Citrix Endpoint Management

Server properties

Server properties are global properties that apply to operations, users, and devices across an entire Endpoint Management instance. Citrix recommends that you evaluate for your environment the server properties covered in this article. Be sure to consult with Citrix before changing other server properties.

To update server properties, go to Settings > Server Properties.

Adding, Editing, or Deleting Server Properties

In Endpoint Management, you can apply properties to the server.

  1. In the Endpoint Management console, click the gear icon in the upper-right corner. The Settings page appears.

  2. Under Server, click Server Properties. The Server Properties page appears. You can add, edit, or delete server properties from this page.

    Server properties

To add a server property

  1. Click Add. The Add New Server Property page appears.

    Server properties

  2. Configure these settings:

    • Key: In the list, select the appropriate key. Keys are case-sensitive. Contact Citrix Support before you edit property values or to request a special key.
    • Value: Enter a value depending on the key you selected.
    • Display Name: Enter a name for the new property value that appears in the Server Properties table.
    • Description: Optionally, type a description for the new server property.
  3. Click Save.

To edit a server property

  1. In the Server Properties table, select the server property you want to edit.

    When you select the check box next to a server property, the options menu appears above the server property list. Click anywhere else in the list to open the options menu on the right side of the listing.

  2. Click Edit. The Edit New Server Property page appears.

    Server properties

  3. Change the following information as appropriate:

    • Key: You cannot change this field.
    • Value: The property value.
    • Display Name: The property name.
    • Description: The property description.
  4. Click Save to save your changes or Cancel to leave the property unchanged.

To delete a server property

  1. In the Server Properties table, select the server properties you want to delete.

  2. Click Delete. A confirmation dialog box appears. Click Delete again.

Server Property Definitions

Access all apps in the managed Google Play store

  • If true, Endpoint Management makes all apps from the public Google Play store accessible from the managed Google Play store. You can use the Restrictions device policy to control access to these apps. Defaults to false.

Add Device Always

  • If true, Endpoint Management adds a device to the Endpoint Management console, even if it fails enrollment. As a result, you can see which devices attempted to enroll. Defaults to false.

AG Client Cert Issuing Throttling Interval

  • The grace period between generating certificates. This interval prevents Endpoint Management from generating multiple certificates for a device in a short time period. Citrix recommends that you don’t change this value. Defaults to 30 minutes.

Allows The Removal of Devices That Have Been Marked Inactive For A Specified Period Of Time

  • If true, devices that have been inactive for a specified time (in days) are removed and deleted from Endpoint Management. The period of activity is set by the Length of Time Device Can Be Inactive Before Being Automatically Removed From CEM server property. The default is true. To change the value of this property, consult your Citrix representative.

Audit Logger

  • If False, does not log user interface (UI) events. Defaults to False.

Block Enrollment of Rooted Android and Jailbroken iOS Devices

When this property is true, Endpoint Management blocks enrollments for rooted Android devices and jailbroken iOS devices. Recommended setting is true for all security levels. Defaults to true.

cdn.s3.retry.interval and cdn.s3.max.retry

The cdn.s3.retry.interval and cdn.s3.max.retry server properties work together to set the maximum time limit on every macOS PKG file upload. By default, Endpoint Management limits file upload times to 100 seconds. If a file upload exceeds that limit, the upload fails. To change the default, configure the cdn.s3.retry.interval and cdn.s3.max.retry keys as follows:

  • cdn.s3.retry.interval. Lets you define the interval, in milliseconds, at which Endpoint Management verifies whether a file upload completes successfully. The default is 10000.
  • cdn.s3.max.retry. Lets you define the maximum number of verification retries after which the upload fails. The default is 10.

The two keys work together to limit file upload times. By default, the time limit is 100 seconds (10000*10 milliseconds).

Certificate Renewal in Seconds

  • The number of seconds before a certificate expires that Endpoint Management starts to renew certificates. An example is when a certificate expires on December 30 and this property is set to 30 days. If the device connects between December 1 and December 30, Endpoint Management attempts to renew the certificate. Defaults to 2592000 seconds (30 days).

Connection Timeout

  • The session inactivity timeout, in minutes, after which Endpoint Management closes the TCP connection to a device. The session remains open. Applies to Android devices. Defaults to 5 minutes.

Default deployment channel

  • Determines how Endpoint Management deploys a resource to a device: At the user-level (DEFAULT_TO_USER) or device-level. Defaults to DEFAULT_TO_DEVICE.

Deprecate mobile service provider

  • Deprecates support for the mobile service provider interface used to query Blackberry and other Exchange ActiveSync devices. While enabled, the Mobile Service Provider interface is hidden from the console. Default is true.

Device tagging

  • If you set enable.device.tagging to true, Endpoint Management tags devices by device type automatically. You can use device tags to deploy policies and apps or configure delivery groups. Endpoint Management applies tags to devices for the following:
    • BYOD tags
      • iOS User Enrollment
      • Android Enterprise work profile
    • Corporate tags
      • Android Enterprise fully managed corporate devices
      • Bulk enrollment
        • Apple Business Manager devices
        • Apple School Manager devices
        • Windows AutoPilot devices
        • Android Enterprise bulk enrollment

Disable Hostname Verification

  • By default, hostname verification is enabled on outgoing connections except for the Microsoft PKI server. When hostname verification fails, the server log includes errors such as: “Unable to connect to the volume purchase Server: Host name ‘’ does not match the certificate subject provided by the peer”. If hostname verification breaks your deployment, change this property to true. Defaults to false.

Disable SSL Server Verification

  • If True, disables SSL server certificate validation when all the following conditions are met:
    • You enabled certificate-based authentication on Endpoint Management
    • The Microsoft CA server is the certificate issuer
    • An internal CA, whose root Endpoint Management doesn’t trust, signed your certificate.

    Defaults to True.

Enable Crash Reporting

  • If true, Citrix collects crash reports and diagnostics to help troubleshoot issues with Secure Hub for iOS and Android. If false, no data is collected. Default value is true.

Enable/Disable Hibernate statistics logging for diagnostics

  • If True, enables Hibernate statistics logging to assist with troubleshooting application performance issues. Hibernate is a component used for Endpoint Management connections to a Microsoft SQL Server. By default, the logging is disabled because it impacts application performance. Enable logging only for a short duration to avoid creating a huge log file. Endpoint Management writes the logs to /opt/sas/logs/hibernate_stats.log. Defaults to False.

Enable macOS OTAE

  • If false, prevents the use of an enrollment link for macOS devices, meaning macOS users can enroll only by using an enrollment invitation. Defaults to true.

Enable Notification Trigger

  • Enables or disables Secure Hub client notifications. The value true enables notifications. Defaults to true.

Full Pull of ActiveSync Allowed and Denied Users

  • The interval in (in seconds) that Endpoint Management pulls a complete list (baseline) of ActiveSync allowed and denied users. Defaults to 28800 seconds.

Identifies if telemetry is enabled or not

  • Identifies if telemetry is enabled. Telemetry is also referred to as the Customer Experience Improvement Program (CEIP). You can opt in to CEIP when you install or upgrade Endpoint Management. If Endpoint Management has 15 consecutive failed uploads, it disables telemetry. Defaults to false.

Inactivity Timeout in Minutes

  • The number of minutes after which Endpoint Management logs out an inactive user. The user must have used the Endpoint Management Public API to access the Endpoint Management console or any third-party app. A time-out value of 0 means that an inactive user remains logged in. For third-party apps that access the API, remaining logged in is typically necessary. Default is 5.

  • If the WebServices timeout type server property is INACTIVITY_TIMEOUT: This property defines the number of minutes after which Endpoint Management logs out an inactive administrator who did the following:

    • Used the Public API for REST Services to access the Endpoint Management console
    • Used the Public API for REST Services to access any third-party app. A timeout of 0 means that an inactive user remains logged in.

