Accessing Microsoft Teams using organizational or personal credentials
Hi Sattar,
Thank you for taking the time to share the detailed information about your environment, along with the error messages you've captured.
From the details provided, one point that stands out is the duplicated openid value shown in the failed request.
Since this request is generated as part of the Microsoft Teams authentication flow, rather than being a scope that is typically configured manually in Microsoft Entra ID, the duplicate entry is certainly worth investigating further. Additionally, given that the older Teams client continues to work correctly within the same Citrix environment, this may suggest that the issue is related either to the newer Teams client itself or to how it interacts with the existing Citrix UPM profile data.
As an initial isolation step, I would recommend testing with one affected user by creating a new UPM profile, while leaving the existing profile unchanged.
- If Teams signs in successfully using the new profile, this would indicate that persisted profile data or cached authentication information may be contributing to the issue.
- On the other hand, if the same error occurs even with a clean profile, it would be reasonable to focus the investigation on the Teams client version or the underlying image-level configuration.
Could you also confirm the exact versions of:
- Citrix VDA 2203 CU
- MsTeamsPluginCitrix
This information may be useful because the current guidance for the new Teams VDI solution references VDA 2203 LTSR CU3 or later, Citrix Workspace app 2402, and MsTeamsPluginCitrix 2024.41.1.1.
In addition, before clearing any cached data, I would suggest enabling Extended Logging, reproducing the issue, and then collecting the Teams diagnostic logs using: Ctrl + Alt + Shift + 1
Microsoft generally recommends collecting the logs immediately after the issue occurs to ensure the relevant diagnostic information is captured.
Should the issue continue, the Teams diagnostic logs, together with the Request ID, Correlation ID, UTC timestamp, and the corresponding Entra sign-in logs, would provide valuable insight for further analysis. It may also be beneficial to compare the logs from a working Teams version against those from the affected version, as this could help determine whether a change introduced in the newer client is influencing the authentication flow.
For reference:
I hope this helps point the investigation in the right direction. Please let me know the results of the clean-profile test and the Citrix component versions, and we can review the next steps accordingly.
Kind regards,