Delivery Controller 1909 and Licensing

Last Modified: Sep 22, 2019 @ 10:14 am

Navigation

💡 = Recently Updated

Change Log

Upgrade

If you are performing a new install of Delivery Controller, then skip to the next section.

Starting in August 2018:

  • XenApp and XenDesktop is renamed to Citrix Virtual Apps and Desktops (CVAD)
  • Versioning changed to YYMM format.
    • Version 1808 is newer than 7.18

You can in-place upgrade directly from any Delivery Controller version 7.0 or newer. Citrix recommends upgrading Delivery Controller 5.6 to 7.6 LTSR Cumulative Update 6 before upgrading to 1909 or 1906.

During the upgrade of Delivery Controller, be aware that a database upgrade is required. Either get a DBA to grant you temporary sysadmin permission, or use Citrix Studio to generate SQL scripts that a DBA must then run in SQL Studio.

  1. NVIDIA – ensure your NVIDIA Virtual GPU software supports the version of CVAD that you are upgrading to.
  2. Consider Utilizing Local Host Cache for Nondisruptive Database Upgrades at Citrix Docs.
  3. License Server Upgrade – Before upgrading to Delivery Controller 1909, if you have a standalone Citrix Licensing Server, upgrade it to 11.16.3.0 Build 28000. The Delivery Controllers will be non-functional until you upgrade the License Server.

    • You can run LicServVerify.exe from the Citrix Virtual Apps and Desktops (CVAD) ISO to verify that the License Server is compatible. Example syntax is: "E:\x64\XenDesktop Setup\LicServVerify.exe" -h myLicenseServer -p 27000 -v

  4. Frequent updates/upgrades– Citrix Virtual Apps and Desktops (CVAD) 1909 and CVAD 1906 are Current Releases.
    • With Current Release (CR), you’re expected to upgrade to the future version 1912 to receive bug fixes. Newer Current Releases come with new features, which might include new bugs. Current Releases are only supported for six months from the release date. That means you should plan to perform these upgrades at least twice a year.
    • If you don’t want to continuously upgrade to the latest Current Release, then you can stay on LTSR 7.15, which receives Cumulative Updates with bug fixes, but no new features. See Lifecycle Milestones for Citrix Virtual Apps & Citrix Virtual Apps and Desktops.
  5. Delivery Controller OS Compatibility – 1909 and 1906 Delivery Controller are supported on Windows Server 2019, Windows Server 2016, and Windows Server 2012 R2.
    • Windows Server 2008 R2 is no longer supported.
  6. VDA OS Compatibility – Virtual Delivery Agent (VDA) 1909 and VDA 1906 are only supported on a limited number of Windows operating system versions, specifically, Windows 10 (1607+), Windows Server 2012 R2, Windows Server 2016, and Windows Server 2019.
    • If you have older VDA machines running Windows 7 or Windows Server 2008 R2, you can leave their VDA software at version 7.15 (with latest Cumulative Update). Citrix supports VDA 7.15 to communicate with Delivery Controllers 1909 and 1906.
  7. SCOM Agent – If StoreFront is installed on the Controller, and if the Citrix SCOM Agent for StoreFront is installed, stop the Citrix MPSF Agent service. See CTX220935 Cannot Perform a StoreFront Upgrade if Citrix SCOM Management Pack Agent Service is Running.
  8. Close PowerShell and Consoles. Make sure all Citrix Consoles and PowerShell consoles are closed. StoreFront won’t upgrade if any are running. If StoreFront fails, then the StoreFront configuration is wiped out and you’ll have to revert to snapshot.
  9. Other Users – Use Task Manager > Users tab to logoff any other user currently logged into the machine.
  10. Snapshot. If StoreFront is installed on the Controller, take a snapshot before attempting the upgrade.
  11. Download the Citrix Virtual Apps and Desktops 7 1909 ISO.
  12. Run AutoSelect.exe from the 1909 or 1906.2 ISO.

  13. On the top left, click Studio and Server Components.
  14. In the Licensing Agreement page, select I have read, understand, and accept the terms, and click Next.
  15. In the Ensure Successful Upgrade page, read the steps, check the box next to I’m ready to continue, and click Next.
  16. If you see a License Errors page, then you need to upgrade your License Server.
  17. In the Preliminary Site Tests page, click Start Preliminary Tests.
  18. The tests will take a few minutes. Click Next when done.
  19. In the Firewall page, click Next.
  20. In the Summary page, click Upgrade.
  21. If you see a Running Processes window, close the listed programs, and click Continue.
  22. Click OK when asked to start the upgrade.
  23. The machine will probably reboot a couple times.

    1. After the reboot, and after logging in again, you might see a Locate ‘Citrix Virtual Apps and Desktops 7’ installation media window. Don’t click anything yet.
    2. Go to the Citrix_Virtual_Apps_and_Desktops_7_1909.iso file and mount it.
    3. Go back to the Locate ‘Citrix Virtual Apps and Desktops 7’ installation media window.
    4. On the left, expand This PC, and click the DVD Drive.
    5. Click Select Folder.
    6. Installation will resume. Repeat these instructions after each reboot.
  24. If the upgrade fails:
    1. Look for MetaInstaller log files under %localappdata%\Temp\Citrix\XenDesktop Installer\MSI Log Files.
    2. Look for StoreFront log files under C:\Program Files\Citrix\Receiver StoreFront\Admin\logs.
    3. Citrix has a MSI Log Analyzer.
  25. In the Diagnostics page, you can optionally enable Collect diagnostic information (aka Call Home). If so, click Connect and login with a Citrix Cloud account. See Citrix Insight Services at Citrix Docs for more information on this feature.
  26. Then click Next.
  27. In the Finish page, check the box next to Launch Studio, and click Finish.

Studio – Upgrade Database, Catalogs, and Delivery Groups

  1. After Citrix Studio launches, if you have sysadmin permissions on SQL, then click Start the automatic Site upgrade. If you don’t have full SQL permission, then get a DBA to help you, click Manually upgrade this site, and follow the instructions.

    • If you choose to Manually upgrade this site, then note that there might not be an upgrade for the Logging Database schema, depending on what version you are upgrading from.

  2. After all Controllers and VDAs are upgraded, in Citrix Studio, view your Catalog for the current functional level (Set to VDA version). Citrix Virtual Apps and Desktops (CVAD) 1909 and CVAD 1906 lets you upgrade your Catalogs and Delivery Groups to functional level 1811.

    1. Don’t upgrade the Catalog or Delivery Group until all VDAs with the Catalog and Delivery Group are VDA version 1811 or newer.
    2. Right-click the Catalog, and click Upgrade Catalog.
      Note: you might not see the Upgrade Catalog option until you reboot the Delivery Controller.

    3. Review the message regarding suitability of the upgrade and then click Upgrade.
    4. Then upgrade the Delivery Groups by right-clicking on a Delivery Group and clicking Upgrade Delivery Group.
    5. Review the suitability message and then click Upgrade.

Other Citrix Virtual Apps and Desktops components can also be in-place upgraded:

New Install Preparation

Frequent updates/upgrades

Citrix Virtual Apps and Desktops (CVAD) 1909 and 1906 are Current Releases.

  • With Current Release (CR), you’re expected to upgrade to the future 1912 to receive bug fixes. Current Releases also come with new features, which might include new bugs. Current Releases are only supported for six months from the release date. That means you should plan to perform these upgrades at least twice a year.
  • If you don’t want to continuously upgrade to the latest Current Release, then you can stay on LTSR 7.15, which receives Cumulative Updates with bug fixes, but no new features. See Lifecycle Milestones for Citrix Virtual Apps & Citrix Virtual Apps and Desktops.

OS Compatibility

Delivery Controller 1909 and Delivery Controller 1906 are supported on Windows 2012 R2 and newer, including Windows Server 2019. Windows Server 2008 R2 is no longer supported.

Virtual Delivery Agent (VDA) 1909 and VDA 1906 are only supported on a limited number of Windows operating system versions, specifically, Windows 10 (1607+), Windows Server 2012 R2, Windows Server 2016, and Windows Server 2019.

  • If you have older VDA machines running Windows 7 or Windows Server 2008 R2, you can install VDA software version 7.15. Citrix supports VDA 7.15 communicating with Delivery Controllers 1909 and 1906.

Installation Automation

If you want to automate the install of Delivery Controllers, see Dennis Span Citrix Delivery Controller unattended installation with PowerShell and SCCM.

Citrix Licensing

If you are going to use an existing Citrix Licensing Server, then upgrade it to 11.16.3.0 build 28000.

  • You can run LicServVerify.exe from the Citrix Virtual Apps and Desktops (CVAD) ISO to verify that the License Server is compatible. Example syntax is: "E:\x64\XenDesktop Setup\LicServVerify.exe" -h myLicenseServer -p 27000 -v

Multiple License Types – Multiple license types (but not multiple editions) are supported in a single farm. See CTX223926 How to Configure Multiple License Types within a Single XenApp and XenDesktop Site.

SQL Databases for Citrix Virtual Apps and Desktops

  • Citrix CTX209080 Database Sizing Tool for XenDesktop 7
  • Citrix article CTX114501 – Supported Databases for XenApp and XenDesktop Components
  • Three databases – There are typically three databases: one for the Site (aka farm), one for Logging (audit log) and one for Monitoring (Director).
    • The name of the monitoring database must not have any spaces in it. See CTX200325 Database Naming Limitation when Citrix Director Accesses Monitoring Data Using OData APIs
    • If you want Citrix Studio to create the SQL databases automatically, then the person running Studio must be a sysadmin on the SQL instances. No lesser SQL role will work. sysadmin permissions can be granted temporarily and revoked after installation.
    • As an alternative, you can use Citrix Studio to create SQL scripts, and then run those scripts on the SQL server. In that case, the person running the scripts only needs the dbcreator and securityadmin roles.
      • CVAD 1909 and newer supports using PowerShell to generate separate SQL scripts for sysadmin vs db_owner. See Preferred database rights scripts at Citrix Docs. 💡
    • It is possible to create the three databases in advance. However, you must use the non-default Latin1_General_100_CI_AS_KS collation.
  • SQL High Availability Options:
    • Basic Availability Groups – Build two SQL 2016 (or newer) Standard Edition servers, and create three Basic Availability Groups, one for each database. Each Basic Availability Group has its own Listener.
    • Database Mirroring – Build two SQL 2014 or older Standard Edition servers, and configure Database Mirroring.
    • AlwaysOn Availability Group – Build two SQL Enterprise Edition servers, and create one AlwaysOn Availability Group with one Listener.
    • Failover Clustering – Build two SQL Enterprise Edition servers, and configure SQL Database Failover Clustering.
  • Cloud – Azure SQL and AWS RDS are not supported. You’ll need to build your own SQL Servers on IaaS VMs.

Windows Feature

Installing Group Policy Management (GPMC) on the Delivery Controllers lets you edit Citrix-targeted Group Policy Objects (GPOs) directly from the Delivery Controllers.

Citrix has a Citrix Group Policy Management Plug-in that adds the Citrix Policies node to the Group Policy Editor. The Citrix Group Policy Management Plug-in is included with the installation of Citrix Studio, meaning that running GPMC on the Delivery Controller automatically grants you access to the Citrix Policies node in the GPOs. If you edit GPOs on a machine that doesn’t have Citrix Studio installed, then you won’t see the Citrix Policies node in GPOs until you manually install the Citrix Group Policy Management Plug-in.

vCenter Service Account

Create a role in vSphere Client. Assign a service account to the role at the vCenter Datacenter or higher level. Delivery Controller will use this service account to login to vCenter.

Delivery Controller New Install

  1. A typical size for the Controller VMs is 2-4 vCPU and 8+ GB of RAM. If all components (Delivery Controller, StoreFront, Licensing, Director, SQL Express) are installed on one server, then you might want to bump up memory to 10 GB or 12 GB. 5 GB is the minimum memory.
  2. From Local Host Cache sizing and scaling at Citrix Docs:
    1. For LHC LocalDB, assign the Controller VMs a single socket with multiple cores.
    2. Add two cores for LHC.
    3. Add at least three more Gigs of RAM and watch the memory consumption.
    4. Since there’s no control over LHC election, ensure all Controllers have the same specs.
    5. SQL LocalDB uses max four cores on one socket. Configure the Delivery Controller VM with four cores per socket.
  3. Operating System: Citrix Virtual Apps and Desktops (CVAD) 1909 and CVAD 1906 are supported on Windows Server 2019, Windows Server 2016, and Windows Server 2012 R2.
  4. Make sure the User Right Log on as a service includes NT SERVICE\ALL SERVICES, or add NT SERVICE\CitrixTelemetryService to the User Right.
  5. Download the Citrix Virtual Apps and Desktops 7 1909 ISO.
  6. On two Delivery Controllers, to install the Delivery Controller software, run AutoSelect.exe from the mounted 1909 ISO.

  7. Click Start next to either Virtual Apps or Virtual Apps and Desktops. The only difference is the product name displayed in the installation wizard.
  8. On the top left, click Delivery Controller.
  9. In the Licensing Agreement page, select I have read, understand, and accept the terms, and click Next.
  10. In the Core Components page, you can install all components on one server, or on separate servers. Splitting out the components is only necessary in large environments, or if you have multiple farms and want to share the Licensing, StoreFront, and Director components across those farms. Click Next.
  11. In the Features page, uncheck the box next to Install Microsoft SQL Server 2014 SP2 Express, and click Next.
  12. In the Firewall page, click Next.
  13. In the Summary page, click Install.
  14. The machine will probably reboot a couple times.

    1. After the reboot, and after logging in again, you might see a Locate ‘Citrix Virtual Apps and Desktops 7’ installation media window. Don’t click anything yet.
    2. Go to the Citrix_Virtual_Apps_and_Desktops_7_1909.iso file and mount it.
    3. Go back to the Locate ‘Citrix Virtual Apps and Desktops 7’ installation media window.
    4. On the left, expand This PC, and click the DVD Drive.
    5. Click Select Folder.
    6. Installation will resume. Repeat these instructions after each reboot.
  15. In the Smart Tools page, make a selection. If you choose Smart Tools and Call Home, then click Connect, and enter your Citrix Cloud or MyCitrix.com credentials. Click Next.
  16. In the Finish page, click Finish. Citrix Studio will automatically launch.
  17. Ensure the two Delivery Controller VMs do not run on the same hypervisor host. Create an anti-affinity rule at vSphere Cluster > Manage > Settings > DRS Rules > Add. Set the Type to Separate Virtual Machines.
  18. Citrix Tech Zone Endpoint Security and Antivirus Best Practices: provides guidelines for configuring antivirus software in Citrix Virtual Apps and Desktops environments

Create Site – Create Database

There are several methods of creating the databases for Citrix Virtual Apps and Desktops (CVAD):

  • If you have sysadmin permissions to SQL, let Citrix Studio create the databases automatically.
  • If you don’t have sysadmin permissions to SQL, then use Citrix Studio to generate SQL scripts, and send the scripts to a DBA.

Use Citrix Studio to Create the Databases Automatically

  1. Launch Citrix Studio. After it loads, click Deliver applications and desktops to your users.
  2. In the Introduction page, select An empty, unconfigured site. This reduces the number of pages in this Setup wizard. The removed pages will be configured later.
  3. Enter a Site Name (aka farm name), and click Next. Only administrators see the farm name.
  4. In the Databases page, if you are building two Delivery Controllers, click Select near the bottom of the same page.

    1. Click Add.
    2. Enter the FQDN of the second Delivery Controller, and click OK. Note: the Delivery Controller software must already be installed on that second machine.
    3. Then click Save.
  5. If the person running Citrix Studio has sysadmin permissions to the SQL Server, then enter the SQL server name/instance in the three Location fields, and click Next.
  6. If you don’t have sysadmin permission, then jump to the SQL Scripts section below.
  7. On the Licensing page, enter the name of the Citrix License Server, and click Connect. If you installed Licensing with your Delivery Controller, then simply enter localhost.
  8. If the Certificate Authentication appears, select Connect me, and click Confirm.
  9. Select your license type, and click Next. If you see both User/Device and Concurrent, then you usually must select User/Device licenses. Also see CTX223926 How to Configure Multiple License Types within a Single XenApp and XenDesktop Site.
  10. In the Summary page, if your databases are mirrored or in an Availability Group, each database will show high availability servers, and the name of the Mirror server. Click Finish.

  11. It will take some time for the site to be created.
  12. Once done, skip to the Second Delivery Controller section.

Use Citrix Studio to create SQL scripts

  1. If you don’t have SQL sysadmin permissions, then change the selection to Generate scripts to manually set up databases on the database server. Change the database names if desired, and click Next.
  2. In the Summary page, click Generate scripts.
  3. A folder will open with six scripts. Edit each of the scripts.
  4. Near the top of each script are two lines to create the database. Uncomment both lines (including the go line). Then save and close the file.

  5. Once all of the scripts are edited, you can send them to your DBA.
    1. On the Principal SQL Server, open the file Site_Principal.sql.

    2. Open the Query menu, and click SQLCMD Mode to enable it.
    3. Then execute the script.
    4. If SQLCMD mode was enabled properly, then the output should look something like this:
    5. If you have a mirrored database, run the second script on the mirror SQL instance. Make sure SQLCMD mode is enabled.
    6. Repeat for the Logging_Principal.sql script.
    7. You’ll have to enable SQLCMD Mode for each script you open.


    8. Repeat for the Monitoring_Principal.sql script.
    9. Once again enable SQLCMD Mode.


    10. The person running Citrix Studio must be added to the SQL Server as a SQL Login, and granted the public server role, so that account can enumerate the databases.

  6. Back in Citrix Studio, click the Continue database configuration and Site setup button.
  7. In the Databases page, enter the SQL server name, and instance name, and click Next.

  8. On the Licensing page, enter the name of the Citrix License Server, and click Connect. If you installed Citrix Licensing with your Delivery Controller, then simply enter localhost.
  9. If the Certificate Authentication window appears, select Connect me, and click Confirm.
  10. Then select your license, and click Next. See CTX223926 How to Configure Multiple License Types within a Single XenApp and XenDesktop Site.
  11. In the Summary page, if your databases are mirrored, each database will show high availability servers, and the name of the Mirror server. Click Finish.

  12. It will take some time for the site to be created.

Second Controller

During Site creation, you might have selected more than one Delivery Controller. In that case, simply run Citrix Studio on the already configured additional Delivery Controllers. If Citrix Studio is already open, close it and reopen it to see the farm configuration.

Otherwise, additional Delivery Controllers need to be added to the SQL databases.

  • If you have sysadmin permissions to SQL, let Citrix Studio modify the databases automatically.
  • If you don’t have sysadmin permissions to SQL then use Citrix Studio to generate SQL scripts and send them to a DBA.

To use Citrix Studio to create the SQL Scripts:

  1. On the first Delivery Controller, if StoreFront is installed on the Controller, then delete the default StoreFront store (/Citrix/Store), and recreate it with your desired Store name (e.g. /Citrix/CompanyStore).
  2. On the second Delivery Controller machine, install Delivery Controller as detailed earlier.
  3. After installation, launch Citrix Studio on the second controller, and click Connect this Delivery Controller to an existing Site.
  4. Enter the name of the first Delivery Controller, and click OK.
  5. If you don’t have full SQL permissions (sysadmin), click No when asked if you want to update the database automatically.
  6. Click Generate scripts.
  7. A folder will open with six scripts. If not mirroring, then the top three scripts need to be sent to a DBA. If mirroring, send all six.
  8. On the SQL Server, open one of the .sql files.

  9. Open the Query menu, and click SQLCMD Mode.
  10. Then execute the SQL script.
  11. If SQLCMD mode was enabled properly, then the output should look something like this:
  12. Repeat for the remaining script files.
  13. Back in Citrix Studio, click OK.
  14. In Citrix Studio, under Configuration > Controllers, you should see both controllers.

SSL for Delivery Controller

SSL certificates should be installed on each Delivery Controller to encrypt the traffic between StoreFront and Delivery Controller. The traffic between StoreFront and Delivery Controller contains user credentials.

The SSL certificate on each Delivery Controller needs to match the FQDN of the Delivery Controller.

  • If StoreFront is installed on the Delivery Controller, then you have two FQDNs to consider: the Delivery Controller FQDN, and the StoreFront FQDN. Make sure the certificate matches the Delivery Controller FQDN, but it’s usually not necessary for the same certificate to also match the StoreFront FQDN.
    • The StoreFront certificate is usually hosted on a Citrix ADC SSL Load Balancing Virtual Server. Users connect to Citrix ADC instead of directly to the StoreFront servers. The StoreFront certificate only needs to be valid between the user and the ADC.
    • For the connection between ADC and StoreFront server, ADC does not validate the certificate so the certificate on the StoreFront server can be anything. That means you can install a certificate that matches the Delivery Controller FQDN, but there’s no need for the certificate to match the StoreFront FQDN.

To enable SSL for a Delivery Controller:

  1. Run certlm.msc, go to Personal > Certificates, and create or install a server certificate that matches the Delivery Controller’s FQDN. This can be an internally-signed certificate if the StoreFront server trusts internally-signed certificates.
  2. If IIS is installed on the Delivery Controller, then simply run IIS Manager, go to Default Web Site, click Edit Bindings, and add an https binding using the chosen certificate.

If IIS is not installed on the Delivery Controller, then we need to build a command line to bind the certificate to Citrix Broker Service.

  1. Open a command prompt as administrator.
  2. Enter the following text but don’t press Enter yet.
    netsh http add sslcert ipport=0.0.0.0:443 certhash=
  3. Right after certhash= paste the certificate thumbprint using the following procedure:
    1. Go to certlm.mscPersonal Certificates.
    2. Double-click the certificate you want to bind.
    3. On the Details tab, scroll down to Thumbprint and copy the thumbprint.
    4. Paste the thumbprint into the command line we’re building.
    5. Remove the special character at the beginning of the thumbprint.
    6. Remove the spaces.
  4. Add the following to the command line:
     appid=
  5. Michael Shuster at HowTo: Enable SSL on Citrix Delivery Controllers – Easy Method says you can run the following PowerShell to get the Broker Service GUID.
    Get-WmiObject -Class Win32_Product | Select-String -Pattern "broker service"
  6. Paste the GUID for Citrix Broker Service that you got from the Get-WmiObject. Make sure the GUID has curly braces on both sides with no space between appid and the left curly brace.
  7. Press <Enter> to run the command.
  8. If you entered everything correctly, then it should say SSL Certificate successfully added.
  9. To confirm the certificate binding, run the following:
    netsh http show sslcert ipport=0.0.0.0:443

Studio – Slow Launch

From B.J.M. Groenhout at Citrix Discussions: The following adjustments can be made if Desktop Studio (and other Citrix management Consoles) will start slowly:

  • Within Internet Explorer, go to Tools – Internet Options – Tab Advanced – Section Security, and uncheck the option Check for publisher’s certificate revocation

After adjustment Desktop Studio (MMC) will be started immediately. Without adjustment it may take some time before Desktop Studio (MMC) is started.

Registry setting (can be deployed using Group Policy Preferences):

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing
    • State“=dword:00023e00

Concurrent Logon Hard Limit

From Samuel Legrand XenApp 7.14 – (Really) Manage a DR! – Citrix Policies has a setting called Concurrent Logon Tolerance. However, it is not a hard limit, meaning once the limits are reached, it continues to let users connect. You can configure the Controllers to make it a hard limit by setting the following registry value:

  • HKLM\Software\Policies\Citrix\DesktopServer
    • LogonToleranceIsHardLimit (DWORD) = 1

Local Host Cache

If you have 10,000 or fewer VDAs per zone (up to 40,000 VDAs per multi-zone site/farm), you can enable Local Host Cache (LHC) instead of Connection Leasing. LHC allows new sessions to be started even if SQL database is unavailable.

From Local Host Cache sizing and scaling at Citrix Docs:

  1. For LHC LocalDB, assign the Controller VMs a single socket with multiple cores.
  2. Add two cores for LHC.
  3. Add at least three more Gigs of RAM and watch the memory consumption.
  4. Since there’s no control over LHC election, ensure all Controllers have the same specs.
  5. The Docs article has scripts for monitoring LHC performance.

From XenApp 7.12, LHC and a reboot at Citrix Discussions:

  • If the rebooted DDC is the elected one, a different DDC will take over (causing registration storm) and when the DDC gets back, it will take over brokering causing second registration storm. Site will sort itself out and all will work.
  • If the rebooted DDC is not the elected one, it will not impact any functionality.
  • If you turn the DDC down when site is working, and start it during outage, LHC will not trigger on that machine. This DDC will not impact the LHC unless it would become the elected one. In that scenario it will take control, however not start LHC and resources would not be available.

Trentent Tye at Citrix XenDesktop/XenApp 7.15 – The local host cache in action has a video showing LHC in action.

As mentioned by Citrix Docs, make sure PowerShell Execution Policy is set to RemoteSigned, Unrestricted, or Bypass.

If you did a fresh install of 1909 or 1906, then Local Host Cache should be enabled by default. You can run Get-BrokerSite to confirm. (run asnp citrix.* first).

If not enabled, you can run some PowerShell commands to enable Local Host Cache:

asnp citrix.*
Set-BrokerSite -ConnectionLeasingEnabled $false
Set-BrokerSite -LocalHostCacheEnabled $true

George Spiers Local Host Cache XenApp & XenDesktop shows the Event Log entries when LHC is enabled.

