Fslogix (2.9.8308.44092)

Brass Contributor

 i use citrix xenapp xendesktop 2203 multi user session on windows server 2019 with fslogix
everything worked fine
but yesterday since i updated fslogix to FSLogix version 2210 (2.9.8308.44092) for vhdx compaction
outlook asks the user for the password at log off if he forgets it and then at the next login he asks for it.
depends on what?

28 Replies
no one else has had this problem?

@Scherubini 

 

Maybe you could be a little clearer with what the problem is exactly. Outlook asks the user for the password at log off? When a user signs out Outlook is asking for a password while his session is logging off? What do you mean by if he forgets it?

@Scherubini I've the same problem on our infrastructure. 

Outlook and OneDrive are prompting for credentials after upgrade from Version 2.9.8228.50276 to 2.9.8361.52326. 

But only once per session. During the open session it's saved. Just after Logout/Login it's newly asked for each user: 

Chris1989_0-1671613513036.png


=> After each Logout it newly asks for the users password (modern authentication screen of both is appearing) 

I did an uninstall of version 2.9.8361.52326 and new install of the old version and the problem has gone.. 

=> Something is deleting users stored credentials or keys during Logout for Office and OneDrive.. 

Even disabling new features didn't changed that behaviour:
-Disk compaction
-AppX 

Regards

Outlook and OneDrive are prompting for credentials after upgrade from Version 2.9.8228.50276 to 2.9.8361.52326. But only once per session. During the open session it's saved. Just after Logout/Login it's newly asked for each user:
Hi,

We have a similar case. Apprently it is linked to the state of your VDI/RDS.
Not yet found a solution, though.

https://learn.microsoft.com/en-us/fslogix/troubleshooting-known-issues#azure-ad-authentication-for-a...

so the best solution is to stay under the FsLogix version (2.9.8308.44092) from this version onwards the problem arises, can it be fixed with a patch that will make Microsoft fslogix?

Correct,

We did a rollback to version 2.9.8228.50276 and have no problems at the moment.
Waiting for an update of Microsoft that tackles the issues.

@TiboV let's wait, whoever has news first shares
thank you

@Scherubini Problem is known officialy now: 

 

Known Issues - FSLogix | Microsoft Learn

 

Users may be required to authenticate to their applications (for example, Microsoft 365 apps, Teams (work or school), OneDrive, etc.) at every sign-in. The repeated authentication prompts are due to the virtual machines Azure AD device state. We recommend virtual machines are Azure AD Joined (AADJ) or Hybrid Azure AD Joined (HAADJ) for the best user experience.

 

Virtual machines, which are AADJ or HAADJ create the user's primary refresh token (PRT) at sign-in. Primary refresh token(s) created at sign-in will be used to authenticate to Azure AD based applications. Standard Domain Joined (DJ) virtual machines don't create a PRT at sign-in, instead rely on the Microsoft Azure AD broker plugin.

 

Azure AD broker directories and apps

 

Starting in FSLogix 2210 (2.9.8361.52326) and later versions, all content stored in following locations is no longer roamed as part of the user profile.

 

%USERPROFILE%\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
%USERPROFILE%\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
%USERPROFILE%\AppData\Local\Microsoft\TokenBroker

thank you very much so whoever wants to use the version of FSLogix 2210 from (2.9.8361.52326) and later what should he do?
We have the same issue. RDS 2019 and FSLogix 2210 (2.9.8361.52326).

We are using the registry key mentioned in the article. Since we do not want multiple devices in Azure AD. Regkey below
"HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin: "BlockAADWorkplaceJoin"=dword:00000001"

The way I see it is two options.

1. Keep this version and wait for a new version release that fixes the issue.
2. Roll back to a version below 2210 (2.9.8361.52326)
hello do you know if fslogix solved the problem?
There is a 2210 hotfix 1 out on private preview. However if you want to address this problem I would recommend you to install version (2.9.8228.50276) for the time being

FSLogix 2210 hotfix 1 does not resolve.
It keeps asking for the psw every time I log into citrix and open office

@Scherubini 

 

Did you add the registry key ”RoamIdentity” with value 1? You must enable this in order to save the credentials

 

ref: https://learn.microsoft.com/en-us/fslogix/reference-configuration-settings?tabs=profiles#roamidentit...

 

must work without making changes, fslogix must provide a product that works without making any further changes. Authentication must remain modern with Mfa active in 365.

The new version (2.9.8440.42104) with Hotfix is working fine on our infrastructure. 

Setting up the group policy option "Roam identity" to Enable and everything is working as usal..

Regards

Setting the "Roaming Identity" Group Policy option to Enable and everything works as usual.
what this key?

@Scherubini 

 

You need to add the regkey under 

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\FSLogix\Profiles

 

We can confirm it works with RoamIdentity value 1 in combination with FsLogix version 2.9.8440.42104