Talk to us
by CitrixTechBag Intel Page

Citrix deviceTRUST

Your users connect from PCs you only partly control. A check at login shouldn’t be the last one — Citrix deviceTRUST reads the security, network and location of the device behind each virtual session, and changes what that session may do the moment any of it changes.

Device context for the whole sessionRuns only on your own serversIn UHMC, Citrix Platform or direct

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Unlimited in UHMC and the Citrix Platform; the direct named-user subscription is priced on request
Quote
Licence
One direct licence covers a person on any number of devices and platforms, for 12 to 60 months
Named user
Hosting
No database, web server or vendor cloud; policy travels by Group Policy or a file you place
Your servers
Analysts
No analyst ranking covers in-session context control; judge it on a pilot, not a quadrant
None cited

Quick answer

Citrix deviceTRUST reads the context of the device a person is working from — its security software, network, location, USB drives, smart card — and carries it into the virtual session, where policy can warn, block an app, or deny the session as soon as that context changes. It runs entirely on your own servers. It is unlimited in UHMC and the Citrix Platform, or sold direct per named user for 12 to 60 months. Read more ↓ Show less ↑
Part 01 · Orient

The Citrix platform family

This page covers Citrix deviceTRUST — the Console, Agent and Client Extension, bundled or bought direct. The rest:

Quick facts

30-second orientation
Product
Context-aware access control for local PCs and for VDI, DaaS and multi-hop sessions
Maker
Citrix (deviceTRUST GmbH, Darmstadt), a business unit of Cloud Software Group, privately held
Parts
Console for policy, Agent on the session host or PC, Client Extension on the user’s device
Context
44 property groups: security products, firewall, updates, location, Wi-Fi, USB, smart card, MDM
Platforms
Citrix Virtual Apps and Desktops and Citrix Cloud; Microsoft RDS and Azure Virtual Desktop
Devices
Windows, macOS, Ubuntu, iOS and iPadOS, IGEL OS, Stratodesk NoTouch and eLux 7 clients
Price
Unlimited inside UHMC and the Citrix Platform; direct named-user subscription on request
Release
2603: smart-card removal checks, App Protection anti-screen-capture task, ARM64 preview
India
No cloud service at all: Console, Agent and policy run on your servers, wherever they sit
In India via
TechBag — entitlement check, use-case design, quote in INR with GST, pilot policy
Part 02 · Learn

Understand contextual access control before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is contextual access control?

Access that depends on the device’s state right now, not only on who signed in and from where.

A device check at login only vs context that follows the session — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA device check at login onlyCitrix deviceTRUST
When the device is judgedOnce, at loginAt login and again whenever its context changes
Home and partner PCsBlocked outright, or trusted blindlyAllowed while antivirus and firewall report healthy
Location rulesIP ranges kept by handLocation, Wi-Fi, network and WHOIS properties
What happens on a breachNothing until the next loginWarn, close one app, log off or disconnect
Where the data sitsDepends on the toolOn your own servers; no vendor cloud involved
What it is NOT—An identity provider, a ZTNA or an MDM

The cheapest test costs nothing extra if you hold UHMC: import the compliance-check template, leave enforcement off for two weeks, and count who would have failed.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What reads the user’s device

Client Extension

deviceTRUST Client Extension

Installed with Citrix Workspace app 2503 or later on Windows, macOS and Ubuntu, and built into Workspace app for iOS and Android; it gathers device context with no management of its own.

02
How context reaches the session

Virtual channel

Context inside the remoting protocol

Context travels in a virtual channel of the remoting protocol, which Citrix may need on its allow list; with no Client Extension present, the session falls back to the host’s local properties.

03
Where policy is enforced

Agent

deviceTRUST Agent on the host or PC

Part of the Citrix VDA install from release 2503, or installed on an RDS host or a local PC; it evaluates contexts, runs actions and writes every operation to the Windows Event Log.

04
Where rules are written

Console

deviceTRUST Console and policy

A Windows console that builds contexts, actions and messages, often from templates, and publishes them through Active Directory Group Policy or as a file copied to the host.

Context read on the device, carried inside the session — enforced by an Agent on the host, with no cloud in between.

Part 03 · Evaluate

Nine capabilities. Sense, decide, enforce.

Citrix deviceTRUST lets the state of the user’s device decide what a session may do, for as long as it runs.

Sense
Properties

Forty-four kinds of context

Property groups cover hardware, OS, domain, network, Wi-Fi access points, certificates, printers, displays, MDM and more.

Sense
Security state

Antivirus, firewall, patches

Real-time properties report the state of antivirus and firewall products, Windows Defender, and Windows or macOS updates.

Sense
Location

Where the device really is

Location, WHOIS, region and network properties let a rule tell an office, a home and another country apart.

Decide
Templates

Start from a use case

Ten remote template families, from BYOD and external partners to time-based access, import ready-made contexts and actions.

Decide
Transitions

React when context changes

Contexts are re-evaluated during the session, and a transition operator lets an action fire on a move from one value to another.

Decide
Multi-hop

Context through every hop

When a user opens a session from inside another session, multi-hop properties carry the original device’s context forward.

Enforce
Session control

Deny, log off, disconnect

A non-compliant device can get a warning, a deny-access screen, a log-off or a disconnect, chosen per use case.

Enforce
App access

Block one app, keep the rest

Conditional application access hides or stops a single sensitive app while the rest of the desktop keeps working.

Enforce
Configuration

Change the session itself

Context can map the nearest printers, apply a dynamic policy, or switch on App Protection anti-screen capture on Windows.

See it, don’t just read it

Watch Citrix deviceTRUST in action

Three 2025 walkthroughs from Citrix’s official channel: access tied to antivirus state, access by geolocation, and geofencing.

Citrix (official)·How-to, 2025

Citrix How To: Zero Trust access based on antivirus compliance

Session access tied to the state of the antivirus on the device the user connects from.

Citrix (official)·How-to, 2025

Citrix How To: Zero Trust access based on geolocation compliance

A walkthrough of allowing or refusing a session by where the connecting device is.

Citrix (official)·Use case, 2025

deviceTRUST Use Case: Geolocation & Geofencing

Geofencing as a deviceTRUST use case: drawing an area and reacting when a device leaves it.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Citrix deviceTRUST

A device that passed at login can fail ten minutes later. deviceTRUST keeps checking for as long as the session runs.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Checks the device during the session, not only at sign-in

Identity tools judge a device at the moment of login. deviceTRUST keeps reading the endpoint while the virtual session is open, so if the firewall is switched off, an unknown USB drive appears, a smart card is pulled or the laptop leaves the office network, policy can warn, close one app or end the session there and then.

02

Already in the Citrix bits you deploy

From release 2503 the Agent installs with the Citrix VDA and the Client Extension with Workspace app on Windows, macOS and Ubuntu, and release 2603 builds it into Workspace app for iOS and Android. In a Citrix Virtual Apps and Desktops estate no separate licence key is needed, and UHMC and the Citrix Platform give unlimited use.

03

Nothing leaves your own infrastructure

deviceTRUST has no cloud service, database or web server. Policy is delivered by Active Directory Group Policy or a file on the host, results go to the Windows Event Log, and the context it reads stays inside the session. For an Indian bank or insurer that keeps desktops in its own data centre, the control stays there too.

04

Where it stops

It governs Windows sessions and PCs, not SaaS sign-ins or private-network access; pair it with an identity provider and a ZTNA. Citrix sessions delivered in HTML5 are not yet supported, Azure Virtual Desktop works only from Windows and IGEL clients, the direct price is unpublished, and custom scripts now have to be signed.

The idea
Device context judged for the whole session
The residency
No vendor cloud; runs on your hosts
The price
In UHMC or Citrix Platform, or per named user
Proof, not promises

The numbers behind the platform

44 groups
of device, network, security and session properties in the 2603 property reference
— Vendor
10 families
of remote templates, among them BYOD, external partners, geolocation and compliance checks
— Vendor
60 months
the longest direct subscription term; the shortest is 12, with 24, 36 and 48 in between
— Vendor
90 days
a reassigned named-user licence stays bound before it can move to another person again
— Vendor
2503
the VDA and Workspace app release from which deviceTRUST components install by default
— Vendor
4 customers
named on devicetrust.com, all in Germany or Switzerland, among them DB Systel and KKH
— Customer

What your Citrix deviceTRUST rollout looks like

Week 1Model

Check what you already own

Confirm whether UHMC or the Citrix Platform covers your users, and whether VDA and Workspace app are on 2503 or later.