Database Maintenance

Enable Read-Committed Snapshot

The Delivery Controller Database can become heavily utilized under load in a large environment. Therefore Citrix recommends enabling the Read_Committed_Snapshot option on the Delivery Controller databases to remove contention on the database from read queries. This can improve the interactivity of Studio and Director. It should be noted that this option may increase the load on the tempdb files. See Citrix article CTX137161 How to Enable Read-Committed Snapshot in XenDesktop for configuration instructions.

Change Database Connection Strings

Sometimes the database connection strings need to be modified:

  • When moving the SQL databases to a different SQL server
  • For AlwaysOn Availability Groups, to add MultiSubnetFailover to the SQL connection strings
  • For SQL mirroring, to add Failover Partner to the SQL connection strings

Here are general instructions for moving the database and assigning the correct permissions:

  1. Backup the three Citrix databases on the original SQL server, and restore them on the new SQL server. See Microsoft’s documentation for details.
  2. In SQL Management Studio > Security > Logins, add the Delivery Controller computer accounts (e.g. CORP\DDC01$)
  3. When adding the SQL Login, on the User Mapping page, select the three Citrix databases (Site database, Monitoring database, and Logging database)
  4. For each of the three Citrix databases, add the Delivery Controller computer account to the various database roles as listed below. The Site database has many more roles than the Logging and Monitoring databases.
    • Site database – ADIdentitySchema_ROLE
    • Site database – Analytics_ROLE (7.8 and newer)
    • Site database – AppLibrarySchema_ROLE (7.8 and newer)
    • Site database – chr_Broker
    • Site database – chr_Controller
    • Site database – ConfigLoggingSchema_ROLE
    • Site database – ConfigLoggingSiteSchema_ROLE
    • Site database – ConfigurationSchema_ROLE
    • Site database – DAS_ROLE
    • Site database – DesktopUpdateManagerSchema_ROLE
    • Site database – EnvTestServiceSchema_ROLE
    • Site database – HostingUnitServiceSchema_ROLE
    • Site database – Monitor_ROLE
    • Site database – MonitorData_ROLE
    • Site database – OrchestrationSchema_ROLE (7.11 and newer)
    • Site database – public
    • Site database – StorefrontSchema_ROLE (7.8 and newer)
    • Site database – TrustSchema_ROLE (7.11 and newer)
    • Monitoring database – Monitor_ROLE
    • Monitoring database – public
    • Logging database – ConfigLoggingSchema_ROLE
    • Logging database – public

From Citrix Docs Update database connection strings when using SQL Server high availability solutions: Citrix offers several PowerShell scripts that update Delivery Controller database connection strings when you are using SQL Server high availability database solutions such as AlwaysOn and mirroring. The scripts, which use the Citrix Virtual Apps and Desktops PowerShell API, are:

  • DBConnectionStringFuncs.ps1: The core script that does the actual work. This script contains common functions that the other scripts use.
  • Change_XD_Failover_Partner_v1.ps1: Updates (adds, changes, or removes) the failover partner. This script prompts for the failover partner location (FQDN) for each database. (Providing a blank failover partner removes the failover partner. You can also use the ClearPartner option to remove a partner.) Do not set the failover partner to the same location as the principal database server.
  • Change_XD_To_ConnectionString.ps1: Uses the provided connection strings to update the connection strings to the databases. This script ensures that certain Citrix services are up and running, and then updates those services in the correct order on all Controllers in the site. Enclose connection string information for each database in quotes.
  • Change_XD_To_MultiSubnetFailover.ps1: Toggles the addition and removal of MultiSubnetFailover=true. If you use AlwaysOn Availability Groups, Microsoft recommends that the connection string include MultiSubnetFailover=true. This option speeds up recovery when a high availability event occurs, and is recommended for both single and multi-subnet environments. Run this script once to add the option. Run the script again to remove it.
  • Change_XD_To_Null.ps1: Resets all the connection strings on the localhost because something has gone wrong. By resetting the connection strings to null, this script places the Controller into an “initial” state. If you run Studio after running this script, you’ll be asked if you want to create a site or join an existing site. This is useful if something has gone wrong and a reset is needed. After the reset, you can try again to set the connection strings.

Here are the DB Connections that must be changed. Make sure you include all of the DB Connections shown below. You can get the full list of database commands by running Get-Command Set-*DBConnection. When changing the DB connections, AdminDBConnection must be the last to be set to NULL, and the first to be configured with the new connection string.

Remove the existing Database connections

At the Delivery Controller, open PowerShell as Administrator and run the following commands to clear the existing database connections.

## Load the Citrix snap-ins
asnp Citrix.*

## Disable configuration logging for the XD site:
Set-LogSite -State Disabled

## ## Clear the current Delivery Controller database connections
## Note: AdminDBConnection must be the last command
Set-ConfigDBConnection -DBConnection $null
Set-AppLibDBConnection –DBConnection $null    #7.8 and newer
Set-OrchDBConnection –DBConnection $null      #7.11 and newer
Set-TrustDBConnection –DBConnection $null     #7.11 and newer
Set-AcctDBConnection -DBConnection $null
Set-AnalyticsDBConnection -DBConnection $null # 7.6 and newer
Set-HypDBConnection -DBConnection $null
Set-ProvDBConnection -DBConnection $null
Set-BrokerDBConnection -DBConnection $null
Set-EnvTestDBConnection -DBConnection $null
Set-SfDBConnection -DBConnection $null
Set-MonitorDBConnection -DataStore Monitor -DBConnection $null   #Monitoring Database
Set-MonitorDBConnection -DBConnection $null                      #Site Database
Set-LogDBConnection -DataStore Logging -DBConnection $null       #Logging Database
Set-LogDBConnection -DBConnection $null                          #Site Database
Set-AdminDBConnection -DBConnection $null -force

Specify the new Database connection strings

Run the following commands to set the new connection strings. Adjust the variables to match your desired connection string. For example, if you wish to add “;MultiSubnetFailover=True” to the connection strings, then set the $csSite variable to "Server=$ServerName;Initial Catalog=$SiteDBName;Integrated Security=True;MultiSubnetFailover=True". Repeat this for the $csLogging and $csMonitoring variables.

## Replace <dbserver> with the SQL server name, and instance if present, e.g "ServerName\SQLInstanceName". If no SQL Instance name is mentioned, this commandlet will try to connect to the default SQL instance.
## Replace <dbname> with the name of your restored Database
## Note: AdminDBConnection should be first

$ServerName = "<dbserver>"
$SiteDBName = "<SiteDbName>"
$LogDBName = "<LoggingDbName>"
$MonitorDBName = "<MonitorDbName>"
$csSite = "Server=$ServerName;Initial Catalog=$SiteDBName;Integrated Security=True;MultiSubnetFailover=True"
$csLogging = "Server=$ServerName;Initial Catalog=$LogDBName;Integrated Security=True;MultiSubnetFailover=True"
$csMonitoring = "Server=$ServerName;Initial Catalog=$MonitorDBName;Integrated Security=True;MultiSubnetFailover=True"

Set-AdminDBConnection -DBConnection $csSite
Set-ConfigDBConnection -DBConnection $csSite
Set-AcctDBConnection -DBConnection $csSite
Set-AnalyticsDBConnection -DBConnection $csSite # 7.6 and newer
Set-HypDBConnection -DBConnection $csSite 
Set-ProvDBConnection -DBConnection $csSite
Set-AppLibDBConnection –DBConnection $csSite # 7.8 and newer
Set-OrchDBConnection –DBConnection $csSite # 7.11 and newer
Set-TrustDBConnection –DBConnection $csSite # 7.11 and newer
Set-BrokerDBConnection -DBConnection $csSite
Set-EnvTestDBConnection -DBConnection $csSite
Set-SfDBConnection -DBConnection $csSite
Set-LogDBConnection -DBConnection $csSite
Set-LogDBConnection -DataStore Logging -DBConnection $null
Set-LogDBConnection -DBConnection $null
Set-LogDBConnection -DBConnection $csSite
Set-LogDBConnection -DataStore Logging -DBConnection $csLogging
Set-MonitorDBConnection -DBConnection $csSite
Set-MonitorDBConnection -DataStore Monitor -DBConnection $null
Set-MonitorDBConnection -DBConnection $null
Set-MonitorDBConnection -DBConnection $csSite
Set-MonitorDBConnection -DataStore Monitor -DBConnection $csMonitoring
Set-LogSite -State Enabled

Test the new Database connection strings

Run the following commands to verify connectivity to the database:

asnp citrix.*

## Copy these variables from the previous step
## If you haven’t closed your PowerShell window, then the variables might still be defined. In that case, just run the Test commands
$ServerName = "<dbserver>"
$SiteDBName = "<SiteDbName>"
$LogDBName = "<LoggingDbName>"
$MonitorDBName = "<MonitorDbName>"
$csSite = "Server=$ServerName;Initial Catalog=$SiteDBName;Integrated Security=True"
$csLogging = "Server=$ServerName;Initial Catalog=$LogDBName;Integrated Security=True"
$csMonitoring = "Server=$ServerName;Initial Catalog=$MonitorDBName;Integrated Security=True"

Test-AcctDBConnection -DBConnection $csSite
Test-AdminDBConnection -DBConnection $csSite
Test-AnalyticsDBConnection -DBConnection $csSite # 7.6 and newer
Test-AppLibDBConnection -DBConnection $csSite # 7.8 and newer
Test-BrokerDBConnection -DBConnection $csSite
Test-ConfigDBConnection -DBConnection $csSite
Test-EnvTestDBConnection -DBConnection $csSite
Test-HypDBConnection -DBConnection $csSite
Test-LogDBConnection -DBConnection $csSite
Test-LogDBConnection -DataStore Logging -DBConnection $csLogging
Test-MonitorDBConnection -DBConnection $csSite
Test-MonitorDBConnection -Datastore Monitor -DBConnection $csMonitoring
Test-OrchDBConnection -DBConnection $csSite # 7.11 and newer
Test-ProvDBConnection -DBConnection $csSite
Test-SfDBConnection -DBConnection $csSite
Test-TrustDBConnection -DBConnection $csSite # 7.11 and newer

Director Grooming

If your Citrix Virtual Apps and Desktops is not Premium Edition, then all historical Director data is groomed at 30 days.

For Citrix Virtual Apps and Desktops Premium Edition, by default, most of the historical Director data is groomed at 90 days. This can be adjusted up to 367 days by running a PowerShell cmdlet.

  1. On a Delivery Controller, run PowerShell elevated (as administrator), and run asnp Citrix.*
  2. Run Get-MonitorConfiguration to see the current grooming settings.
  3. Run Set-MonitorConfiguration to change the grooming settings.

View Logging Database

To view the contents of the Logging Database, in Studio, click the Logging node. On the right is Create Custom Report. See Citrix article CTX138132 Viewing Configuration Logging Data Not Shown for more info.

The Logging Database can be queried using Get-LogLowLevelOperation. See Stefan Beckmann Get user who set maintenance mode for a server or client for an example script that uses this PowerShell cmdlet.

Logging Database Grooming

By default, the Logging Database does not groom old entries. You can enable grooming in Citrix PowerShell by running the Set-LogSite cmdlet with the -LoggingDBPurgeDurationDays parameter. More info at Schedule periodic data deletion at Citrix Docs. 💡

Citrix CTX215069 Troubleshooting and managing Oversized Configuration Logging database: The article’s queries can be used to determine the number of configuration operation types performed by Citrix Virtual Apps and Desktops Administrator, and to analyze the content of the Configuration Logging database when it is considered oversized. A grooming query is also provided to delete data older than a specified date.

Export/Import Configuration

Ryan Butler has a PowerShell script that can export configuration from one Citrix Virtual Apps and Desktops farm and import it to another.

Kaspars Vilde at XenDesktop/XenApp 7.X Applications – Exporting / Importing at Citrix Discussions has scripts to export published apps from one farm and import to another farm.

Studio Administrators

Full Administrators

  1. In the Studio, under Configuration, click the Administrators node. The first time you access the node you’ll see a Welcome page. Feel free to check the box to Don’t show this again, and then click Close.
  2. On the Administrators tab, right-click, and click Create Administrator.
  3. In the Administrator and Scope page, Browse to a group (e.g. Citrix Admins) that will have permissions to Citrix Studio and Director. These groups typically have access to all objects, so select the All scope. Alternatively, you can create a Scope to limit the objects. Click Next.
  4. On the Role page, select a role, and then click Next. For example:
    • Full Administrator for the Citrix Admins group
    • Help Desk Administrator for the Help Desk group
    • Machine Catalog Administrator for the desktop team
  5. In the Summary page, click Finish.

Help Desk

  1. In Citrix Studio, under Configuration, click the Administrators node. On the Administrators tab, right-click, and click Create Administrator.
  2. In the Administrator and Scope page, Browse to a Help Desk group that will have permissions to Citrix Studio and Director. Select the All scope. And click Next.
  3. On the Role page, select the Help Desk Administrator role, and then click Next.
  4. In the Summary page, click Finish.
  5. When administrators in the Help Desk role log into Director, all they see is this.

    To jazz it up a little, add the Help Desk group to the read-only role.
  6. Right-click the Help Desk Administrator, and click Edit Administrator.
  7. Click Add.
  8. In the Scope page, select a scope, and click Next.
  9. In the Role page, select Read Only Administrator, and click Next.
  10. In the Summary page, click Finish.
  11. Then click OK. Now Director will display the dashboard.

Customer Experience Improvement Program

Citrix Virtual Apps and Desktops enables CEIP by default. If desired, you can disable it in Citrix Studio:

  1. On the left, go to the Configuration node.
  2. On the right, switch to the Product Support tab.
  3. Click End.
  4. Click Yes.

Citrix Studio collects data for Google Analytics. You can disable this in the registry at HKLM\Software\Citrix\DesktopStudio\GAEnabled = 0.

Each Citrix Virtual Apps and Desktops component has a separate configuration for disabling Customer Experience Improvement Program:

vCenter Connection

Citrix Virtual Apps and Desktops uses an Active Directory service account to log into VMware vCenter. This service account needs specific permissions in vCenter. To facilitate assigning these permissions, create a new vCenter role and assign it to the service account. The permissions should be applied at the vCenter datacenter or higher level.

Import vCenter Root Certificate

If the vCenter certificate is valid and trusted, then you can skip to the Hosting Resource section.

For newer versions of vCenter, you can import the root certificate that signed the vCenter Server/Appliance certificate.

  1. Point your browser to the root path of the vCenter Server URL.
  2. On the bottom right, click Download trusted root CA certificates.
  3. Extract the downloaded files.
  4. Go to \certs\win.
  5. Sort the files by date, and double-click the newest .crt file.
  6. On the General tab, click Install Certificate.
  7. In the Welcome to the Certificate Import Wizard page, change the Store Location selection to Local Machine, and click Next.
  8. In the Certificate Store page, click Browse.
  9. Select Trust Root Certification Authorities, and click OK.
  10. In the Completing the Certificate Import Wizard page, click Finish.
  11. If you close your browser and reopen it, and then go to the vCenter URL, there should no longer be any certificate errors.
  12. Skip to the Hosting Resource section.

Import vCenter Certificate

If the vCenter certificate is valid and trusted, then you can skip to the Hosting Resource section.

Alternatively, you can import the actual vCenter Server certificate (instead of the root). This is the only option for older self-signed vCenter certificates.

Newer versions of Citrix Virtual Apps and Desktops have the ability to import the vCenter certificate thumbprint into the database so every Delivery Controller trusts it. However, it is difficult to update the thumbprint whenever the vCenter certificate changes. It might instead be more reliable to use the older method of configuring the Trusted People store on the Delivery Controllers. Whenever the vCenter certificate is changed, you’ll need to repeat these steps.

  1. Get the vCenter certificate.
    1. Open a browser and point it to the vCenter URL. Note: this procedure to get the certificate won’t work in Internet Explorer.
    2. If Google Chrome, click the Secure box in the address bar, and then click Certificate.
    3. On the Details tab, click Copy to File.
    4. In the Welcome to the Certificate Export Wizard page, click Next.
    5. In the Export File Format page, either format will work. Click Next.
    6. In the File to Export page, browse to a new file, and click Next.
    7. In the Completing the Certificate Export Wizard page, click Finish.
  2. On the Delivery Controller, run certlm.msc. This opens the MMC console with the Certificates snap-in already added and pointing to Local computer.
  3. On the left, right-click the Trusted People node, expand All Tasks, and click Import.
  4. In the Welcome to the Certificate Import Wizard page, click Next.
  5. In the File to Import page, browse to the certificate you saved earlier, and click Next.
  6. In the Certificate Store page, click Next.
  7. In the Completing the Certificate Import Wizard page, click Finish.
  8. Click OK to acknowledge that the import was successful.
  9. Repeat these steps on the second Delivery Controller. It is important that you import the certificate on all Delivery Controllers before you add the Hosting Resource in Citrix Studio.
  10. If you open a browser and point o the vCenter Server, there should be no certificate errors.

Hosting Resources

A Hosting Resource = vCenter + Cluster (Resource Pool) + Storage + Network. When you create a machine catalog, you select a previously defined Hosting Resource, and the Cluster, Storage, and Network defined in the Hosting Resource object are automatically selected. If you need some VDA machines on a different Cluster+Storage+Network, then you’ll need to define more Hosting Resources in Studio.

  1. In Citrix Studio, expand Configuration and click Hosting. Right-click Hosting, and click Add Connection and Resources.
  2. In the Connection page, for Connection type, select VMware vSphere.
  3. Notice there’s a Learn about user permissions blue link to an article that describes the necessary permissions.
  4. Enter https://vcenter01.corp.local/sdk as the vCenter URL. The URL must contain the FQDN of the vCenter server.
  5. Enter credentials of a service account that can log into vCenter.
  6. In the Connection name field, give the connection a name. Typically, this matches the name of the vCenter server.
  7. If you are not using Machine Creation Services, and instead only need the vCenter connection for machine power management, change the Create virtual machines using selection to Other Tools.
  8. If you intend to use MCS, leave Create virtual machines using set to Studio Tools.
  9. Click Next.

  10. In the Storage Management page, click Browse, and select a vSphere cluster.
    • Note: as detailed at CTX223662, make sure there’s no comma in the datacenter name.
  11. Select Use storage shared by hypervisors.
  12. Beware of Optimize temporary data on available local storage. From Mark Syms at XA 7.9 MCS with RAM Caching at Citrix Discussions: “If you use just MCS caching to local storage then the VM is not agile at all and cannot be moved even when powered off as it has a virtual disk permanently associated with a single host.”
  13. Click Next.
  14. In the Storage Selection page, OS and Personal vDisk must be selected on at least one datastore.
    • For maximum virtual machine placement flexibility, only select one datastore per Hosting Resource. To select additional datastores, run this wizard again to create a separate Hosting Resource for each datastore.
    • When creating a Machine Catalog, you select a Hosting Resource. If the Hosting Resource only has one datastore selected, then you know which datastore the new VMs will be placed on. However, if the Hosting Resource has multiple datastores, then the datastores are selected round robin, and you don’t have any control over which datastore is selected for each new machine.
  15. If you selected the temporary data on local storage option, on the bottom, click Select, and choose the datastores you want to use for disk caching. By default, all local datastores are selected. Click Next when done.
  16. In the Network page, enter a name for the Hosting Resource. Since each Hosting Resource is a combination of vCenter, Cluster, Network, and Datastores, include those names in this field (e.g. vCenter01-Cluster01-Network01-Datastore01).
  17. Select a network and click Next.
  18. In the Summary page, click Finish.
  19. If you need to rename Storage, Network, or Datacenters in vCenter, see Citrix CTX225019 XA/XD 7.13: Renaming Storage, Network or Datacenters When Used With MCS or PVS. Either run Update-HypHypervisorConnection -LiteralPath "XDHyp:\Connections\MyConnection", or right-click the Hosting Resource and click Edit Storage. You can cancel the wizard.

If you have multiple datastores for your VDAs:

  1. Run the Add Connection and Resources wizard again.
  2. You can use the existing vCenter connection.
  3. This time, select a different datastore. Remember, don’t select more than one datastore per Hosting Resource.
  4. Give the Hosting Resource a name that indicates the chosen datastore.

When you later create a Machine Catalog:

  1. Select the Hosting Resource for the datastore where you want the VDAs to be placed.
  2. You can create multiple Machine Catalogs, with each of them on different datastores. You can then combine the Catalogs into a single Delivery Group.
  3. Later in the Catalog wizard, you’re given an option to enable caching and select a cache size. This is similar to Provisioning Services option “Cache in RAM with overflow to disk”. Note: MCS’s version of memory caching seems to cause performance problems.

Citrix Licensing Server

Citrix Virtual Apps and Desktops 1909 comes with Citrix Licensing Server 11.16.3.0 build 28000.

New Licensing Server

If you’re building a new standalone Citrix License Server:

  1. Extract the downloaded Citrix Licensing 11.16.3.0 build 28000, and run CitrixLicensing.exe.

  2. In the Software License Agreement page, check the box next to I have read, understand, and accept the terms, and click Next.
  3. In the Install Location page, click Next.
  4. In the Configure Ports page, click Next.
  5. In the Configure Customer Success Services Renewal page, click Install.
  6. In the Summary page, click Finish.

Upgrade Licensing Server

If you have a standalone Licensing Server, upgrade it to Citrix Licensing 11.16.3.0 build 28000, if it isn’t already.

  1. Go to the downloaded Citrix Licensing 11.16.3.0 build 28000, and run CitrixLicensing.exe.

  2. If you see the Subscription Advantage Renewal page, make a selection, and click Next.
  3. In the Upgrade page, click Upgrade.
  4. Click Finish.
  5. If you go to Programs and Features, it should now show version 11.16.3.0 build 28000.
  6. If you login to the Citrix License Administration Console (:8082)…
  7. the Administration tab…
  8. It shows the version as 11.16.3.0 build 28000.
  9. After upgrading Citrix Licensing Server, in Citrix Studio, go to Configuration > Licensing.
  10. On the right, click Authenticate Certificate.
  11. Change the selection to Connect me, and click Confirm.

Citrix Licensing Manager

Newer versions of License Server come with a new management web site. Citrix seems to be slowly moving all License Server functionality to this new web site.

  1. From the Start Menu, run Citrix Licensing Manager. Or go to https://<My_Licensing_Server>:8083
  2. You might be prompted to login.

    • To eliminate this login, add the License Server URL to the Local Intranet zone.
  3. Build 27000 and newer might prompt you to register with Citrix Cloud.

    1. On the Settings > Usage and Statistics page, in the Share usage statistics with Citrix section, click Register.
    2. You’ll see a screen with a registration code. Click the Copy button and then click Register to be take to Citrix Cloud.
    3. After logging in to Citrix Cloud, on the top left, click the menu (hamburger) icon and then click License & Usage. If you don’t see this link, you might have to logout and log back in.
    4. In the License & Usage service, switch to the Registrations tab.
    5. Click the blue Register button in the middle of the page.
    6. Paste in the copied code and then click Continue.
    7. Click Register.
    8. Back in the on-premises Licensing Manager, it will eventually show as Registered.
    9. On the same Usage & Statistics page, scroll down, and then click Upload now. This should cause data to upload to Citrix Cloud and show up in Citrix Cloud License & Usage.
  4. Build 27000 has a new Dashboard page to replace the one in License Administration Console.

    1. Click the arrow next to a license to see when it expires and the number of licenses in use.
  5. If you click the gear icon on the top right…
  6. On the Account tab, you can add License Server Administrators.
  7. The Update Licenses tab lets you check for license renewals and download them.

Activate Citrix License

The easy way to install and activate a Citrix license is through Citrix Studio:

  1. In Citrix Studio, expand Configuration, right-click Licensing, and click Allocate Licenses.
  2. Enter the LA- license code, and click Show.
    • You can find your LA- code at http://mycitrix.com, click All Licensing Tools, and click View Licenses.
  3. Then click the Allocate licenses button.

    • Another method of allocating licenses is in the Citrix Licensing Manager at https://MyLicenseServer:8083 > Install Licenses tab.
  4. After licenses are installed, right-click the Licensing node, and click Edit Product Edition
  5. Change the edition to match your licenses. If you see both Virtual Apps and Virtual Desktops licenses, you must select Virtual Desktops. If you see both Concurrent and User/Device, then you must select User/Device. Click OK when done.
  6. Citrix Virtual Apps and Desktops supports mixed licensing in a single site/farm. See the following:

License Server CEIP

Citrix Licensing Server enables CEIP by default. This can be disabled in the Citrix Licensing Manager (https://MyLicenseServer:8083) by clicking the gear icon.

Switch to the Usage and Statistics tab, and make a selection in the Share usage statistics with Citrix section.

Citrix License Management Service

Citrix Licensing Server includes the Citrix License Management Service. This service helps you avoid prohibited practices:

  • Duplication of licenses outside a Disaster Recovery (DR) environment
  • Use of legacy licenses for new product versions
  • Use of rescinded licenses

Citrix Licensing Server Monitoring

Citrix Licensing Server has historical usage reporting:

  1. Run Citrix Licensing Manager from the Start Menu. Or use a browser to connect to https://MyLicenseServer:8083
  2. On the Historical Use tab, use the drop-down menus to select a license type, select dates, and export to a .csv file.
  3. At the bottom of this page is a link to change the retention period.

Jonathan Medd Monitor Citrix License Usage With PowerShell.

