Enhanced SSO session may experience problem accessing network shares or group policy updates

Enhanced SSO session may experience problem accessing network shares or group policy updates

book

Article ID: CTX693146

calendar_today

Updated On:

Description

You have configured configured Enhanced SSO for Citrix workspace app and you are either on Windows 10 or Windows 11 endpoints.

When you launch a desktop session and try to access the domain shares you may encounter the below prompt for credentials - 

You can also repoduce this issue by accessing the server through rdp by providing the /remoteguard switch.

  1. Open run and type mstsc /remoteguard
  2. In the prompt please use the FQDN of the server e.g. vda1.citrix.com
  3. launch the rdp session and try to access domain shares and you would encounter a credential prompt within it.

This can also affect applications which may be hosted on a network share, or any resources that an application may require access to that is hosted on a network share.

You may also observe events related to group policy updates failing within system event logs.

When you enter the credentials manually, the prompt goes away and does not asked the second time, but upon a reboot or on launch of a new session you may experience the problem again.

 

 

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Resolution

The issue is documented under the public article - https://learn.microsoft.com/en-us/answers/questions/1294080/windows-11-22h2-remote-credential-guard-(rcg)-hop

To avoid the issue, you can be on the below combinations that is compatible with remote credential guard feature.

1. Endpoint on Windows 10 + VDA OS on  Windows Server 2019  
2. Endpoint on Windows 11 + VDA OS on Windows Server 2025 

For fix related to this problem, please contact Microsoft support.


Problem Cause

The problem is due to a compatibility issue in remote credential guard feature. 

This is documented under - https://learn.microsoft.com/en-us/answers/questions/1294080/windows-11-22h2-remote-credential-guard-(rcg)-hop

Additional Information

https://learn.microsoft.com/en-us/answers/questions/1294080/windows-11-22h2-remote-credential-guard-(rcg)-hop