EDGE issues within WVD

%3CLINGO-SUB%20id%3D%22lingo-sub-1222529%22%20slang%3D%22en-US%22%3EEDGE%20issues%20within%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1222529%22%20slang%3D%22en-US%22%3E%3CP%3EPilot%20users%20are%20having%20an%20issue%20with%20the%20EDGE%20browser%20within%20WVD%2C%20when%20accessing%20sites%20that%20leverage%20ADFS.%20Users%20can%20connect%20to%20one%20host%2C%20one%20day%20and%20Edge%20will%20work%20as%20expected%20when%20accessing%20sites.%20The%20next%20day%20they%20may%20connect%20to%20a%20different%20host%20and%20the%20will%20receive%20an%20error%20when%20trying%20access%20sites%20that%20leverage%20ADFS.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20error%20generated%20is%20%22Cannot%20connect%20securely%20to%20this%20page%22%20%22This%20might%20be%20because%20the%20site%20uses%20outdated%20or%20unsafe%20TLS%20security%20settings.%20If%20this%20keeps%20happening%20try%20contact%20the%20website%20owner.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20the%20users%20opens%20up%20IE%20in%20the%20same%20session%2C%20they%20can%20access%20the%20site%2C%20if%20the%20user%20resets%20edge%20via%20settings%2Fapps%20the%20site%20starts%20working%20(until%20they%20move%20to%20a%20different%20host%2C%20it%20appears%20again)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20implemented%20Redirections.xml%2C%20but%20are%20currently%20only%20excluding%20(%3CEXCLUDE%20copy%3D%22%26quot%3B0%26quot%3B%22%3EAppData%5CLocal%5CPackages%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5CAC%5CMicrosoftEdge%5CCache%3C%2FEXCLUDE%3E)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1285116%22%20slang%3D%22en-US%22%3ERe%3A%20EDGE%20issues%20within%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285116%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20we're%20seeing%20similar%20behaviour%20but%20it%20seems%20limited%20to%20when%20we%20have%20FSLogix%20enabled.%20Is%20that%20the%20case%20for%20your%20environment%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20FSLogix%20is%20disabled%20the%20the%20profiles%20write%20locally%20to%20each%20WVD%20host%20then%20we%20cannot%20replicate%20this%20problem.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20some%20testing%20with%20an%20FSLogix%20profile%20and%20could%20see%20that%20if%20the%20profile%20disk%20edited%20and%20the%20appdata%2Flocal%20folder%20is%20removed%2C%20that%20the%20issue%20seems%20to%20vanish.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20add%20further%20complication%2C%20we%20have%20some%20users%20that%20are%20excluded%20from%20group%20policy%20and%20they%20cannot%20replicate%20this%20fault%20at%20all%2C%20so%20we're%20now%20looking%20through%20to%20reverse%20engineer%20that.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1770296%22%20slang%3D%22en-US%22%3ERe%3A%20EDGE%20issues%20within%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1770296%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F568761%22%20target%3D%22_blank%22%3E%40Jonny5%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20the%20same%20issue%20and%20following%20steps%20solved%20my%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EExcluding%20%22AppData%5CLocalLow%5CMicrosoft%22%20didn't%20help%20with%20all%20the%20users%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERoot%20cause%3A%20Local%20profile%20wasn't%20deleted%20properly%20and%20especially%20this%20folder%20(locallow%5Cmicrosoft%5Ccrypto%5CTokenBindingKeys)%20was%20causing%20the%20issue.%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22tokenBindingKeys.jpg%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F225903i041AC7DB616E7269%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22tokenBindingKeys.jpg%22%20alt%3D%22tokenBindingKeys.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELots%20of%20users%20were%20already%20used%20WVD%20and%20FSLogix%20so%20it%20was%20unable%20to%20exclude%20the%20folder%20from%20some%20of%20the%20session%20hosts.%20To%20tackle%20the%20issue%20I%20enabled%20the%20following%20Group%20Policy%20and%20it%20worked%20like%20a%20charm.%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22ProfileContainer.jpg%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F225904iA0FF9F5C169997E7%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22ProfileContainer.jpg%22%20alt%3D%22ProfileContainer.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EExample%20of%20my%20redirection.xml%20file%3C%2FP%3E%3CPRE%3E%26lt%3B%3Fxml%20version%3D%221.0%22%3F%26gt%3B%0A%0A%26lt%3BFrxProfileFolderRedirection%20ExcludeCommonFolders%3D%220%22%26gt%3B%0A%20%0A%26lt%3BExcludes%26gt%3B%20%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocalLow%5CMicrosoft%26lt%3B%2FExclude%26gt%3B%20%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CGoogle%5CChrome%5CUser%20Data%5CDefault%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CMicrosoft%5CEdge%5CUser%20Data%5CDefault%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CPackages%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5CAC%5CMicrosoftEdge%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CBraveSoftware%5CBrave-Browser%5CUser%20Data%5CDefault%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%26lt%3B%2FExcludes%26gt%3B%0A%20%20%0A%26lt%3BIncludes%26gt%3B%0A%0A%20%26lt%3BInclude%20Copy%3D%223%22%26gt%3BAppData%5CLocalLow%5CSun%5CJava%5CDeployment%5Csecurity%26lt%3B%2FInclude%26gt%3B%0A%0A%26lt%3B%2FIncludes%26gt%3B%0A%0A%26lt%3B%2FFrxProfileFolderRedirection%26gt%3B%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20that%20will%20help.%3C%2FP%3E%3CP%3EPlease%20don't%20forget%20to%20restart%20your%20Session%20Hosts.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1770309%22%20slang%3D%22en-US%22%3ERe%3A%20EDGE%20issues%20within%20WVD%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1770309%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551632%22%20target%3D%22_blank%22%3E%40townendk%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F568761%22%20target%3D%22_blank%22%3E%40Jonny5%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20the%20same%20issue%20and%20following%20steps%20solved%20my%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EExcluding%20%22AppData%5CLocalLow%5CMicrosoft%22%20didn't%20help%20with%20all%20the%20users%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERoot%20cause%3A%20Local%20profile%20wasn't%20deleted%20properly%20and%20especially%20this%20folder%20(locallow%5Cmicrosoft%5Ccrypto%5CTokenBindingKeys)%20was%20causing%20the%20issue.%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22tokenBindingKeys.jpg%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F225903i041AC7DB616E7269%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22tokenBindingKeys.jpg%22%20alt%3D%22tokenBindingKeys.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELots%20of%20users%20were%20already%20used%20WVD%20and%20FSLogix%20so%20it%20was%20unable%20to%20exclude%20the%20folder%20from%20some%20of%20the%20session%20hosts.%20To%20tackle%20the%20issue%20I%20enabled%20the%20following%20Group%20Policy%20and%20it%20worked%20like%20a%20charm.%3C%2FP%3E%3CDIV%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22ProfileContainer.jpg%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F225904iA0FF9F5C169997E7%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22ProfileContainer.jpg%22%20alt%3D%22ProfileContainer.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EExample%20of%20my%20redirection.xml%20file%3C%2FP%3E%3CPRE%3E%26lt%3B%3Fxml%20version%3D%221.0%22%3F%26gt%3B%0A%0A%26lt%3BFrxProfileFolderRedirection%20ExcludeCommonFolders%3D%220%22%26gt%3B%0A%20%0A%26lt%3BExcludes%26gt%3B%20%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocalLow%5CMicrosoft%26lt%3B%2FExclude%26gt%3B%20%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CGoogle%5CChrome%5CUser%20Data%5CDefault%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CMicrosoft%5CEdge%5CUser%20Data%5CDefault%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CPackages%5CMicrosoft.MicrosoftEdge_8wekyb3d8bbwe%5CAC%5CMicrosoftEdge%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%20%26lt%3BExclude%20Copy%3D%220%22%26gt%3BAppData%5CLocal%5CBraveSoftware%5CBrave-Browser%5CUser%20Data%5CDefault%5CCache%26lt%3B%2FExclude%26gt%3B%0A%0A%26lt%3B%2FExcludes%26gt%3B%0A%20%20%0A%26lt%3BIncludes%26gt%3B%0A%0A%20%26lt%3BInclude%20Copy%3D%223%22%26gt%3BAppData%5CLocalLow%5CSun%5CJava%5CDeployment%5Csecurity%26lt%3B%2FInclude%26gt%3B%0A%0A%26lt%3B%2FIncludes%26gt%3B%0A%0A%26lt%3B%2FFrxProfileFolderRedirection%26gt%3B%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20that%20will%20help.%3C%2FP%3E%3CP%3EPlease%20don't%20forget%20to%20restart%20your%20Session%20Hosts.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Pilot users are having an issue with the EDGE browser within WVD, when accessing sites that leverage ADFS. Users can connect to one host, one day and Edge will work as expected when accessing sites. The next day they may connect to a different host and the will receive an error when trying access sites that leverage ADFS. 

 

The error generated is "Cannot connect securely to this page" "This might be because the site uses outdated or unsafe TLS security settings. If this keeps happening try contact the website owner."

 

If the users opens up IE in the same session, they can access the site, if the user resets edge via settings/apps the site starts working (until they move to a different host, it appears again)

 

We have implemented Redirections.xml, but are currently only excluding (<Exclude Copy="0">AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache</Exclude>)

3 Replies
Highlighted

Hi, we're seeing similar behaviour but it seems limited to when we have FSLogix enabled. Is that the case for your environment?

 

When FSLogix is disabled the the profiles write locally to each WVD host then we cannot replicate this problem.

 

I did some testing with an FSLogix profile and could see that if the profile disk edited and the appdata/local folder is removed, that the issue seems to vanish.

 

To add further complication, we have some users that are excluded from group policy and they cannot replicate this fault at all, so we're now looking through to reverse engineer that.

Highlighted

@Jonny5 

 

I have the same issue and following steps solved my issue.

 

Excluding "AppData\LocalLow\Microsoft" didn't help with all the users

 

Root cause: Local profile wasn't deleted properly and especially this folder (locallow\microsoft\crypto\TokenBindingKeys) was causing the issue.

 

tokenBindingKeys.jpg

 

Lots of users were already used WVD and FSLogix so it was unable to exclude the folder from some of the session hosts. To tackle the issue I enabled the following Group Policy and it worked like a charm.

 

ProfileContainer.jpg

 

Example of my redirection.xml file

<?xml version="1.0"?>

<FrxProfileFolderRedirection ExcludeCommonFolders="0">
	
<Excludes>	

 <Exclude Copy="0">AppData\LocalLow\Microsoft</Exclude>	

 <Exclude Copy="0">AppData\Local\Google\Chrome\User Data\Default\Cache</Exclude>

 <Exclude Copy="0">AppData\Local\Microsoft\Edge\User Data\Default\Cache</Exclude>

 <Exclude Copy="0">AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache</Exclude>

 <Exclude Copy="0">AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache</Exclude>

</Excludes>
  
<Includes>

 <Include Copy="3">AppData\LocalLow\Sun\Java\Deployment\security</Include>

</Includes>

</FrxProfileFolderRedirection>

 

Hope that will help.

Please don't forget to restart your Session Hosts.

 

Thank you

Highlighted

@townendk 

 

@Jonny5 

 

I have the same issue and following steps solved my issue.

 

Excluding "AppData\LocalLow\Microsoft" didn't help with all the users

 

Root cause: Local profile wasn't deleted properly and especially this folder (locallow\microsoft\crypto\TokenBindingKeys) was causing the issue.

 

tokenBindingKeys.jpg

 

Lots of users were already used WVD and FSLogix so it was unable to exclude the folder from some of the session hosts. To tackle the issue I enabled the following Group Policy and it worked like a charm.

 

ProfileContainer.jpg

 

Example of my redirection.xml file

<?xml version="1.0"?>

<FrxProfileFolderRedirection ExcludeCommonFolders="0">
	
<Excludes>	

 <Exclude Copy="0">AppData\LocalLow\Microsoft</Exclude>	

 <Exclude Copy="0">AppData\Local\Google\Chrome\User Data\Default\Cache</Exclude>

 <Exclude Copy="0">AppData\Local\Microsoft\Edge\User Data\Default\Cache</Exclude>

 <Exclude Copy="0">AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\Cache</Exclude>

 <Exclude Copy="0">AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache</Exclude>

</Excludes>
  
<Includes>

 <Include Copy="3">AppData\LocalLow\Sun\Java\Deployment\security</Include>

</Includes>

</FrxProfileFolderRedirection>

 

Hope that will help.

Please don't forget to restart your Session Hosts.

 

Thank you