Lal Mohan – Citrix License Usage Monitoring Using Powershell

Jaroslaw Sobel – Monitoring Citrix Licenses usage – Graphs using WMI, Powershell and RRDtool. This script generates a graph similar to the following:

Remote Desktop Licensing Server

Install Remote Desktop Licensing Server

Do the following on your Delivery Controllers:

  1. In Server Manager, open the Manage menu, and click Add Roles and Features.
  2. In the Installation Type page, select Role-based or feature-based installation.
  3. Click Next until you get to the Server Roles page. Check the box next to Remote Desktop Services, and click Next.
  4. Click Next until you get to the Role Services page. Check the box next to Remote Desktop Licensing, and click Next.
  5. Click Add Features if prompted.
  6. Then finish the wizard to install the role service.

Activate Remote Desktop Licensing

  1. After RD Licensing is installed, in Server Manager, open the Tool menu, expand Terminal Services (or Remote Desktop Services), and click Remote Desktop Licensing Manager.
  2. The tool should find the local server. If it does not, right-click All servers, click Connect, and type in the name of the local server.
  3. Once the local server can be seen in the list, right-click the server and click Activate Server.
  4. In the Welcome to the Activate Server Wizard page, click Next.
  5. In the Connection Method page, click Next.
  6. In the Company Information page, enter the required information, and click Next.
  7. All of the fields on the Company Information page are optional, so you do not have to enter anything. Click Next.
  8. In the Completing the Activate Server Wizard page, uncheck the box next to Start Install Licenses Wizard now, and click Finish. Since the session hosts will be configured to pull Per User licenses, there is no need to install licenses on the RD Licensing Server.
  9. In RD Licensing Manager, right-click the server, and click Review Configuration.
  10. Ensure you have green check marks. If the person installing Remote Desktop Licensing does not have permissions to add the server to the Terminal Server License Servers group in Active Directory, ask a domain admin to do it manually. If you have the proper permissions, click Add to Group.
  11. Click Continue when prompted that you must have Domain Admins privileges.
  12. Click OK when prompted that the computer account has been added.
  13. Click OK to close the window.

Citrix Scout

Delivery Controller includes Citrix Scout that can be launched from the Start Menu.

The tool can run a manual collection, run a trace, schedule periodic collection, or run a Health Check.

Health Check:

  1. When you select machines, it might tell you to enable PSRemoting.
  2. Winrm is usually not enabled on desktop machines. Login to the machine, open command prompt as administrator, and run winrm quickconfig. It’s also possible to use Group Policy to enable winrm.
  3. Scout 1909 and newer lets you add a StoreFront machine. 💡
  4. Go back to Citrix Scout and click Continue.
  5. Click Start Checking.
  6. You can click View Details to view the issues it found.

Collect:

  1. The wizard is identical to the Health Check wizard, except there’s another screen to upload the data.

  2. If Citrix Cloud credentials, then you need to Generate a token.
  3. After logging into Citrix Cloud, copy the token.
  4. Go back to Citrix Scout and paste the token. Click Continue.
  5. Click Start Upload.
  6. Click View Analysis.

Links with more information:

Citrix Virtual Apps and Desktops Health Check

Sacha Tomet Finally 1.0 – but never finalized!: XenApp & XenDesktop 7.x Health Check script has now Version 1.0.

Pavan900 posted a PowerShell-based Health Check script at Citrix Studi – Colors for Maintenance Mode at Citrix Discussions.

Andrew Morgan – New Free Tool: Citrix Director Notification Service: The Citrix Director Notification service sits on an edge server as a service (or local to the delivery controller) and periodically checks the health of:

  • Citrix Licensing.
  • Database Connections.
  • Broker Service.
  • Core Services.
  • Hypervisor Connections.

And if any of these items fall out of bounds, an SMTP alert is sent to the mailbox of your choice for action. The tool will also send “All Clear” emails when these items are resolved, ensuring you are aware when the service has resumed a healthy state.

Matt Bodholdt XenDesktop 7.x Controller Service Status Script at CUGC – PowerShell script that checks the following:

  • Lists Controllers with boot time
  • Licensing status
  • Service status on each Controller
  • DB Connections
  • Controller Available Memory
  • Hypervisor Connections Status

Related Pages

32 thoughts on “Delivery Controller 1909 and Licensing”

  1. Hi,
    Looking for an up to date How-to for Citrix Virtual XenDesktop full installation, and your blogs seems to be the most up to date site, but i can’t understand the flow of how to follow your directions, as you can read i am newby, but found a simple old blog, its not up-to-date nor have any new stuff (WEM, FSLogix, O365, etc..), but it’s very easy to follow:

    https://carlwebster.com/citrix-xendesktop-7-6-provisioning-services-7-6-xendesktop-setup-wizard-write-cache-personal-vdisk-drives/

    A few other people also seem to like the style of how this tutorial is written.

    Do you have any how-to like this or how can i copy and paste your blog to see this type steps needed to do full deploy of 1909 with WEM 1909, FSLogix, O365, Gateway 1909?

    Please & Thanks.

  2. Hello Carl. https://www.carlstalhood.com/delivery-controller-cr-and-licensing/#ssl in the certificate location the name may change across versions. Registry key might exist that shows “Citrix Broker Service” and a document such as https://support.citrix.com/article/CTX130213 would work. But if a newer product is installed or patched it might need a different key that shows something like “Broker_Service_x64”, ran into this with 7.15 CU4 install, different GUID.

  3. Hi Carl
    Is there a way to secure the SDK? i see that brokerService uses por 80 for SDK, (brokerservice.exe /show)
    my company’s ciso does not approve openning port 80 through FW, and require ssl,

    is that possible?
    thanks
    itamar

  4. Hi Carl,

    Hope your doing well!!

    This is regarding Sacha Tomet health check script may be it is not related to you. I have implemented the health checks Script in our current environment and everything working fine except license server details. In my case I am using Enterprise license and the license server is currently located on another server. I am looking for modification to pull out the license server report if license server hosted on separate servers.

    Thanks you in Advanced.

    1. Hello Ahmed, that’s possible, but need that according ports to the license server are open. See the PowerShell code and try to query the license directly from the server where the script is running on it. If that works, also the script will work.

      1. Thanks Sacha for your kind support… I wanted to know do I need to specify license server host name in script if license server hosted on other server?

        1. No, just be sure in the config file enable it on line 119 and choose the correct license mode on line 126.

          if you want to troubleshoot see line 836, the command you can use to test starts with Get-WmiObject …

  5. Has anyone seen slowness in Studio 1903? We upgraded from 7.15 LTSR and have seen consistent slowness in our NP and Pre-Prod environments. Citrix workaround is to install previous version of studio.

  6. We are trying to upgrade to 1808. All components done except the controllers. It failed on the pre-requisites (IIS Features).

    Add-WindowsFeature : The request to add or remove features on the specified server failed.
    Installation of one of more roles, role services,or features failed. Error: 0x800f0831

      1. It turned out to be an issue with Windows Updates that had not installed correctly. This was resolved and the installation went smoothly.

  7. Carl,

    I have setup mirroring on the 3 databases, site, logging, monitoring. (this was on a site already in use, not fresh)
    I ran the powershell scripts to update all connection strings and doing various checks in powershell shows all have the failover setting in their strings now.

    In Studio, on configuration I see the server and mirror addresses for all three fine.

    However, if i failover the logging db to the secondary server to test, it stops logging.
    In studio if i check the logging preferences, it only lists the primary server location.

    Should that have both entries (does it support that?) or will I need to manually update this to the 2nd sql server to fail this over? Same for monitoring/site?

    I can not seem to find anything on this online or in citrix docs.

    Thanks

    1. Did you use “Set-LogDBConnection -DataStore Logging -DBConnection $mySQLString” to set the string? The key is “-datastore logging”.

      Logging service connects to the Site database. From there, it gets the string for the Logging database and connects to that. In other words, Logging has two strings.

      1. I had run the citrix power shell ones, Change_XD_Failover_Partner_v1.ps1, not manually.
        Maybe I should have to run Change_XD_To_ConnectionString.ps1 as well or do it manually for each.

        I thought I had checked all the various get-logdbconnection, etc and they all have the failover but maybe I missed something like the one you mentioned above. All registry entries seem to have the correct strings as well.

        Will try that thanks

  8. Hi Carl,

    I need to move the databases to a new standard SQL server. In your Database Maintenance Section I understand I need to run Change_XD_To_ConnectionString.ps1. That script will clear the connections to the old database and set the connections to the new string supplied correct? So where you show the steps to Remove the existing Database connections and Specify the new Database connection strings – that is just for reference?

  9. The part about RDS licensing got me confused. You say not to install licenses on the licensing server since the hosts will be configured to pull licenses. But how can they pull a license if no licenses are available since none are installed? Also, obviously as a I see it, RD Licensing Diagnoser on a RD Host says there are no licenses available on the specified licensing server.

