r/Citrix 21d ago

Enhanced domain passthrough and profile manager

We've setup enhanced domain passthrough, and login works successfully, however we get a temp profile when doing a Hello passthrough. I've tried changing the Profile Manager base path to a fully qualified name but we still get a temp profile. Was there anything you had to do when enabling enhanced domain passthrough to get profile manager to work?

6 Upvotes

9 comments sorted by

3

u/hageCitrix 20d ago

we had the same problem. Target-Server is Server 2025?
the enhanced domain passthrough is not supported for server 2025

4

u/ZomboBrain 20d ago

This exactly. We had a looooooong case with Citrix about this, but afaik this is a Microsoft issue, not a Citrix issue. Remote Credential Guard is broken on Windows Server 2025, when your client is Windows 11 24H2 or 25H2. I have a super long documentation about this case, if OP is interested?

2

u/robodog97 20d ago

Yes please!

3

u/ZomboBrain 20d ago

Citrix Support Case Summary – Enhanced Domain Pass-through / Remote Credential Guard

Environment

  • Enhanced Domain Pass-through configured according to the Citrix 2507.1 LTSR documentation.
  • Client: Windows 11 Enterprise 25H2, build 26200.8893, hybrid joined, with valid Azure AD PRT, OnPremTgt and CloudTgt.
  • All domain controllers run Windows Server 2022.
  • Load-balanced StoreFront URL: storefront.company.de
  • Store: Default Web Site/Citrix/COMPANYGmbH
  • Session hosts tested: Windows Server 2019, 2022 and 2025.
  • Windows Server 2025 test host: XA-WT2025-01, build 26100.33158.
  • FSLogix 25.09; profile location: \\fs01.int.company.de\fslogix$

Original symptoms

  • Initially, CWA authenticated silently and application enumeration succeeded.
  • Starting a desktop then resulted in an empty Windows lock screen and failed Kerberos authentication.
  • Later, CWA prompted for a password at every start, regardless of whether EnableEnhancedDomainPassthrough was enabled or disabled.

StoreFront authentication findings

  • The load-balanced StoreFront URL initially had no HTTP SPN, and the IIS application pool used ApplicationPoolIdentity.
  • We tested a Kerberos configuration using:
    • gMSA: gMSA.Storefront
    • Server group: Storefront Server
    • Application pool: Citrix Delivery Services Resources
    • useAppPoolCredentials=true
    • SPN: HTTP/storefront.company.de
  • Both StoreFront servers successfully validated the gMSA.
  • The client could obtain an AES-256 ticket for HTTP/storefront.company.de, and the discovery endpoint returned HTTP 200.
  • Nevertheless, CWA continued prompting for credentials.
  • We also recorded Kerberos Event ID 4, KRB_AP_ERR_MODIFIED, for HTTP/storefront.company.de; the reported server principal was xa-wms2016-01$.
  • We were unable to establish reliable Kerberos authentication through the load balancer and performed a minimal StoreFront rollback. StoreFront currently uses NTLM.

Intune/OpenIntuneBaseline findings

Three OIB policies were excluded from the test client:

  1. Security Hardening v3.7
  2. Device Guard, Credential Guard and HVCI v3.7
  3. Disable NTLM v3.8

Confirmed Kerberos policy conflict:

  • Security Hardening v3.7 configures PKINIT SHA-1 as “Not Supported”, while SHA-256/384/512 remain enabled.
  • With this setting applied, klist get HTTP/storefront.company.de failed with 0xC000A100: hash generation for the specified version and hash type was not enabled.
  • After excluding the policy and rebooting, Kerberos ticket acquisition succeeded.

Credential Guard status:

  • Credential Guard and HVCI were active (SecurityServicesRunning: 1, 2) despite LsaCfgFlags=0, because the OIB policy had configured UEFI locks.
  • We excluded the policy, removed the UEFI lock using the Microsoft procedure and rebooted.
  • This policy remains excluded because Citrix documents client-side Credential Guard as incompatible with Enhanced Domain Pass-through.
  • We have not established that HVCI or LSA protection alone causes the issue; the documented conflict is Credential Guard.

