

You can use a GPO to configure this on the client side There is a group policy setting at User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page > Site to Zone Assignment List that can be used to put Internet sites in Internet Explorer security zones. Local Intranet zone should have Automatic Logon only in Intranet Zone enabled. Click OK.Įnsure that the internal StoreFront FQDN is in the Local Intranet Zone in Internet Explorer as below. Select Enabled and then check the box next to Allow pass-through authentication for all ICA connections. On the right, double-click Local user name and password. Go to Computer Configuration > Policies > Administrative Templates > Citrix Components > Citrix Receiver.Įxpand Citrix Receiver and click User authentication.

adml) template into PolicyDefinitions if you haven’t already by following this guide.Įdit a GPO that is applied to the client PCs where the Citrix Receiver is installed. To verify that SSON is installed, go to C:\Program Files (x86)\Citrix\ICA Client and look for the file ssonsvr.exe.Īnd if you open regedit and go to HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order, you should see PnSson in the ProviderOrder. When installing Receiver on a VDI ensure you click the Enable Single Sign-On check box as below: Set-BrokerSite -TrustRequestsSentToTheXmlServicePort $True Run the following on a delivery controller from a Windows Powershell Prompt as an Administrator:
