Device Identity & Compliance Verification
deviceTRUST reads hardware identifiers, domain membership, OS version, Workspace App version, installed security software, patch level, and certificate state, building a device identity profile that is continuously re-evaluated. Only devices that satisfy all configured compliance criteria can access corporate resources, and the check never stops.
Device Posture
Geolocation & Network Access Control
Access policies can be bound to geographic regions, specific IP ranges, or named network profiles. deviceTRUST uses real-time location properties to deny access from prohibited countries at logon, and can revoke or restrict an active session if a user's location changes to an unauthorised zone during the session, without requiring re-authentication.
Geo-Fencing
Dynamic In-Session Application Control
Context changes during a session do not need to result in disconnection. deviceTRUST can restrict access to specific published applications, adjust virtual channel policies such as clipboard redirection and printing rights, or lock the session screen, all while keeping the session alive and the user informed. Restrictions are reversed automatically when compliance is restored.
In-Session Policy
Peripheral & USB Device Control
deviceTRUST monitors connected peripheral devices in real time, detecting when a USB drive, storage device, or other peripheral is inserted during an active session. Policies can whitelist approved storage media, and automatically lock session access or block drive redirection when an unauthorised device is detected, protecting against data exfiltration through physical media.
Data Loss Prevention
BYOD & Unmanaged Device Scenarios
deviceTRUST enables organisations to define differentiated access policies for managed corporate devices versus personal BYOD devices, allowing both to connect, but applying stricter session restrictions to unmanaged endpoints. Users on personal devices may access a limited set of applications, with clipboard and printing disabled, while corporate device users receive full access, all within the same Citrix infrastructure.
BYOD Policy
Audit Trail & Compliance Reporting
Every context evaluation, policy decision, and enforcement action is logged, providing a complete audit trail of what was checked, when, what was found, and what action was taken. This audit data supports regulatory compliance reporting, security incident investigations, and the AAA (authorise, authenticate, audit) framework that is the foundation of a credible Zero Trust posture.
Full Audit Trail