Include legacy content

Archive: How to Configure Single Sign-on for Web Interface Using Version 10, 11, and 12x Plug-ins

  • CTX113004
  • Created On  May 03, 2007
  • Updated On  Jun 18, 2014
  • 21 found this helpful
  • Article
  • Topic : Authentication
This article is no longer maintained, its content refers to a discontinued product and may be out of date. Refer to the Discontinued Product Lifecycle or Active Citrix Product pages for more information on support schedules.


This article describes how to configure Single Sign-on (SSO) for Web Interface by using XenApp Plug-in 10.x, 11.x, or 12.x.


XenApp Plug-in 10.0 and later for Windows lets administrators use a provided Group Policy Object (GPO) template file called icaclient.adm, to modify some settings that were previously modified in the appsrv.ini file, such as, SSO through Web Interface. A truncated version of the appsrv.ini file is copied to the user profile by default. This behavior is expected.

The icaclient.adm file is available when you download and extract the file. This file is also available when you install the client. The default location for the icaclient.adm file is the \Program files\Citrix\ICA client\configuration folder.

Note: If you use the Web Interface Desktop Credential Pass-through feature, you must manually add the EnableSSONThruICAFile=On parameter to the appsrv.ini file located in the user profile.


To configure Single Sign-on (SSO) for Web Interface by using XenApp Plug-in 10.x, 11.x, or 12.x, complete the following procedure:

Note: The full client is required. This does not work with just the Web client.

  1. From a computer that is installed with XenApp Plug-10.x client or later, open the Group Policy Object Editor. Click on Start > Run and enter gpedit.msc.
  2. In the Group Policy Object Editor, right-click Administrative Templates.
  3. Click Add/Remove Templates.
  4. Browse to the C:\Program Files\Citrix\ICA Client\Configuration folder and add the icaclient.adm file.

  1. Expand Computer Configuration > Administrative Templates > Citrix Components > Presentation Server Client > User Authentication.
  2. On the right pane, select Local User name and password.
  3. Right-click and enable the policy for pass-through authentication. This policy is applied to all users logging on to this workstation.
  4. To apply GPO settings on a per-user basis, configure the settings under User Configuration. Expand User Configuration > Administrative Templates > Citrix Components.

  1. Run GPupdate on the workstation to apply the policy immediately.
  2. Log off and log on again.
  3. Check the Task Manager on the workstation to verify that the ssonsvr.exe process is running.

More Information

CTX122676 – How to Install the Web Plug-in and the Pass-Through Authentication Component for Use with ICA Files or Web Interface

CTX368624 – Troubleshooting Citrix Pass Through Authentication

CTX112957 – [Document Not Found]

CTX076838 – Troubleshooting the Desktop Credential Pass-Through Feature

CTX124871 – 12.0 Online Web Plug-in Using Single Sign On - SSON Fails with Web Interface

Group Policy settings can be configured on each individual client machine or in Active Directory for large environments.

Latest available Receiver downloads

For latest receiver information refer to SSON eDocs page 40 -

Share your comments or find out more about this topic

Citrix Forums



| Terms of Use | Privacy | Governance