    1. In “Per User” mode, since there’s no enforcement, it’s not necessary to install licenses, but you certainly can if you want to track them. Of course you are required to own them. The lack of licenses on the server should not stop connections.

  10. Hi Carl,

    I am working on a Citrix Cloud POC. Citrix cloud tenant has been set and our server VDAs are in AWS. I have created new test VPC for this POC and kept master image under this POC.

    I am unable to create MCS catalog using MCS service as it is throwing below error message. However, I can use other services and make the Xenapp 2016 session host server work without any issues.

    I have all neccessary permissions given to the IAM role, still no luck Any ideas?

    Error Id: XDDS:067EDB65

    Exception:
        Citrix.Orchestration.Base.LogicModels.Exceptions.ProvisioningTaskException An error occurred while preparing the image.
           at Citrix.Orchestration.Base.PowerShellSdk.ProvisioningSchemeService.BackgroundTasks.ProvisioningSchemeTask.ThrowOnTerminatingError(SdkProvisioningSchemeAction sdkProvisioningSchemeAction)
           at Citrix.Orchestration.Base.PowerShellSdk.ProvisioningSchemeService.BackgroundTasks.ProvisioningSchemeTask.WaitForProvisioningSchemeActionCompletion(Guid taskId, Action`1 actionResultsObtained)
           at Citrix.Orchestration.Base.PowerShellSdk.ProvisioningSchemeService.BackgroundTasks.ProvisioningSchemeCreationTask.StartProvisioningAction()
           at Citrix.Orchestration.Base.PowerShellSdk.ProvisioningSchemeService.BackgroundTasks.ProvisioningSchemeCreationTask.RunTask()
           at Citrix.Orchestration.Base.PowerShellSdk.BackgroundTaskService.BackgroundTask.Task.Run()
        
        DesktopStudio_ErrorId : ProvisioningTaskError
        ErrorCategory : NotSpecified
        ErrorID : FailedToCreateImagePreparationVm
        TaskErrorInformation : Terminated
        InternalErrorMessage : Value (ami-028237498284723) for parameter volumes is invalid. Expected: ‘vol-…’.
        DesktopStudio_PowerShellHistory : Create Machine Catalog ‘CitrixXA’
        3/6/2019 12:37:48 PM
        
        Get-LogSite  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ********
        Start-LogHighLevelOperation  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ******** -Source “Studio” -StartTime “3/6/2019 12:36:36 PM” -Text “Create Machine Catalog `’CitrixXA`'”
        New-BrokerCatalog  -AdminAddress “p26686-2-1.prodcp9.local:80” -AllocationType “Random” -BearerToken ******** -IsRemotePC $False -LoggingId “361d33e1-4910-43a9-9ea3-c2c1ef7aca7c” -MinimumFunctionalLevel “L7_6” -Name “CitrixXA” -PersistUserChanges “Discard” -ProvisioningType “MCS” -Scope @() -SessionSupport “MultiSession” -ZoneUid “348c6f84-605d-4498-8632-cd45894ecaf4”
        New-AcctIdentityPool  -AdminAddress “p26686-2-1.prodcp9.local:80” -AllowUnicode -BearerToken ******** -Domain “TESTPOC.COM” -IdentityPoolName “CitrixXA” -LoggingId “361d33e1-4910-43a9-9ea3-c2c1ef7aca7c” -NamingScheme “TESTPOCXA##” -NamingSchemeType “Numeric” -Scope @() -ZoneUid “348c6f84-605d-4498-8632-cd45894ecaf4”
        Set-BrokerCatalogMetadata  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ******** -CatalogId 16 -LoggingId “361d33e1-4910-43a9-9ea3-c2c1ef7aca7c” -Name “Citrix_DesktopStudio_IdentityPoolUid” -Value “95249e31-4339-4604-85aa-38d90e3075ad”
        Test-ProvSchemeNameAvailable  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ******** -ProvisioningSchemeName @(“CitrixXA”)
        New-ProvScheme  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ******** -CleanOnBoot -CustomProperties “” -HostingUnitName “test vpc” -IdentityPoolName “CitrixXA” -InitialBatchSizeHint 2 -LoggingId “361d33e1-4910-43a9-9ea3-c2c1ef7aca7c” -MasterImageVM “XDHyp:\HostingUnits\testvpc\CitrixCloudPOCBase (ami-02ae67095842aed64).template” -NetworkMapping @{“0″=”XDHyp:\HostingUnits\poc vpc\\us-east-1b.availabilityzone\173.x.x.x“/24 (vpc-0de1bca62e3f93448).network”} -ProvisioningSchemeName “CitrixXA” -RunAsynchronously -Scope @() -SecurityGroup @(“XDHyp:\HostingUnits\test vpc\default.securitygroup”,”XDHyp:\HostingUnits\test vpc\test POC.securitygroup”,”XDHyp:\HostingUnits\test vpc\CitrixCloudConnector.securitygroup”) -ServiceOffering “XDHyp:\HostingUnits\poc vpc\M1 Large Instance.serviceoffering”
        Remove-ProvTask  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ******** -LoggingId “361d33e1-4910-43a9-9ea3-c2c1ef7aca7c” -TaskId “b1beba4d-279e-492e-92ef-b38f4c4b4dee”
        Stop-LogHighLevelOperation  -AdminAddress “p26686-2-1.prodcp9.local:80” -BearerToken ******** -EndTime “3/6/2019 12:37:48 PM” -HighLevelOperationId “361d33e1-4910-43a9-9ea3-c2c1ef7aca7c” -IsSuccessful $False
       ************************************************************************************
      N.B: I am getting below message I test resource host connection.(3 Successful tests)

    Check for connection maintenance mode.

    Check that the hypervisor for the connection is not in maintenance mode.
    Test run on entire Site
     Host 3/6/2019 1:00:56 PM Successful 
    Check the hypervisor connection.

    Check that a connection to the hypervisor can be established.
    Test run on controllers: p26686-2-1.prodcp9.local
     Host 3/6/2019 1:00:58 PM Successful 
    Check hypervisor specific connection details

    Check the details of the hypervisor connection and run tests specific to the target hypervisor.
    Test run on controllers: p26686-2-1.prodcp9.local
     Host 3/6/2019 1:00:58 PM Successful 
    **************************************************************************************

    Below error message appears when I test network connection (3 fail tests)

    Check the hypervisor storage.

    Run the hypervisor-specific storage tests on storage locations defined in the hosting unit.
    Test run on controllers: p26686-2-1.prodcp9.local

    Controller p26686-2-1.prodcp9.local: Object reference not set to an instance of an object. 
    An unexpected error occurred.
     Host 3/6/2019 1:02:17 PM Failed 
    Check the hypervisor infrastructure.

    Run the hypervisor-specific infrastructure tests for the hosting unit.
    Test run on controllers: p26686-2-1.prodcp9.local

    Controller p26686-2-1.prodcp9.local: Object reference not set to an instance of an object. 
    An unexpected error occurred.
     Host 3/6/2019 1:02:17 PM Failed 
    Check the hypervisor networks.

    Run the hypervisor-specific network tests on the networks defined in the hosting unit.
    Test run on controllers: p26686-2-1.prodcp9.local

    Controller p26686-2-1.prodcp9.local: Object reference not set to an instance of an object. 
    An unexpected error occurred.
     Host 3/6/2019 1:02:17 PM Failed 
    Check for connection maintenance mode.

    Check that the hypervisor for the connection is not in maintenance mode.
    Test run on entire Site

    Test requires an object of type ‘HypervisorConnection’ but no object of that type was found because no root object was provided for discovery 

      3/6/2019 1:02:17 PM Not run 
    Check the hypervisor connection.

    Check that a connection to the hypervisor can be established.
    Test run on controllers: p26686-2-1.prodcp9.local

    Controller p26686-2-1.prodcp9.local: Test requires an object of type ‘HypervisorConnection’ but no object of that type was found because no root object was provided for discovery 

      3/6/2019 1:02:17 PM Not run 
    Check hypervisor specific connection details

    Check the details of the hypervisor connection and run tests specific to the target hypervisor.
    Test run on controllers: p26686-2-1.prodcp9.local

    Controller p26686-2-1.prodcp9.local: Test requires an object of type ‘HypervisorConnection’ but no object of that type was found because no root object was provided for discovery 

      3/6/2019 1:02:17 PM Not run 

    1. Hi Googletry,

      We’re experiencing the same issue when creating a machine catalog on AWS. Running the 1903 build.

      Were you able to find a solution to this issue?

Leave a Reply