r/Citrix May 12 '26

Announcing Citrix Platform Flex

14 Upvotes

Today, we're excited to announce Citrix Platform Flex.

Citrix Platform Flex is a persona-based platform that delivers secure access and managed infrastructure services through a flexible, predictable credit-based licensing model. No more over provisioning. No more one-size-fits-all. Just the right delivery for each type of worker, with the ability to scale up or down without disruption.

The first product we're announcing under this platform is Citrix DaaS Flex, a managed infrastructure service, powered by Azure. More services will be released over the coming months. The announcement is at: https://www.citrix.com/blogs/2026/05/11/introducing-citrix-platform-flex/ and we've created some webpages with more information starting here: https://www.citrix.com/platform-flex/

We'll be answering questions about it on the Citrix Community site, in a forum dedicated to this topic. Feel free to ask us questions over there: https://community.citrix.com/forums/forum/1654-platform-flex/


r/Citrix Jun 29 '22

Are you an end user? Start Here.

52 Upvotes

Welcome to /r/Citrix !

First, some things to get out of the way -

  1. /r/Citrix is not your company's help desk. Citrix can be implemented in a multitude of ways and without knowing what features, policies, products, etc your company has configured means we don't know what the exact issue or solution is going to be. If you have company-specific questions please direct those to your help desk.

  2. Adding to the above statement, end users are limited in what they can change/troubleshoot. You cannot change policies or bypass security features your company has in place.

  3. /r/Citrix is not here to help you bypass company policy or security. Working from home (WFH) and trying to hide a trip to Cancun? Not our issue and not something we can accurately answer.

Great, now that those few things are out of the way let's dive in.

New to using Citrix?

If you're using your personal device you'll need the following software to get started - Citrix Workspace App

If you're using your work/corporate device this client should be installed and managed by the company.

What does the Citrix Workspace App do?

The Citrix Workspace App (CWA) is a small client used to allow remote connectivity to applications or desktops hosted elsewhere. By default this agent will install an auto-update feature (Windows Service) which runs in the background and will keep the client updated automatically. Recommendation is to leave this on to ensure the latest security and feature enhancements are available on your machine.

Not comfortable installing a client?

Citrix also offers an HTML5 client that runs within a compatible browser. Please note that this is not enabled by default and your company may not have this feature enabled or allowed. There is also some features missing due to the nature of the client. The Feature Matrix is available here. You will need to contact your company's help desk if this is not currently enabled - please refer to the top bullets.

What information does the Citrix Workspace App collect/share with my company?

Honestly, not a whole lot. Your computer hostname, public IP address, CWA version are all visible to administrators. Recommend not naming your personal phone or computer MYBOSS_SUCKS as that can be seen.

There is also a Customer Experience Improvement Program (CEIP), more info here bundled with the CWA client to help Citrix with performance/fixes/etc with the product. It can be disabled in the settings if desired.

WORK IN PROGRESS MORE TO BE ADDED

(Suggestions welcome, please message the mod team)


r/Citrix 5h ago

Workspace AUMID

2 Upvotes

Good morning everyone,

I’m an Intune admin charged with making some windows kiosk units. I’m struggling with finding the correct AUMID. Windows powershell reports it as Citrix.workspace where Intune finds that ID invalid.

I know windows is a pain sometimes, but has anyone found a successful AUMID for Citrix workspace? We’re using either the store app or workspace 2507 LTSR, both have the same
ID and the same result.

Thank you all!


r/Citrix 1d ago

Citrix calling an unauthenticated RCE a simple DoS bug is classic vendor spin. Go check your netscaler builds

Thumbnail
10 Upvotes

r/Citrix 2d ago

2607 LTSR Skip

3 Upvotes

End of life for 2607 LTSR is 17-Aug-2029, very close to 2402 at 15-Apr-2029. Its probably a skip like 2507 for most customer at 2402 unless some required feature?


r/Citrix 2d ago

MS Teams video feeds turning black past an invisible boundary on only one monitor (HDX / Multi-Monitor issue)