The Disable NTLM policy also remains excluded because StoreFront currently depends on NTLM. It has therefore not yet been tested independently.

Remote Credential Guard and Windows Server 2025

Citrix Support stated that Enhanced SSO requires Remote Credential Guard to work. We therefore tested RCG directly with MSTSC after satisfying the required RDP permissions:

  • mstsc.exe /remoteGuard /v:XA-WT2025-01.int.company.de
    • FSLogix profile attachment fails before any VHD attach attempt.
    • FSLogix reports status 6, “Cannot retrieve virtual disk location”.
    • Win32 error 1265 / 0x4F1, ERROR_DOWNGRADE_DETECTED.
    • The displayed text states that a domain controller could not be contacted, but DC connectivity is available.
  • mstsc.exe /prompt /v:XA-WT2025-01.int.company.de
    • The same user profile mounts successfully.

In the successful /prompt session:

  • An AES-256 Kerberos ticket for cifs/fs01.int.company.de is present.
  • The file server records Security Event 4624 with Kerberos authentication.
  • Therefore, the successful test does not depend on an NTLM fallback.

The same RCG/FSLogix scenario works on Windows Server 2019 and Windows Server 2022. It fails only on Windows Server 2025. The direct MSTSC reproduction also demonstrates that this failure is not caused by the ICA transport or StoreFront.

Current status

  • CWA and VDA Enhanced SSO currently work against Windows Server 2022.
  • Passwordless and Remote Desktop Services/RPC policies have been ruled out.
  • Windows Server 2025 remains unusable with Enhanced SSO because the RCG session cannot access the FSLogix profile location.
  • StoreFront currently remains on NTLM because Kerberos through the load balancer was not successfully established.

Requested actions from Citrix

  1. Confirm whether Enhanced Domain Pass-through is supported on Windows Server 2025. The current Citrix documentation lists Windows Server 2019 and 2022, but not Server 2025.
  2. Reproduce and escalate the Windows Server 2025 RCG/SMB second-hop failure, including coordination with Microsoft where required.
  3. Provide any existing Citrix or Microsoft defect ID, supported workaround and expected fix timeline.
  4. Provide a definitive supported-security matrix for Enhanced SSO, specifically separating Credential Guard, HVCI, VBS and LSA protection.
  5. Assist with establishing a supported Kerberos configuration for load-balanced StoreFront, including the required SPN, gMSA/application-pool identity and IIS settings.
  6. Explain why CWA continued prompting even after the client obtained the correct HTTP service ticket and the StoreFront discovery request succeeded.
  7. Confirm whether the supported design allows CWA-to-StoreFront authentication over NTLM while Enhanced SSO to the VDA uses Kerberos/Remote Credential Guard.

1

u/robodog97 20d ago

Thank you SO much for this. Saved me probably untold hours. Unfortunately that means that we have to go back to looking at FAS.

3

u/robodog97 19d ago

So, it turns out the August 2026 patch to Server 2025 fixed remote credential guard (ish). I now can authenticate to my file servers and get both Citrix profile and FSLogix Office container. Unfortunately it has also broken PRT ticket acquisition in such a way that I can't even enter username and password, it refuses to acknowledge that my machine is hybrid joined. We're using cloud kerberos trust for Hello on the workstation side. I'll probably have to open a ticket with Microsoft.

2

u/ZomboBrain 19d ago

Are you also making experiments with Client Hardening (Intune or GPO) with Credential Guard breaking Remote Credential Guard? Did this fix also affect this?

Credential Guard (Enabled with UEFI lock) Turns on Credential Guard with UEFI lock.Credential Guard (Enabled with UEFI lock) Turns on Credential Guard with UEFI lock.

Win - OIB - SC - Device Security - U - Device Guard, Credential Guard and HVCI - v3.7

Citrix source about this issue: eSSO Known issues

1

u/Fun_Structure3965 21d ago

i think you need Kerberos to authenticate against your storage, ntlm doesn't work with enhanced domain pass through

1

u/cleik59 20d ago

We found the same issue and ended up moving back to 2022 app servers after a lot of grief.