FsLogix error "Group Policy Client service failed the logon. Access denied."

Stefanos Evangelou 106 Reputation points
2020-11-26T16:11:25.407+00:00

Hello,

I have a Citrix Virtual Apps and Desktops 1912 LTSR CU1 environment with FsLogix profiles in place on top of Windows Server 2019 session machines. After installing the latest FsLogix version 2.9.7576.47294 we have been getting the following error from a considerable number of end users when trying to login to their Citrix/RDS session: "Group Policy Client service failed the logon. Access denied.". The case is described in more detail at https://stefanos.cloud/blog/kb/how-to-resolve-error-group-policy-client-service-failed-the-logon-access-denied-in-citrix-and-fslogix-environments/.

Has anyone seen this error persistently in their VDI environment? Is this something which is identified as potential defect/bug in this new FsLogix release?

Looking forward to your feedback.

FSLogix
FSLogix
A set of solutions that enhance, enable, and simplify non-persistent Windows computing environments and may also be used to create more portable computing sessions when using physical devices.
463 questions
0 comments No comments
{count} votes

10 answers

Sort by: Most helpful
  1. Much R 71 Reputation points
    2021-01-14T11:03:01.83+00:00

    Hi there,

    the problem seems to be related to this problem in some way.
    fslogix-unclean-logoff-causing-locked-files-until.html

    I think the problem is caused by FSLogix 2009 on Windows Server 2019.

    The only thing that helps me is restarting the server.

    Best regards
    Michael

    0 comments No comments

  2. Gianluca Melis 101 Reputation points
    2021-04-21T10:45:27.77+00:00

    running the latest FsLogix version (2.9.7654.46150) on srv2019, i have the same problem here..
    i restart the server and its gone but then reappears after one or more days.
    Is there any solution to this?

    89971-image.png

    0 comments No comments

  3. Markus Wehr 1 Reputation point
    2021-05-05T09:40:27.083+00:00

    I observe the problem in rare occasions mainly with powerusers/testers. The majority of users disconnect from sessions so the probem with the locked folder under \users\local_USERNAME wont occur.

    Another obeservation: last time it occured to a profile that got the DOMAIN appendix like c:\users\uername.DOMAIN. This seems to be sticky in the profile once it was created with the appendix it well keep it through all new sessions.

    Deleting the profile will recreate a clean one c:\users\username again.

    However deleting the profile wont help with the hanging \local_username folder problem.

    0 comments No comments

  4. Андрей Михалевский 2,641 Reputation points
    2021-07-01T06:03:00.59+00:00

    LeilaKong, you said at the end of the month there will be a new version, where is it ? I have the same error. Will it be fixed there ?

    I found this solution: https://azvise.com/2021/01/21/wvd-the-group-policy-client-service-failed-the-sign-in-access-is-denied/

    But i cant find this policy in GPO.

    0 comments No comments

  5. Kristof Kuderko 6 Reputation points
    2022-01-21T16:04:31.27+00:00

    Had the exact error on AVD. Somehow user's session was stuck on one of the shut down session hosts (as they shutting down by auto scaling plan)
    When user tried to log in, it got an error and CORRUPTED_ fslogix disk was appearing each time, even after deleting all the profile disks prior to login.
    I powered up all "sleeping" hosts, user then logged in and session took over from the locked session host.
    I could see some historically opened apps (like MS Access, Explorer) popped out right away even when user didn't open them this time.
    Seemed odd but this hinted me that this was some old session.
    Once the session was taken over, I logged the user out, made sure there's no left overs on any hosts and the Access Denied issue has been fixed.

    0 comments No comments