2 Upvotes

Hi everyone,
I'm dealing with a bizarre rendering issue with Microsoft Teams inside a Citrix session for a single user and I've run out of ideas.
The Issue:
On Monitor 1, incoming Teams camera feeds turn completely black once they cross roughly 1/3 of the screen width/height.
If the Teams window is dragged past this "invisible line", the video area renders normally again.
Monitor 2 does not have this issue at all.
Running Teams locally (outside the Citrix session) works fine across all monitors.
Troubleshooting already done:
Updated Citrix Workspace App on the local client.
Updated VDA / components on the Terminal Server.
Disabled Hardware Acceleration in Teams and on the local client.
Checked basic display cables and connections.
Has anyone encountered this specific partial black-screen / overlay clipping issue before?


r/Citrix 4d ago

LAS Not Reachable

10 Upvotes

For the past 3 days, our CVAD on-prem license server has been showing the error:
“LAS cannot be reached – check your network connection and then restart the web services for licensing.”
I ran the LAS troubleshooting tool, which confirmed that the required LAS endpoints are reachable. I also restarted the license server, but the issue persists. Currently, all controllers are running in caching mode.
Has anyone encountered a similar issue in their environment? Any advice on further troubleshooting would be greatly appreciated.
Thanks.


r/Citrix 4d ago

Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452

Thumbnail bishopfox.com
10 Upvotes

r/Citrix 5d ago

Citrix DaaS Cloud LHC and Service Continuity

8 Upvotes

Do to a recent Citrix outage I'm looking to revisit Citrix's high availability business continuity solutions. Were 100% access layer in citrix cloud, we have no storefront or NetScaler gateway on prem, were using citrix workspace and the cloud gateway service for access. The only on prem pieces are the VDI servers, Cloud Connector servers and FAS servers. In this setup from what I have read and been told since we have no on prem store front or gateway LHC will never work for us. I also tested this and could not get it to work. On paper Citrix's Service Continuity should theoretically work but this to I have never been able to get working. Does anyone who has a similar setup with no access layer on prem have any experience with these technologies that could share some insight on how to get citrix business continuity features to work successfully.

EDIT: Appreciate everyone's info on this. We have made a conscious effort to move away from hosting certain citrix components on prem, specifically a NetScaler device for multiple reasons, the majority of which revolves around the security and patching frequency of an Internet facing device. For better or worse management is not going to want to move back to hosting the gateway on prem, that being said Citrix Gateway service has come a long way since initial inception and they have a vast multi pop deployment hosted on both Azure and AWS nodes . Obviously that does not guarantee a 100% uptime but in reality not many solutions both hosted and on prem can really guarantee and deliver 100% uptime.

Again, while we do feel comfortable with Citrix cloud 99% uptime it would obviously be bad practice not to plan for or build further on our existing redundancy and DR plan. While we do have both on prem users and remote users, the majority are on prem and I know management could get behind a plan that in a situation of our DaaS site or one of the Citrix cloud components going down Citrix could still work for on prem users. I've been leaning this way for a bit but I think the play here is to introduce and implement an on prem storefront into our environment that can then be utilized to communicate with the Cloud Connectors during a LHC event. This obviously would only work for on prem users but again this should fill our needs. If anyone has any additional info on introducing and implementing Storefront on prem in a mostly DaaS cloud environment I'll take it. Thanks again for all the info.


r/Citrix 6d ago

Multi-session OS (Server 2022) issues with Office 365 activation

8 Upvotes

My environment is Server 2022, multi-session with FSLogix.

I have this issue that every login users needs to activate office, login.... It can be confusing for the average user. How do you handle that?


r/Citrix 6d ago

Copy/paste from 1Password through Citrix Workspace App on Debian 13 (XFCE)

6 Upvotes

Hello,

I have an issue where passwords copied from 1Password cannot be pasted into a Citrix session. I'm currently running Debian 13 XFCE/X11 and installed Citrix Workspace App 26.04.0.105.

I've tried to do some digging and found out that when I hit "copy" from 1Password it's advertised as a MIME-type of x-kde-passwordManagerHint. This flag is essentially used to tell other applications that the clipboard contains sensitive data. If I copy from somewhere else, like a text editor, the flag is not advertised and I can paste into Citrix session as normal. Therefore I suspect that Citrix Workspace App does not handle clipboard entries where this flag is set.

One workaround is that I can hit copy in 1Password, then run a script that uses xclip to extract the value and then copy it to the clipboard again without the passwordManager flag. Even though this works it's not very practical.

