The Workspace service is used to manage access to Application Groups, Applications and Resources for each users.
Each Application Group, Application or Resource is mapped to Active Directory security groups. These can then be used with services such as Citrix Hosted Apps and Desktops, VMWare Workspace One, or even to control access to Applications and Groups using traditional tools such as SCCM.
The Workspace Import tool speeds the import of groups from Active Directory for subsequent management via Workspace.
Currently, only Private Locations support the Workspace Import service
Navigate to the customer and provision the Workspace/Citrix service - It is likely if this is a fresh installation, there will be no Applications or Resources. Regardless of this, just provision the service even if you have no values for Applications/Resources.

Importing the Applications/Resources
Once the service is provisioned to the customer , Navigate to "Services > Workspace/Citrix > Configuration > Import" on the left hand menu.
The Workspace Import feature will retrieve the OU structure from the directory.
Select the Relevant OU where the Security Groups are stored.
In this example, the Security Groups are under "WorkspaceUsersOU > Queenstown > Executive Team"

Select the relevant Applications/Resources you'd like to import. Multiple Applications/Resources can be selected for import.
You will be presented with the option of selecting if the Group is an Application or Resource.
If the "Provision the Workspace service to users who are not provisioned with the service already." Option is selected, it will automatically provision all the users who are members of the selected Application or Resource with the Workspace Service, as well as adding the respective Application/Resource to them that they are a member of.
Now, we can see that our user has the relevant Service and the correct Applications that they have in the Remote Active Directory