Workspace Environment Management

What’s new

What’s new in 2511

Tip:

You can download the latest Workspace Environment Management installer from the Citrix Virtual Apps and Desktops downloads page https://www.citrix.com/downloads/citrix-virtual-apps-and-desktops/. On that page, access the installer under Components of the latest version of Citrix Virtual Apps and Desktops.

This release includes the following new features and addresses issues to improve the user experience:

Support for configuring default registry values

You can now configure data for the (Default) value name under a registry key by leaving the Value name field empty. This enhancement expands the range of configurable registry entries and applies in the following scenarios:

  • Creating or editing Registry entries actions.

  • Creating, editing, or importing Registry-based Group Policy settings actions.

For more information, see Create a registry-based GPO and Add a registry entry.

Reporting for script-based external tasks

You can now view execution result reports for script-based external tasks directly in the WEM web console. This enhancement improves visibility across your environment, helping you track task success or failure more easily. By reducing the need to check logs manually, it streamlines monitoring and supports faster issue resolution.

For more information, see Enable and view reports for script-based external tasks.

Simplified privilege elevation for domain-joined environments

Privilege elevation no longer requires assigning accounts to specific Active Directory groups. Previously, accounts had to be members of groups such as Authenticated Users in the Pre-Windows 2000 Compatible Access group and Enterprise Domain Controllers in the Windows Authorization Access Group. With this enhancement, you can now enable privilege elevation without these group assignments, making security configuration simpler and more flexible.

For more information, see Privilege elevation.

Support for importing AppLocker rules in WEM web console

The WEM web Console now supports importing application security rules in bulk using an AppLocker XML file. Previously, you had to create rules individually through the console, which was repetitive and inefficient in environments with extensive application control needs.

With the new import interface, you can quickly bring in multiple rules from existing AppLocker configurations, streamlining setup, and improving consistency across environments. For more information, see Import AppLocker rules in WEM web console.

Scripted task validation tool

Validating scripts within the WEM using scripted tasks previously required you to follow a complex and time-consuming workflow.

You can now use the new scripted task validation tool to quickly validate WEM scripted tasks without requiring a full deployment. This enhancement simplifies script development by allowing you to test and adjust scripts locally, speeding up troubleshooting, and reducing testing time. By validating scripts before rollout, you can ensure greater reliability, improve efficiency, and minimize the risk of user impact.

For more information, see Validate and export a scripted task.

Agent Insights panel

This release introduces Agent Insights, a new feature in the WEM agent that helps you and your users monitor and troubleshoot session performance, profile container usage, and logon activity. Users can open the panel from the agent icon in the notification area to view detailed metrics that help identify and troubleshoot issues quickly.

The release also includes new settings to control how the panel is displayed and how agent-generated reports are collected and stored.

For more information, see Agent Insights.

New built-in scripted tasks for easier troubleshooting

You can now use new built-in scripted tasks to simplify diagnostics and reduce manual effort. These tasks automate common troubleshooting actions across your Citrix environment, helping you quickly identify and resolve issues.

The following scripted tasks are now available:

  • AOT Log Collection: Automates the collection and processing of AOT logs.
  • Check DNS Settings: Verifies DNS configuration and identifies potential issues.
  • Check RDS License: Verifies RDS licensing configuration and compliance.
  • Diagnose VDA Unregistration: Runs diagnostic checks to identify causes of VDA unregistration.
  • Run Profile Management health check: Examines your Citrix Profile Management configuration and analyzes logs to identify profile-related issues.
  • Set profile reset trigger: Backs up the user’s existing profile to create a clean profile folder on the next logon.

For more information, see Built-in scripted tasks.

Enhanced logon duration diagnostics

You can now view more details for diagnosing logon duration. The metrics User Profile Loading and Group Policy Processing include more sub-metrics and tips that help you identify and resolve issues more effectively. For more information, see Windows Logon Analysis.

Rule Generator for App Access Control supports importing FSLogix Apps rule sets

The Rule Generator for App Access Control tool in WEM Tool Hub now supports importing FSLogix Apps rule sets. This enhancement lets you reuse existing FSLogix configurations to quickly create equivalent App Access Control rules, simplifying migration and ensuring consistent application access rules. For more information, see Rule Generator for App Access Control.

Support for creating filters from templates

You can now create filters using predefined templates. This enhancement simplifies filter creation by prepopulating conditions. For more information, see Create filters from templates.

