Users experience slow logons on sites with Read-Only Domain Controllers (RODC). Administrators may also notice a spike in processor usage by winlogon.exe for up to 30 seconds.
The existence of Read-Only Domain Controllers is causing Active Directory Service Interface (ADSI) calls to take a long time, which in turn is causing a slow logon and winlogon to spike.
Switch away from Read-Only Domain Controllers on the site where you are experiencing the issue.
Citrix have diagnosed the root-cause behind this issue, and a Private fix is available for XenApp 5, XenApp 6, and XenApp 6.5. As this fix is still a private fix, you must contact Citrix Support to obtain a copy of this.
Please quote CPR Ref: LA1617 when contacting support to assist with locating the correct fix.
Read the original article at the Knowledgebase here.