en-US citrix user

OAuth Redirection

Verified with Citrix Workspace App 26.3.10 — updated on July 10, 2026

Supported on: All Citrix Workspace supported platforms

Path in the GPO console

User Configuration\Administrative Templates\Citrix Components\Citrix Workspace\User experience

Description

OAuth Redirection allows configuring URL patterns to allow OAuth logins to be redirected over Bidirectional Content Redirection. -OAuth Pattern : This indicates the list of URL regular expressions that, when redirected to the client via Host-to-Client URL redirection, will be tracked as if an OAuth authentication flow has begun, and when the flow completes that resulting URL will be redirected back into the Host VDA that initiated that flow.. Semi Colon ";" acts as a delimeter. -OAuth Scheme : This indicates the scheme of URLs .If a Scheme is specified, the terminating URL is expected to be of the form: scheme://something. If Scheme is not specified (empty), then the original resulting URL pattern is extracted from the Pattern via a regular expression capture group (must be specified in the Pattern). Semi Colon ";" acts as a delimeter. Note: 1)Number of Patterns and scheme entries should match .If no scheme is specified for pattern just porvide ';' for empty scheme 2)OAuth Redirection works only if BidirectionalContentRedirection is enabled

Registry

HKCU Software\Policies\Citrix\ICA Client\OAuth Redirection

Value name: AllowOAuthRedirection

Enabled: AllowOAuthRedirection = 1

Disabled: AllowOAuthRedirection = 0

This policy sets several registry values:

URL Protocol citrix-oauth-redir
Enabled: URL Protocol =

More options available

Options

Pattern:
Pattern text
Scheme:
Scheme text

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: OAuth Redirection
; State: Enabled
; Supported on: All Citrix Workspace supported platforms

[HKEY_CURRENT_USER\Software\Policies\Citrix\ICA Client\OAuth Redirection]
"AllowOAuthRedirection"=dword:00000001
"Pattern"=""
"Scheme"=""

[HKEY_CURRENT_USER\Software\Classes\citrix-oauth-redir]
"URL Protocol"=""
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: OAuth Redirection
# State: Enabled
# Supported on: All Citrix Workspace supported platforms
# Warning: In SYSTEM context (the Intune default), HKCU targets the SYSTEM profile. Run this script using the logged-on credentials.

$path = 'HKCU:\Software\Policies\Citrix\ICA Client\OAuth Redirection'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowOAuthRedirection' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'Pattern' -Value '' -Type String
Set-ItemProperty -Path $path -Name 'Scheme' -Value '' -Type String

$path = 'HKCU:\Software\Classes\citrix-oauth-redir'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'URL Protocol' -Value '' -Type String

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview