Local App Access settings
Verified with Citrix Workspace App 26.3.10 — updated on July 10, 2026
Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
Path in the GPO console
User Configuration\Administrative Templates\Citrix Components\Citrix Workspace\User experience Description
Use this policy to control how the client presents local applications inside a hosted desktop. Local App Access enables the integration of locally installed applications within a hosted desktop. When users launch locally installed applications using shortcuts, applications appear to be running on their hosted desktop even though it is running on their local device. When this policy is enabled, client presents locally installed applications inside hosted desktop as shortcuts. When disabled, client doesn't present local apps inside hosted desktop. URL redirection is also disabled. Allow URL Redirection: When this is checked, client allows URLs to be redirected from hosted desktop browser to locally installed browser or vice versa. URL blacklist and whitelist on host determine which URLs would be redirected. Browser add-ons, extensions and plugins required for this feature would also need to enable. When unchecked, URLs are not redirected from hosted desktop to client or vice versa. Browser add-ons, extensions and plugins are not disabled.
Registry
Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control Value name: ClientHostedAppsShortcuts
Enabled: ClientHostedAppsShortcuts = true
Disabled: ClientHostedAppsShortcuts = false
This policy sets several registry values:
ClientHostedApps ClientHostedApps = * ClientHostedApps = false RTWIMode Seamless Windows RTWIMode = * RTWIMode = false Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Local App Access settings
; State: Enabled
; Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
[HKEY_CURRENT_USER\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control]
"ClientHostedAppsShortcuts"="true"
"ClientHostedApps"="*"
"ClientHostedAppsURLEnabled"=dword:00000000
[HKEY_CURRENT_USER\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Seamless Windows]
"RTWIMode"="*" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Local App Access settings
# State: Enabled
# Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClientHostedAppsShortcuts' -Value 'true' -Type String
Set-ItemProperty -Path $path -Name 'ClientHostedApps' -Value '*' -Type String
Set-ItemProperty -Path $path -Name 'ClientHostedAppsURLEnabled' -Value 0 -Type DWord
$path = 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Seamless Windows'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RTWIMode' -Value '*' -Type String Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Local App Access settings
# State: Enabled
# Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control' -Name 'ClientHostedAppsShortcuts' -Expected 'true' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control' -Name 'ClientHostedApps' -Expected '*' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Seamless Windows' -Name 'RTWIMode' -Expected '*' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control' -Name 'ClientHostedAppsURLEnabled' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Local App Access settings
# State: Enabled
# Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClientHostedAppsShortcuts' -Value 'true' -Type String
Set-ItemProperty -Path $path -Name 'ClientHostedApps' -Value '*' -Type String
Set-ItemProperty -Path $path -Name 'ClientHostedAppsURLEnabled' -Value 0 -Type DWord
$path = 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Seamless Windows'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RTWIMode' -Value '*' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Local App Access settings
# State: Enabled
# Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Local App Access settings
# State: Enabled
# Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control' -Name 'ClientHostedAppsShortcuts' -Expected 'true' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control' -Name 'ClientHostedApps' -Expected '*' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Seamless Windows' -Name 'RTWIMode' -Expected '*' -Kind String)
(Test-RegistryValue -Path 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control' -Name 'ClientHostedAppsURLEnabled' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Local App Access settings
# State: Enabled
# Supported on: ADMX Migrator encountered a policy that does not have a supportedOn value.
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.
$path = 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Control'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ClientHostedAppsShortcuts' -Value 'true' -Type String
Set-ItemProperty -Path $path -Name 'ClientHostedApps' -Value '*' -Type String
Set-ItemProperty -Path $path -Name 'ClientHostedAppsURLEnabled' -Value 0 -Type DWord
$path = 'HKCU:\Software\Policies\Citrix\ICA Client\Engine\Lockdown Profiles\All Regions\Lockdown\Virtual Channels\Seamless Windows'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'RTWIMode' -Value '*' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.