Citrix Device Posture service is a cloud-based solution designed to enforce security requirements for endpoint devices accessing Citrix DaaS (virtual apps and desktops) or Citrix Secure Private Access resources (SaaS, web, TCP, and UDP apps).
This service supports a zero-trust security model by assessing device compliance before granting access.
Below is a brief summary for the full article - Click here
How it works:
- Administrators create device posture policies to evaluate the status of endpoint devices.
- Devices are classified based on their compliance with these policies, determining their level of access.
- Users can log in through a browser or the Citrix Workspace app.
Device Classification:
- Compliant devices: Meet policy requirements and are granted full access.
- Non-Compliant devices: Meet policy requirements but receive partial or restricted access.
- Denied login: Fail to meet the requirements and are blocked from logging in.
This classification helps Citrix DaaS and Citrix Secure Private Access services to enable smart access controls based on the device's compliance status.
Note - Citrix advises:
- The device posture policies must be configured specifically for each platform. For example, for macOS, an admin can allow access for the devices that have a specific OS version. Similarly, for Windows, the admin can configure policies to include a specific authorization file, registry settings, and so on.
- Device posture scans are done only during pre-authentication/before logging in.
- For definitions of “compliant” and “non-compliant,” see Definitions.
Further reading: