Policy with 'Allow - Without Citrix Gateway' filter is applied to ICA sessions not connected via Citrix Gateway Service.

Expected behavior is that the policy should be applied only to internal ICA sessions not connected via Citrix Gateway.
However, policy is also applied incorrectly to an external ICA session connected via Citrix Gateway.
For Citrix DaaS, Adaptive Access must be enabled to use Access Control. With Adaptive Access disabled, Smart Access Tag processing is disabled in DaaS, which means all sessions are treated as Not Via Gateway under Access Control.
https://docs.citrix.com/en-us/citrix-daas/policies/policies-create.html

Enable Adaptive Access .
https://docs.citrix.com/en-us/citrix-daas/manage-deployment/adaptive-access.html

Access Control filter for “Without Citrix Gateway” is incorrectly applied to external traffic passing through Citrix Gateway Service.