Your users connect from PCs you only partly control. A check at login shouldn’t be the last one — Citrix deviceTRUST reads the security, network and location of the device behind each virtual session, and changes what that session may do the moment any of it changes.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Citrix deviceTRUST — the Console, Agent and Client Extension, bundled or bought direct. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Access that depends on the device’s state right now, not only on who signed in and from where.
What consolidation actually replaces, dimension by dimension.
| Dimension | A device check at login only | Citrix deviceTRUST |
|---|---|---|
| When the device is judged | Once, at login | At login and again whenever its context changes |
| Home and partner PCs | Blocked outright, or trusted blindly | Allowed while antivirus and firewall report healthy |
| Location rules | IP ranges kept by hand | Location, Wi-Fi, network and WHOIS properties |
| What happens on a breach | Nothing until the next login | Warn, close one app, log off or disconnect |
| Where the data sits | Depends on the tool | On your own servers; no vendor cloud involved |
| What it is NOT | — | An identity provider, a ZTNA or an MDM |
The cheapest test costs nothing extra if you hold UHMC: import the compliance-check template, leave enforcement off for two weeks, and count who would have failed.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Installed with Citrix Workspace app 2503 or later on Windows, macOS and Ubuntu, and built into Workspace app for iOS and Android; it gathers device context with no management of its own.
Context travels in a virtual channel of the remoting protocol, which Citrix may need on its allow list; with no Client Extension present, the session falls back to the host’s local properties.
Part of the Citrix VDA install from release 2503, or installed on an RDS host or a local PC; it evaluates contexts, runs actions and writes every operation to the Windows Event Log.
A Windows console that builds contexts, actions and messages, often from templates, and publishes them through Active Directory Group Policy or as a file copied to the host.
Context read on the device, carried inside the session — enforced by an Agent on the host, with no cloud in between.
Citrix deviceTRUST lets the state of the user’s device decide what a session may do, for as long as it runs.
Property groups cover hardware, OS, domain, network, Wi-Fi access points, certificates, printers, displays, MDM and more.
Real-time properties report the state of antivirus and firewall products, Windows Defender, and Windows or macOS updates.
Location, WHOIS, region and network properties let a rule tell an office, a home and another country apart.
Ten remote template families, from BYOD and external partners to time-based access, import ready-made contexts and actions.
Contexts are re-evaluated during the session, and a transition operator lets an action fire on a move from one value to another.
When a user opens a session from inside another session, multi-hop properties carry the original device’s context forward.
A non-compliant device can get a warning, a deny-access screen, a log-off or a disconnect, chosen per use case.
Conditional application access hides or stops a single sensitive app while the rest of the desktop keeps working.
Context can map the nearest printers, apply a dynamic policy, or switch on App Protection anti-screen capture on Windows.
Three 2025 walkthroughs from Citrix’s official channel: access tied to antivirus state, access by geolocation, and geofencing.
Session access tied to the state of the antivirus on the device the user connects from.
A walkthrough of allowing or refusing a session by where the connecting device is.
Geofencing as a deviceTRUST use case: drawing an area and reacting when a device leaves it.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Identity tools judge a device at the moment of login. deviceTRUST keeps reading the endpoint while the virtual session is open, so if the firewall is switched off, an unknown USB drive appears, a smart card is pulled or the laptop leaves the office network, policy can warn, close one app or end the session there and then.
From release 2503 the Agent installs with the Citrix VDA and the Client Extension with Workspace app on Windows, macOS and Ubuntu, and release 2603 builds it into Workspace app for iOS and Android. In a Citrix Virtual Apps and Desktops estate no separate licence key is needed, and UHMC and the Citrix Platform give unlimited use.
deviceTRUST has no cloud service, database or web server. Policy is delivered by Active Directory Group Policy or a file on the host, results go to the Windows Event Log, and the context it reads stays inside the session. For an Indian bank or insurer that keeps desktops in its own data centre, the control stays there too.
It governs Windows sessions and PCs, not SaaS sign-ins or private-network access; pair it with an identity provider and a ZTNA. Citrix sessions delivered in HTML5 are not yet supported, Azure Virtual Desktop works only from Windows and IGEL clients, the direct price is unpublished, and custom scripts now have to be signed.
Confirm whether UHMC or the Citrix Platform covers your users, and whether VDA and Workspace app are on 2503 or later.
Choose the riskiest gaps, such as unhealthy home PCs and USB drives, and import the matching templates in the Console.
Deploy the policy by GPO to one delivery group with enforcement actions off, and read the Event Log to see who would fail.
Turn on deny or log-off actions for the pilot, tune messages users see, and list exceptions with an owner for each.
Roll the policy out group by group, add geolocation or partner rules, and sign any custom scripts before upgrades.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Agents on home laptops with the firewall off now get a warning, then lose the claims app after two minutes. No more blanket bans.”
“We pull the trading desktop the moment a laptop leaves the office Wi-Fi. Geofencing took one template and an afternoon.”