Week 2Decide

Pick two use cases

Choose the riskiest gaps, such as unhealthy home PCs and USB drives, and import the matching templates in the Console.

Week 3Pilot

Run in notify-only mode

Deploy the policy by GPO to one delivery group with enforcement actions off, and read the Event Log to see who would fail.

Month 2Prove

Switch on enforcement

Turn on deny or log-off actions for the pilot, tune messages users see, and list exceptions with an owner for each.

Month 3Commit

Extend to every host

Roll the policy out group by group, add geolocation or partner rules, and sign any custom scripts before upgrades.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
38+ reviews*
83% would recommend
Depth of device context4.5
In-session enforcement4.4
Template coverage4.2
Ease of rollout3.9
Pricing clarity3.5
5★
46%
4★
35%
3★
13%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Insurance
“Agents on home laptops with the firewall off now get a warning, then lose the claims app after two minutes. No more blanket bans.”
Information Security Manager
Insurance
BFSI
“We pull the trading desktop the moment a laptop leaves the office Wi-Fi. Geofencing took one template and an afternoon.”
VDI Architect
BFSI
Manufacturing
“It was already in our VDA build. The real work was agreeing which USB drives count as authorised, not installing anything.”
Citrix Administrator
Manufacturing
Healthcare
“Printers now map by floor from the device’s network, so the helpdesk stopped fielding ‘wrong printer’ tickets every Monday.”
End-User Computing Lead
Healthcare
IT Services
“Signed scripts broke two of our custom checks on upgrade. Read the compatibility notes and sign everything before you deploy.”
Systems Engineer
IT Services
Pharma
“Our partners use their own PCs. The external-partner template blocks downloads unless their antivirus reports healthy.”
Head of IT Security
Pharma
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the contextual access market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Contextual Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Citrix deviceTRUSTThis page

Unlimited in UHMC and the Citrix Platform; direct price on request.

Grid 02 · The architecture

Session Reach × Context Depth

The grid nobody publishes — how far into the working session each tool keeps acting vs how much it can read about the device.

Rich signals, sign-in onlySession-long context controlBasic sign-in gatesOngoing but narrow
Citrix deviceTRUSTThis page

Acts throughout the session; 44 property groups.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Citrix deviceTRUST vs the conditional access field

Against Microsoft Entra Conditional Access, Cisco Duo, Okta Device Assurance, Omnissa Access and Citrix SecurAccess ZTNA — on when they act, signals, devices, virtual desktops, price and India.

DimensionCitrix deviceTRUSTMicrosoft Entra Conditional AccessCisco DuoOkta Device AssuranceOmnissa AccessCitrix SecurAccess ZTNA
What it isIn-session context toolEntra’s policy engineMFA with device trustPosture rules in OktaIdP with context rulesCitrix’s ZTNA
Where it actsThroughout the sessionAfter first-factor loginAt authenticationIn app sign-in policyAt catalogue accessPer app connection
DeploymentAll on your serversMicrosoft cloud onlyCloud serviceOkta cloudCloud or on-premCloud or hybrid
Context signals44 property groupsDevice, IP, risk, appHealth, OS, locationOS version and patchNetwork, OS, compliancePosture, geo, EDR
Devices coveredSeven client platformsAll major platformsManaged and personalFour Okta Verify OSesBest with Omnissa UEMWindows and macOS agent
Virtual desktopsCitrix, RDS and AVDGates the AVD sign-inGates RDP logonsNot session-awareNative with HorizonApps via StoreFront
Actions on changeWarn, block, log offBlock or require moreBlock or step upAllow or deny sign-inStep up or denyRevoke dynamically
Pricing modelBundle or named userPer user, Entra ID P1Per user, four editionsPer user, plus AMFAPer user, in editionsPer user, in bundles
Published entry priceOn requestAbout $6–7 a user$3 / $6 / $9 a userFrom $6, plus add-on$3 add-on onlyNot published
Included vs add-onSupport in the termIntune and P2 extraHealth is Advantage+AMFA SKU requiredUEM for complianceChrome path is CPL
Policy and adminGPO or file, Event LogAdmin center, what-ifDuo Admin PanelOkta Admin ConsoleRules per appCitrix Cloud console
India data locationWherever you host itAsia/Pacific geoMumbai data centreIndia tenants (2026)On-prem keeps it localNo India region
Lock-in and exitCitrix-centredTied to Entra IDSits beside any IdPTied to OktaOmnissa stackCitrix subscription
Best fitSession-level controlMicrosoft-first estatesMixed IdPs, RDP, VPNsOkta-centred SaaSHorizon + Workspace ONERetiring the VPN
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Citrix deviceTRUST if…