  • Includes all device properties in a device search. The default is Off, which limits the search scope to these device properties, for fast searching:
    • Serial Number
    • IMEI
    • Wi-Fi MAC address
    • Bluetooth MAC address
    • Active Sync ID
    • User Name

    When this property is On, device searches can take longer.

ios.delayBeforeDeclareUnreachable; macos.delayBeforeDeclareUnreachable

  • Specifies the number of days after which an offline iOS or macOS device is considered unreachable. When an iOS or macOS device reaches the limit specified, they stop checking back with Endpoint Management. Both properties default to 45 days.

iOS Device Management Enrollment Install Root CA if Required

  • The server property ios.mdm.enrollment.installRootCaIfRequired is set to False for all Endpoint Management environments. Endpoint Management uses a publicly trusted certificate chain, thus it isn’t necessary to push a root CA to devices. (This property is used only for on-premises environments.)

iOS Device Management Enrollment Last Step Delayed

  • During device enrollment, this property value specifies the amount of time to wait between installing the MDM profile and starting the Agent on the device. Citrix recommends that you edit this property only for network latency or speed issues. In that case, don’t set to the value to more than 5000 milliseconds (5 seconds). Defaults to 1000 milliseconds (1 second).

iOS Device Management Identity Delivery Mode

  • Specifies whether Endpoint Management distributes the MDM certificate to devices using SCEP (recommended for security reasons) or PKCS12. In PKCS12 mode, the key pair is generated on the server and no negotiation is performed. Defaults to SCEP.

iOS Device Management Identity Key Size

  • Defines the size of private keys for MDM identities, iOS profile service, and Endpoint Management iOS agent identities. Defaults to 2048.

iOS Device Management Identity Renewal Days

  • Specifies the number of days before the certificate expiration that Endpoint Management starts renewing certificates. For example: If a certificate expires in 10 days and this property is 10 days: When a device connects 9 days before expiration, Endpoint Management issues a new certificate. Defaults to 30 days.

iOS MDM APNS Private Key Password

  • This property contains the APNs password, which is required for Endpoint Management to push notifications to Apple servers.

Length of Inactivity Before Device Is Disconnected

  • Specifies how long a device can remain inactive, including the last authentication, before Endpoint Management disconnects it. Defaults to 7 days.

Length of Time Device Can Be Inactive Before Being Automatically Removed From CEM

  • The length of time (in days) a device can be inactive before being automatically removed from Endpoint Management. The minimum is 14 days and the default is 30 days. The Allows The Removal of Devices That Have Been Marked Inactive For A Specified Period Of Time server property must be set to true for this property to take effect.


  • Specifies the number of minutes a user must wait after exceeding the lockout limit. Supported values are 0–999. The default is 30 minutes.


  • Specifies the maximum number of consecutive invalid login attempts per user. Supported values are 0–999. The default is 6 attempts.


This server property lets you configure administrator password rotation intervals for macOS devices enrolled through the Apple Deployment Program. Endpoint Management checks whether to rotate the password of the administrator account daily. By default, Endpoint Management rotates the password every 10,080 minutes (7 days). Configure the mac.dep.admin.passwd.rotate key as follows:

  • Value: administrator-defined The interval, in minutes, at which Endpoint Management rotates the password. Type a value equal to or greater than 360 (6 hours). Endpoint Management ignores values smaller than 360 and rotates the password every 360 minutes (6 hours) instead.
  • Display name: administrator-defined
  • Description: administrator-defined

MAM Only Device Max

  • This Custom Key limits the number of MAM-only devices that each user can enroll. Configure the key as follows. A Value of 0 allows unlimited device enrollments.

  • Key = number.of.mam.devices.per.user
  • Value = 5
  • Display name = MAM Only Device Max
  • Description = Limits the number of MAM devices each user can enroll.


  • The number of threads used when importing many volume purchase licenses. Defaults to 3. If you need further optimization, you can increase the number of threads. However, a larger number of threads results in high CPU usage.