“It was already in our VDA build. The real work was agreeing which USB drives count as authorised, not installing anything.”
“Printers now map by floor from the device’s network, so the helpdesk stopped fielding ‘wrong printer’ tickets every Monday.”
“Signed scripts broke two of our custom checks on upgrade. Read the compatibility notes and sign everything before you deploy.”
“Our partners use their own PCs. The external-partner template blocks downloads unless their antivirus reports healthy.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the contextual access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Unlimited in UHMC and the Citrix Platform; direct price on request.
The grid nobody publishes — how far into the working session each tool keeps acting vs how much it can read about the device.
Acts throughout the session; 44 property groups.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Microsoft Entra Conditional Access, Cisco Duo, Okta Device Assurance, Omnissa Access and Citrix SecurAccess ZTNA — on when they act, signals, devices, virtual desktops, price and India.
| Dimension | Citrix deviceTRUST | Microsoft Entra Conditional Access | Cisco Duo | Okta Device Assurance | Omnissa Access | Citrix SecurAccess ZTNA |
|---|---|---|---|---|---|---|
| What it is | In-session context tool | Entra’s policy engine | MFA with device trust | Posture rules in Okta | IdP with context rules | Citrix’s ZTNA |
| Where it acts | Throughout the session | After first-factor login | At authentication | In app sign-in policy | At catalogue access | Per app connection |
| Deployment | All on your servers | Microsoft cloud only | Cloud service | Okta cloud | Cloud or on-prem | Cloud or hybrid |
| Context signals | 44 property groups | Device, IP, risk, app | Health, OS, location | OS version and patch | Network, OS, compliance | Posture, geo, EDR |
| Devices covered | Seven client platforms | All major platforms | Managed and personal | Four Okta Verify OSes | Best with Omnissa UEM | Windows and macOS agent |
| Virtual desktops | Citrix, RDS and AVD | Gates the AVD sign-in | Gates RDP logons | Not session-aware | Native with Horizon | Apps via StoreFront |
| Actions on change | Warn, block, log off | Block or require more | Block or step up | Allow or deny sign-in | Step up or deny | Revoke dynamically |
| Pricing model | Bundle or named user | Per user, Entra ID P1 | Per user, four editions | Per user, plus AMFA | Per user, in editions | Per user, in bundles |
| Published entry price | On request | About $6–7 a user | $3 / $6 / $9 a user | From $6, plus add-on | $3 add-on only | Not published |
| Included vs add-on | Support in the term | Intune and P2 extra | Health is Advantage+ | AMFA SKU required | UEM for compliance | Chrome path is CPL |
| Policy and admin | GPO or file, Event Log | Admin center, what-if | Duo Admin Panel | Okta Admin Console | Rules per app | Citrix Cloud console |
| India data location | Wherever you host it | Asia/Pacific geo | Mumbai data centre | India tenants (2026) | On-prem keeps it local | No India region |
| Lock-in and exit | Citrix-centred | Tied to Entra ID | Sits beside any IdP | Tied to Okta | Omnissa stack | Citrix subscription |
| Best fit | Session-level control | Microsoft-first estates | Mixed IdPs, RDP, VPNs | Okta-centred SaaS | Horizon + Workspace ONE | Retiring the VPN |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no contextual access control guide yet, so Citrix deviceTRUST sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (users working in virtual sessions; security-admin hour cost). Estimates model the time spent handling access exceptions, investigating risky home or partner devices and maintaining location rules by hand, at an assumed 1.5 hours per user a year, with 70% of it removed by template-driven context policies. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: deviceTRUST is unlimited inside Universal Hybrid Multi-Cloud and the Citrix Platform licence, both quoted per user, and in a Citrix Virtual Apps and Desktops estate it needs no separate key. It is also sold direct per named user on 12 to 60-month terms, with maintenance and support included, priced on request. TechBag checks your entitlement first, then quotes in INR with GST.
Best for estates already on a Citrix subscription
Best for a broader rollout
Best for Microsoft RDS and AVD hosts
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do UHMC or the Citrix Platform already cover your users, or do RDS and AVD hosts need direct named-user licences?
Are your VDAs and Workspace apps on 2503 or later, so the Agent and Client Extension come in by default?
Which devices connect: Windows, macOS, Ubuntu, iOS, IGEL, NoTouch or eLux? Any HTML5 sessions will lack context.
Which risks come first: home-PC health, USB drives, location, partners or smart-card removal? Start with two.
For each failure, is the response a message, one blocked app, a log-off or a disconnect? Agree it with users.
Will policy go out by Group Policy or as a file on each host? Deploy new Agents before policy from a newer Console.
Do any custom properties or tasks rely on scripts? They must now be signed, and Batch and VBS are deprecated.
If buying direct, which term from 12 to 60 months, and who owns reassignments? Ask for INR with GST.
Check whether your Citrix subscription already covers it first, or let a TechBag advisor design two use cases and run them in notify-only mode on one delivery group.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.