  • ✓Your users work in Citrix or RDS sessions from home PCs, partner laptops or thin clients you only partly control
  • ✓A failed firewall, a new USB drive or a move off the office network must change what the session allows, mid-session
  • ✓You already hold UHMC or the Citrix Platform, so the entitlement is unlimited and the components ship with VDA 2503+

Compare alternatives if…

  • ✓You mainly need device checks at SaaS sign-in — Entra Conditional Access or Okta device assurance sit in the IdP you own
  • ✓You want a published per-user price — Cisco Duo lists paid editions from $3 a user a month
  • ✓Your desktops run on Horizon with Workspace ONE UEM — Omnissa Access reads that compliance natively

Do not expect…

  • ✓A cloud console or SaaS tenant: every part runs on infrastructure you operate
  • ✓Sign-in protection for SaaS apps, or private-app access in place of a ZTNA
  • ✓Citrix HTML5 sessions, or AVD from macOS and Ubuntu clients, to carry context today

TechBag has no contextual access control guide yet, so Citrix deviceTRUST sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does policing endpoints by hand cost you?

Drag the sliders (users working in virtual sessions; security-admin hour cost). Estimates model the time spent handling access exceptions, investigating risky home or partner devices and maintaining location rules by hand, at an assumed 1.5 hours per user a year, with 70% of it removed by template-driven context policies. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual access-exception cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: deviceTRUST is unlimited inside Universal Hybrid Multi-Cloud and the Citrix Platform licence, both quoted per user, and in a Citrix Virtual Apps and Desktops estate it needs no separate key. It is also sold direct per named user on 12 to 60-month terms, with maintenance and support included, priced on request. TechBag checks your entitlement first, then quotes in INR with GST.

Inside UHMC or the Citrix Platform

Best for estates already on a Citrix subscription

  • Unlimited use, no separate licence key
  • Agent ships with VDA 2503 and later
  • Quoted per user with the subscription

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Direct named-user subscription

Best for Microsoft RDS and AVD hosts

  • Per named user, any number of devices
  • Terms of 12, 24, 36, 48 or 60 months
  • Support included; price on request

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Entitlement

Do UHMC or the Citrix Platform already cover your users, or do RDS and AVD hosts need direct named-user licences?

2
Versions

Are your VDAs and Workspace apps on 2503 or later, so the Agent and Client Extension come in by default?

3
Clients

Which devices connect: Windows, macOS, Ubuntu, iOS, IGEL, NoTouch or eLux? Any HTML5 sessions will lack context.

4
Use cases

Which risks come first: home-PC health, USB drives, location, partners or smart-card removal? Start with two.

5
Actions

For each failure, is the response a message, one blocked app, a log-off or a disconnect? Agree it with users.

6
Policy delivery

Will policy go out by Group Policy or as a file on each host? Deploy new Agents before policy from a newer Console.

7
Scripts

Do any custom properties or tasks rely on scripts? They must now be signed, and Batch and VBS are deprecated.

8
Licence terms

If buying direct, which term from 12 to 60 months, and who owns reassignments? Ask for INR with GST.

FAQ

Questions buyers ask

It is Citrix’s context-aware access control. A Client Extension reads the state of the user’s device, the Agent on the session host or PC receives it, and policy built in the Console decides what that session may do. It works on local PCs, VDI and DaaS, including sessions opened from within other sessions.

Ready to evaluate Citrix deviceTRUST?

Check whether your Citrix subscription already covers it first, or let a TechBag advisor design two use cases and run them in notify-only mode on one delivery group.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.