Microsoft Teams Account Picker Appears on Every Login in Citrix Non-Persistent VDI – AADSTS70011 Invalid Scope Error

Sattar Ahmed Alamgeer 20 Reputation points
2026-09-25T05:27:32.5533333+00:00

We are experiencing a Microsoft Teams authentication/account-picker issue in a Citrix non-persistent VDI environment.

Environment:

Citrix VDA: 2203 LTSR

Windows 10 Enterprise 21H2 / OS Build 19044

Microsoft Teams: 26198.304.4946.9672

Citrix Workspace App: 2402

Citrix UPM is used for profile management.

VDIs are non-persistent and provisioned using PVS/ELM.

Teams is running in Citrix HDX Optimized mode.

Issue:

After updating Teams, affected users are repeatedly presented with the Teams account picker/sign-in prompt instead of Teams automatically using the previously signed-in account.

We also see the following authentication errors:

0xCAA5001C

Token broker operation failed

Operation: GetTokenSilently

Error: -895352825 (0xcaa20007)

AADSTS70011:

The provided request must include a 'scope' input parameter.

Scope:

openid openid https://api.spaces.skype.com offline_access profile

The scope format is invalid.

We also see:

0xCAA90006

Failed to get token by WS-Trust flow

The older Teams version 26163.405.4842.717 worked correctly in the same environment.

Microsoft Teams | Microsoft Teams for business | Sign up and Sign in | Sign in
0 comments No comments

Answer accepted by question author
Killian N 4,410 Reputation points Independent Advisor
2026-09-25T06:37:04.1833333+00:00

Hi Sattar,

Thank you for taking the time to share the detailed information about your environment, along with the error messages you've captured.

From the details provided, one point that stands out is the duplicated openid value shown in the failed request.

Since this request is generated as part of the Microsoft Teams authentication flow, rather than being a scope that is typically configured manually in Microsoft Entra ID, the duplicate entry is certainly worth investigating further. Additionally, given that the older Teams client continues to work correctly within the same Citrix environment, this may suggest that the issue is related either to the newer Teams client itself or to how it interacts with the existing Citrix UPM profile data.

As an initial isolation step, I would recommend testing with one affected user by creating a new UPM profile, while leaving the existing profile unchanged.

  • If Teams signs in successfully using the new profile, this would indicate that persisted profile data or cached authentication information may be contributing to the issue.
  • On the other hand, if the same error occurs even with a clean profile, it would be reasonable to focus the investigation on the Teams client version or the underlying image-level configuration.

Could you also confirm the exact versions of:

  • Citrix VDA 2203 CU
  • MsTeamsPluginCitrix

This information may be useful because the current guidance for the new Teams VDI solution references VDA 2203 LTSR CU3 or later, Citrix Workspace app 2402, and MsTeamsPluginCitrix 2024.41.1.1.

In addition, before clearing any cached data, I would suggest enabling Extended Logging, reproducing the issue, and then collecting the Teams diagnostic logs using: Ctrl + Alt + Shift + 1

Microsoft generally recommends collecting the logs immediately after the issue occurs to ensure the relevant diagnostic information is captured.

Should the issue continue, the Teams diagnostic logs, together with the Request ID, Correlation ID, UTC timestamp, and the corresponding Entra sign-in logs, would provide valuable insight for further analysis. It may also be beneficial to compare the logs from a working Teams version against those from the affected version, as this could help determine whether a change introduced in the newer client is influencing the authentication flow.

For reference:

I hope this helps point the investigation in the right direction. Please let me know the results of the clean-profile test and the Citrix component versions, and we can review the next steps accordingly.

Kind regards,

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.