Menu
Skip to main content
Table of Contents
<All topics
Print

Appterix Enrollment of YubiKeys in RDP and Citrix Sessions

Problem Description

When setting up (enrolling) YubiKeys via the Appterix Agent in RDP or Citrix sessions, limitations or missing functions may occur.

IMPORTANT NOTE:
The cause of this behavior is explicitly not due to the Appterix software. The limitations are technical and result from the general compatibility and hardware handling of YubiKeys by RDP and Citrix protocols.
Since direct "low-level" access to the USB hardware (the YubiKey) is not possible in a Citrix or RDP environment, device control is severely limited. This behavior can be reproduced exactly using Yubico's proprietary tools.

By default, RDP and Citrix use a so-called "high-level smartcard redirection" (based on the PC/SC interface). Only the logical The smartcard is passed through to the session, but not the physical USB hardware. However, for more advanced configurations (such as setting up certificates or FIDO PINs), management tools require direct access to the YubiKey (via CCID, FIDO, or HID interfaces). This low-level access is blocked by the default forwarding.

Requirements for enrollment in Citrix and RDP

Generally, starting an enrollment in an RDP/Citrix session works if the user logs in with a user account managed in Appterix.

– If the enrollment is not displayed at all, it may not be the correct or managed user.

Local users are treated separately by Appterix and receive the prefix "ex-" in their SID during administration. This can be verified in the Appterix Agent by clicking on the user icon in the upper right corner.

Supported and unsupported features in RDP / Citrix

Due to the lack of low-level hardware connectivity, enrollment via RDP and Citrix is ​​limited to pure PIV (Personal Identity Verification) functions.

Supported enrollment steps (smartcard function usable):

– PIV reset

– Certificate-based authentication

PIV relies on the standardized Windows smartcard service, which RDP and Citrix natively support and reliably forward. Writing to NFC modules or modifying proprietary USB interfaces (such as Yubico OTP) requires manufacturer-specific commands that the PC/SC channel simply cannot transmit.

Note: The Appterix agent recognizes these limitations and indicates to the user if an enrollment includes actions that cannot be performed in the current RDP session.

Driver problems under Windows

Sometimes the problems also lie with the driver information within Citrix and RDP. For example, a known problem arises when Windows uses the incorrect USBCCID driver (WUDF) instead of the correct UMDF2 driver.
The Windows User-Mode Driver Framework (UMDF) version 2 provides the necessary stability for modern smart card operations. If Windows falls back to older WUDF drivers, remote sessions often experience timeouts, or the YubiKey may not be recognized as a smart card at all. Administrators should ensure that the latest "Microsoft Usbccid Smartcard Reader" driver (based on UMDF2) is installed.

Solutions and workarounds

Native Windows clients use (Recommended method)

Most customers circumvent these protocol-related limitations by performing the enrollment steps on a native (local) Windows client. This can be done directly in the Appterix Agent with the relevant user or conveniently via the "On Behalf Of" function.

Adjust Citrix Redirection and Device Splitting

Although the dependencies under Citrix are not due to Appterix, there are ways to improve support for setting up YubiKeys in Citrix environments. Yubico has documented methods to circumvent Citrix and Windows-side limitations through specific adjustments (such as device splitting).

Further details on configuring the Citrix environment can be found in the following official Yubico support article:
https://support.yubico.com/s/article/Citrix-redirection-FIDO-over-USB