Currently, three templates are available to help you quickly create filters that identify Citrix Virtual Apps™ environments, Citrix Virtual Desktops environments, and time ranges.

Increased character limit for condition values

When creating a condition for use in assignment filters, you can now enter up to 10,000 characters in the condition values—up from the previous limit of 256 characters. This enhancement applies to all condition types and gives you more flexibility when defining complex conditions. For more information, see Create a condition.

Improved “View reports” button behavior

The View reports button now updates dynamically based on report status. While a report is being generated, the button remains disabled and checks automatically every five seconds for up to 30 seconds. Once the report is ready, the button is enabled. If the report isn’t ready after 30 seconds, the button becomes active again, allowing you to retry. This enhancement helps prevent confusion about when a report is available. For more information, see Agents.

Summary view for agent statistics

  • This enhancement includes a new summary view with four charts displaying statistical results and a rearranged layout, moving the search bar and filter. For more information, see the Summary view

Enhanced analysis of process activities during user .ogon

We’ve introduced an analysis of process activities during user logon in the Windows Logon Analysis to help users identify more logon performance issues. For more information, see Process activity and details.

Improved security for password storage in configurations

We have updated the internal workflow to store passwords contained in configurations, such as network drives and printers, more securely. This change is compatible with version 2005.2.0.1 and newer.

Using older versions before 2005.2.0.1 might result in the following issues:

  • WEM agents older than version 2005.2.0.1 are unable to process configurations containing passwords correctly.
  • When importing configuration sets exported with a console older than version 2005.2.0.1, configurations containing passwords are not imported.
  • When restoring actions or settings backed up with a console older than version 2005.2.0.1, configurations containing passwords are not restored.
  • When migrating from on-premises older than version 2005.2.0.1 to the cloud service, configurations containing passwords are not migrated.

New functionalities in the web console

The new functionalities in the web console are as follows:

  • Save and Assign button: A new Save and Assign button has been added, allowing for continuous action creation.
  • Manage Assignments link: A new Manage Assignments link has been added to the toast notification.
  • Registry Operations column: A Registry Operations column has been added to the data table.

For more information, see Create a GPO and Manage assignments for a GPO.

Enhanced performance of assignment targets and directory objects

Previously, loading the Directory objects and Assignment target pages triggerred numerous translation requests leading to slow load times, especially with large datasets.

With this enhancement, the object names are stored in the database, translating them only when necessary, significantly improving the performance. You can manually refresh individual records to see the updated names. Additionally, Refresh options are added to refresh all or selected records or only usernames. For more information, see Assignment targets and the Note in Add a machine or machine group.

UI enhancements

The WEM UI enhancements are as follows:

  • Agent UI Update: All UI interfaces in the Agent section have been updated to adopt the Windows 11 theme style.

  • Broker UI Update: The UI interfaces of Norskale Broker Service Configuration Utility and Norskale Database Management Utility have also been upgraded to the Windows 11 theme style.

  • System Tray Icon Context Menu: The right-click menu of the Agent UI’s system tray icon has been optimized with a new modern design.

  • Light and Dark Mode Support: All Agent UI elements, including the system tray icon’s context menu, now support Light Mode and Dark Mode. These modes automatically align with the System theme settings.

  • Agent Skin Customization: Starting from version 2502.1.0.1, the ability to change skins through the Console’s Workspace Environment Management > Configuration sets > UI agent personalization feature has been removed for newer agents. Agents from versions before 2502.1.0.1 continue to support skin customization. For more information, see UI Agent Personalization under the web console.

Description column in Security rules tables

A new Description column is now available in the tables on the Application security, Privilege elevation, and Process hierarchy control pages. The column shows the rule descriptions, making it easier to review and understand configured rules.

Filter conditions support folder paths for delivery groups and machine catalogs

You can now use delivery groups and machine catalogs stored in subfolders as filter conditions. When you create or manage filter conditions using Delivery group name or Machine catalog name, you can include items in subfolders by specifying the full path in the name. Example: Subfolder name\Delivery group name, Subfolder name\Machine catalog name

Enhancements to the Agent Statistics page

The Agent Statistics page includes the following improvements:

  • A new MAC address column is available. To display it, select Columns to display, and then select MAC address. You can also use the MAC address as a filter criterion, except for agents that do not have unique MAC addresses and have Use the alternative agent identifier enabled.

  • Three new filter conditions for agent versions: Does not contain, Is earlier than, and Is later than.

What’s new