that customer ID to the last available Citrix Cloud connection by default, causing them to appear in that connection’s view regardless.
Since filtering by Delivery Group names (for example, using exclusion rules like “*”) does not affect unassigned machines—which by definition have no Delivery Group—this method is ineffective for hiding these machines from clients.
The recommended solution is to use a dedicated MSP-only Citrix Cloud connection for unassigned machines. This involves adding a second Citrix Cloud connection using the same Customer ID but naming it something clearly internal, such as “CSP-Unassigned.” On this connection, the “Include Unassigned Machines” checkbox is checked, while on all client-facing connections it remains unchecked. By placing this MSP-only connection in a folder or with permissions that clients cannot access, unassigned machines are effectively segregated and hidden from end clients. This setup ensures clients only see Delivery Groups and connectors specific to them, while unassigned machines remain visible only to the MSP’s internal team.
In rare cases where the connector setup itself does not behave as expected—such as when unassigned machines do not show even when the “Include Unassigned Machines” box is checked—it may be necessary to contact ControlUp support for assistance.
For more details on configuring Citrix Cloud connections and collection rules, refer to ControlUp official documentation at https://docs.controlup.com and the ControlUp Academy at https://cuacademy.controlup.com.
Read the entire ‘Managing Unassigned Machines in Citrix Cloud Connections for MSP Environments with ControlUp’ thread below:
Hello, I am having an issue where I am setting up an EUC Connector at an MSP. I am using the collection rules to filter the Delivery Groups and Cloud connectors. I am running into an issue where it is pulling in Unassigned Machines even thought I do not have it checked. I am running the latest version of the console. Has anyone else seen this?
It would appear to me that the Include Unassigned Machines checkbox (meaning having it unchecked) is not working on Console 9.2.5 but maybe I am missing something obvious.
This is expected.
Include Unassigned Machines assigns ownership of Citrix machines that are not in a Delivery Group. Unchecked does not mean “don’t collect them.”
If no connection has it checked, ControlUp still puts those machines on the last Citrix Cloud connection for that Customer ID. With a single connector, that is always this one, so Unassigned Machines still shows.
Ok so no way to prevent that? Because we have a Citrix CSP model we do not want those machines to show up in Control up for a client with their own tenant. I hope that makes sense. For example in the screenshot above if I had not have blanked them out I could see the company name of other clients in our Citrix CSP Tenant. We do not want that.
For example can I exclude * to make sure they get removed?
We cannot have a client see other clients machines in Control up even if they are not in a delivery group for some reason.
There is no collection-rule switch that means “do not collect Unassigned Machines at all.” Unchecked only means “this connection does not _own_ them.” If no other connection owns them, ControlUp still puts that pool on the last connection for that Customer ID. Exclusion `` will not help: it filters Delivery Group names, and these machines have no Delivery Group. `` would remove the client’s DGs and still leave the other customers’ machine names.
What you can do is park that pool on an MSP-only connector so clients never see it:
1. Add a second Citrix Cloud connection using the same Customer ID.
2. Name it something internal, e.g.`CSP-Unassigned`.
3. On that connection only, check Include Unassigned Machines.
4. Leave that checkbox unchecked on every client connection.
5. Put`CSP-Unassigned`in a folder that client users cannot see (permissions/folder ACL).
6. Save and let the data collectors reload.
After that, each client connection should only show Delivery Groups and Cloud Connectors that match its inclusion patterns. The shared unassigned machines stay on the MSP connector.
I think I may need to open a ticket with support. I setup the connector but it shows no unassigned machines even though I checked the box.
My other site still shows all of them
Continue reading and comment on the thread ‘Managing Unassigned Machines in Citrix Cloud Connections for MSP Environments with ControlUp’. Not a member? Join Here!
Categories: All Archives, ControlUp for VDI