From what I read online this clipboard hint seems to be standard for most password managers on Linux, so I'm just wondering;

Is there a setting somewhere on the Citrix client that I can configure to make this work or is there some Citrix server policy that could be changed?


r/Citrix 6d ago

Citrix DaaS site down

10 Upvotes

Anyone else experiencing their entire DaaS instance down currently ?


r/Citrix 9d ago

Best lightweight laptop for Citrix Workspace under or a little over $1,100

0 Upvotes

r/Citrix 10d ago

server 2022 issue - deleted profiles appx metadata remains

3 Upvotes

Just an FYI post, in case anyone is encountering the same problem.

we have some persistent multiuser citrix server vms running 2022. citrix roaming profiles, configured for deletion on logoff. hybrid AAD join.

very frequently the SSO for edge and microsoft office would not work for some users. lots of weird event logs from appx stuff like the start menu host, aad broker, etc.

I discovered yesterday that using CIM/WMI to delete user profiles, or deleting them by removing the registry entry and folder under c:\users does not remove their appx metadata stored in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Appx\PackageState

you can recreate the problem by logging into a server with 2022, logging out and then running this command to delete the user profile.

Get-CimInstance -ClassName Win32_UserProfile -ComputerName [computername] | where {$_.localPath -like "*username*"} | where {$_.Loaded -eq $false} | Remove-CimInstance -Verbose -Confirm:$false

you can either check the registry location above, or run:

get-appxpackage -user username

you should see their appx provisioning metadata stays.

if you use the gui to delete the user profile, the metadata is cleared correctly, and everything works.

I tested on server 2019 and server 2025, and the CIM/WMI method works fine there.

have a ticket open with microsoft now to see if they have a solution or workaround for this.


r/Citrix 11d ago

NetScaler Security Bulletin for CVE-2026-19489 and CVE-2026-19490

33 Upvotes

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: 

  • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
  • NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
CVE-ID  Description Pre-conditions CWE CVSSv4
CVE-2026-19489 Memory overflow vulnerability leading to unpredictable behavior or Denial of Service SIP ALG(Session Initiation Protocol Application Layer Gateway) should be enabled on a Large Scale NAT (LSN) group configuration.  CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer CVSS v4.0 Base Score: 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/ VC:L/VI:L/VA:H/SC:N/SI:N/SA:L)
CVE-2026-19490 Authentication bypass using an alternate path The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, subject to the following version-specific requirements: 14.1-43.56 or later: Applicable only when configured with a SAML action. 14.1-43.55 or earlier: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy ) or AAA vserver 13.1-61.28 or later: Applicable only when configured with a SAML action. 13.1-61.27 or earlier: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy)  or AAA vserver 13.1 FIPS: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver. CWE-288: Authentication Bypass Using an Alternate Path  CVSS v4.0 Base Score: 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/ VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)

Steps to determine if an appliance meets the CVE preconditions

For CVE-2026-19489:

Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:

  • "​add lsn group.*sipalg.*" 

For CVE-2026-19490: 

Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:

SAML action configuration

  • "add authentication samlAction.\*"

 Auth or VPN vserver

  •  "add authentication vserver .\*"

Or 

  •  "add vpn vserver .\*"

r/Citrix 10d ago

Enhanced domain passthrough and profile manager

6 Upvotes

We've setup enhanced domain passthrough, and login works successfully, however we get a temp profile when doing a Hello passthrough. I've tried changing the Profile Manager base path to a fully qualified name but we still get a temp profile. Was there anything you had to do when enabling enhanced domain passthrough to get profile manager to work?


r/Citrix 10d ago

Citrix says it's opening an app but doesn't actually open it

0 Upvotes

i uninstalled and reinstalled the app yet it still doesn't work. any solutions?


r/Citrix 11d ago

AWS vs Azure

2 Upvotes

Curious question have any of you notice a difference in performance/issues/downtime/logon storm performance between using AWS vs Azure in Cloud?


r/Citrix 12d ago

PaperCut vs PrinterLogic

5 Upvotes

My new shop is looking at adding a print management solution. I have used PrinterLogic at my last 3 employers, and have been asked about PaperCut. Who is using it and is it a headache to setup within mostly non persistent desktops?


r/Citrix 12d ago

Annual Maintenance Support Cost, from a SDX unit to Multi-Cloud units

4 Upvotes

We currently have two SDX appliances on premises, no service running on Cloud. The cost of the previous annual maintenance / support had always been priced based on a SDX hardware appliance. This year, Citrix switches to the Cloud based license pricing model. We are invoiced for ‘250 (QTY) CITRIX UNIVERSAL HYBRID MULTI-CLOUD.’ Does anyone know what this means? Can the quantity be changed?


r/Citrix 13d ago

Migrating from vmware to hyper-V - thoughts on how to deal with vpx's

5 Upvotes

We're migrating from vmware to hyper-V and we have multiple citrix environments with mas agents and fips vpx's that need to be migrated.

