Citrix Workspace Repeated Credential Prompts

Harry Porter 0 Reputation points
2026-10-02T13:15:26.4933333+00:00

Hi there, citrix Workspace continues to ask users to enter their credentials each time the application is opened, although SAML SSO has already been configured. The SSO setup is available, but the Workspace client does not appear to retain or use the existing authentication session correctly. Looking at the Workspace registry configuration to identify the settings that may need to be adjusted.

Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments

1 answer

Sort by: Oldest
  1. Domic Vo 34,170 Reputation points Independent Advisor
    2026-10-02T13:48:48.65+00:00

    Hello Harry,

    The repeated credential prompts in Citrix Workspace despite SAML SSO being configured usually point to the Workspace client not persisting the authentication token correctly. This is often tied to registry settings or client-side policies that control how Workspace handles authentication.

    First, confirm that the Workspace client is running the latest build, as older versions had known issues with SAML token persistence. Then check the registry under HKEY_CURRENT_USER\Software\Citrix\Receiver and HKEY_LOCAL_MACHINE\Software\Citrix\Receiver. The key to focus on is AuthManager\Sites. If the SAML site is not properly registered there, Workspace will continue to prompt for credentials. You should see entries like Store0 with values pointing to your StoreFront or Gateway URL.

    Additionally, verify that the EnableSSON DWORD under HKEY_LOCAL_MACHINE\Software\Citrix\Receiver is set to 1. If it is missing or set to 0, Workspace will not attempt to reuse the SSO session. On some builds, the relevant path is HKEY_LOCAL_MACHINE\Software\Wow6432Node\Citrix\Receiver.

    Another common cause is the Windows Credential Manager not storing the token. If Workspace is configured to use SAML but the token is not cached, every launch will trigger a fresh login. In that case, check if the policy AllowSavePassword is enabled in Citrix Studio or via Workspace app GPO templates.

    If all registry and policy settings are correct, but the issue persists, it may be due to Workspace not correctly handling the PersistentCookies setting on the Gateway. Ensure that your Citrix Gateway is configured to allow persistent cookies, otherwise the client cannot reuse the session.

    I recommend validating these registry keys and Gateway cookie settings first. If you confirm they are correct and the issue continues, we may need to enable Workspace logging (%localappdata%\Citrix\Workspace\Logs) to capture why the token is being rejected.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    DV.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.