Citrix Virtual Apps and Desktops

Virtual channel allow list policy settings

The Virtual channel allow list policy setting enables the use of an allow list that specifies which virtual channels are allowed to be opened in an ICA session.

When disabled, all virtual channels are allowed.

When enabled, only Citrix virtual channels are allowed.

To use custom or third-party virtual channels, add the virtual channels to the list. To add a virtual channel to the list:

  1. Enter the virtual channel name followed by a comma.
  2. Enter the path to the process that accesses the virtual channel.

More executable paths can be listed, and the paths are separated by commas.

For example,

CTXCVC1,C:\VC1\vchost.exe

CTXCVC2,C:\VC2\vchost.exe,C:\Program Files\Third Party\vcaccess.exe

Starting with Citrix Virtual Apps and Desktops 7 2109, virtual channel allow lists are enabled by default. For more information on adding virtual channels to the allow list, see Adding virtual channels to the allow list

If you’re using the HDX RealTime Optimization Pack for Skype for Business, add the virtual channel to the allow list. For more information, see the HDX RealTime Optimization Pack documentation.

Important:

The VDA machines must be rebooted for the setting to take effect.

For more information about virtual channels, see ICA virtual channels.

Virtual channel allow list logging

You can use this policy setting to configure the level for Virtual Channel Allow List logging.

The following options are available:

Options Description
Disabled Disables all log events.
Log warnings only Events are logged only for custom Virtual Channels that try to open and that are not part of the allow list.
Log all events All events are logged

Virtual channel allow list log throttling

You can use this policy setting to configure the frequency for logging events for an active session.

All events for each virtual channel will be logged on their first occurrence. Repeated events will be suppressed for the duration of the throttling period while the session is active. If a session is disconnected, the throttling period is reset.

Virtual channel allow list policy settings