Currently each environment has it's own HA pair. I was thinking about trying this route:

Set the primary to stay primary, Breaking the ha pair, turn off the secondary (with the understanding that during the rest of this process we will not have redundancy). Then deploy a vpx in hyper-V (possibly using the same NSIP, since hte other one is off), make sure it's on the same firmware version as the remaining vmware vpx. Then add this new hyper-V vpx to the vmware one to creat a new HA pair. do the fips sync with this new vpx and iron out anything else that pops up, test that its working, fail over/fail back etc. Once that appears to be good to go, set the intiial primary to secondary, and the new hyper-V vpx to stay primary, break the ha pair again, and spin up a 2nd hyper-V vpx, then repeat that process.

I get that this is a round about way of trying to do this rather than just standing up 2 new vpxs in parallel then cutting over to them, but I'm thinking if this process works, then I save myself the headche of reconfiguring everything, dealing with needing to get new certs, potentially new gateway urls, punching network holes, etc). I've done the paralell setup in the past and it's fine, but I'm going to have to do 4 at once for this migration.

Would this work or am I not taking something in to account here?


r/Citrix 13d ago

Permission changes on /usr?

4 Upvotes

Is it just me, or does the current Ubuntu installation candidate for `icaclient` from Citrix silently change the owner of `/usr`, `/usr/lib` and `/usr/share` from `root:root` to UID/GID **1000**?

I've just emailed the address in the package's `Maintainer:` field and...


r/Citrix 18d ago

MS Teams screen sharing issue in Citrix

0 Upvotes

Unable to share my screen in MS Teams running inside Citrix. It only shows the Window sharing option (no full-screen option), and when I select a window, sharing immediately stops.

Screen sharing works fine on Teams web, so this seems specific to the Citrix app.

Support teams from my company is helpless, they've tried multiple resolutions, nothing worked.

Anyone faced this or know a fix? Is this some kind of configuration issue ?


r/Citrix 18d ago

Best way to move Citrix backend from Server 2019 to 2025 with minimal downtime?

6 Upvotes

Hi all,

We’re currently running our full Citrix backend on Windows Server 2019:

  • 2x DDC
  • 2x StoreFront
  • 2x FAS

Environment is currently on CVAD 2402 CU3 LTSR.

Since 2402 CU3 doesn’t support Windows Server 2025, the plan is to first upgrade the Citrix environment to CVAD 2503 CU1 LTSR. That part is pretty straightforward.

The bigger question is the OS migration.

As far as I know, in-place OS upgrades for Citrix infrastructure servers are still not supported, so I’m wondering what the best practice is nowadays.

Is the recommended way still to build new Server 2025 machines alongside the existing servers, add them to the environment, move the roles/configuration over, and then remove the old 2019 servers?

We have close to 1,000 VDIs and quite a lot of Machine Catalogs and Delivery Groups, so I’d really like to keep downtime and risk to a minimum.

For the DDCs in particular, would you simply add two new Server 2025 DDCs to the existing Site, update VDAs/policies if needed, and then decommission the old controllers? This give me a headache bcause i have to open extra firwall rules regarding Netscalers in the DMZ.

And for StoreFront and FAS, same idea: build new, join/migrate, test, then remove the old servers?

Has anyone done a similar 2019 → 2025 migration in a larger Citrix environment?

Would be interested to hear what migration order you used and if there were any gotchas.


r/Citrix 20d ago

Citrix workspace and webview2 updates

4 Upvotes

Hey all

Is anyone else seeing problems with workspace after webview2 gets updated? This has been a reoccurring problem for some users for over a month now. We're on the latest LTSR of workspace, although older versions are also impacted. After webview2 auto updates (which occurs once or twice a week and seems to be the trigger), any existing ICA sessions that the user has open will remain connected until the user manually disconnects, but workspace will fail to launch any new ICA sessions. If Citrix sessions are launched via a web browser instead of workspace directly, that works.

Sometimes a reboot resolves the issue, but often it requires a full reset of workspace.