The Internet Explorer Enhanced Security Configuration (IE ESC) on the server is disabled for all users (admins and non-admins), but it still shows as enabled when users launch a Published Internet Explorer, and certain Web sites do not work as expected.
Caution! Refer to the Disclaimer at the end of this article before using Registry Editor.
Complete the following steps to resolve the issue:On the affected XenApp server, open the Registry Editor and navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap, change the value of “IEHarden” to “0” (zero, disabled).
Recreate the User Profile for all affected users so their profiles reflect the new registry setting on logon.
Restart the server.
When you disable IE ESC, Windows fails to update a necessary registry key, which causes the update to not reflect for remote users.