Citrix Gateway (NetScaler) Single Sign-On

  • If False, disables the Endpoint Management callback feature during single sign-on from Citrix Gateway to Endpoint Management. If the Citrix Gateway configuration includes a callback URL, Endpoint Management uses the callback feature to verify the Citrix Gateway session ID. Defaults to False.

Number of consecutive failed uploads

  • Displays the number of consecutive failures during Customer Experience Improvement Program (CEIP) uploads. Endpoint Management increments the value when an upload fails. After 15 upload failures, Endpoint Management disables CEIP, also called telemetry. For more information, see the server property Identifies if telemetry is enabled or not. Endpoint Management resets the value to 0 when an upload succeeds.

Number of Users Per Device

  • The maximum number of users who can enroll the same device in MDM. The value 0 means that an unlimited number of users can enroll the same device. Defaults to 0.


  • This server property lets you customize the optional Active Directory user attributes.

    Create the custom key and, in the Values field, edit user attributes to define which attributes Endpoint Management can access to create a user account. For more information, see Customize user properties.

    • Key: Custom Key
    • Key: optional.user.identity.attributes
    • Value: commonName, firstName, lastName, displayName, streetAddress, city, state, country, workPhone, homePhone, mobilePhone, company, department, description, employeeID, faxNumber, initials, ipPhone, manager, homePostalAddress, otherMobile, pager, physicalDeliveryOfficeName, postalCode, postOfficeBox, title, organization, preferredLanguage
    • Display Name: optional.user.identity.attributes
    • Description: Optional Active Directory user attributes

Organization Name for macOS and iOS/iPadOS Enrollment Profiles

  • The value you type for corresponds to the name of the organization that provides the enrollment profile. The name displays when users enroll their device to Endpoint Management. The default name that displays is Citrix Workspace.

Pull of Incremental Change of Allowed and Denied Users

  • The number of seconds that Endpoint Management waits for a response from the domain when running a PowerShell command to get a delta of ActiveSync devices. Defaults to 60 seconds.

Read Timeout to Microsoft Certification Server

  • The number of seconds that Endpoint Management waits for a response from the certificate server when performing a read. If the certificate server is slow and has much traffic, you can increase this value to 60 seconds or more. A certificate server that doesn’t respond after 120 seconds requires maintenance. Defaults to 15000 milliseconds (15 seconds).

REST Web Services

  • Enables the REST Web Service. Defaults to true.

Retrieves devices information in chunks of specified size

  • This value is used internally for multithreading during device exports. If the value is higher, a single thread parses more devices. If the value is lower, more threads fetch the devices. Reducing the value might increase the performance of exports and device list fetches, yet might reduce available memory. Defaults to 1000.


  • If False, prevents access to the Self-Help Portal. Users who navigate to the portal on port 4443 get an “Access Denied” message. If True, provides access to the Self-Help Portal over port 443.

    Defaults to False.

  • If False, prevents users from enabling their devices from the Self-Help Portal. If True, users can enable their devices from the Self-Help Portal.

    The BitLocker recovery key feature requires that you set this property to False and the shp.console.enable property to True.

    Defaults to False.

Session Log Cleanup (in Days)

  • The number of days that Endpoint Management retains the session log. Defaults to 7.

Content Collaboration configuration type

  • Specifies the Citrix Files storage type. ENTERPRISE enables Citrix Files Enterprise mode. CONNECTORS provides access only to storage zone connectors that you create through the Endpoint Management console. Defaults to NONE, which shows the initial view of the Configure > Citrix Files screen where you choose between Citrix Files Enterprise and Connectors. Defaults to NONE.

Static Timeout in Minutes

  • If the WebServices timeout type server property is STATIC_TIMEOUT: This property defines the number of minutes after which Endpoint Management logs out an administrator after using the following:
    • The Public API for REST Services to access the Endpoint Management console.
    • The Public API for REST Services to access any third-party app.

    Defaults to 60.

Trigger Agent Message Suppression

  • Enables or disables Secure Hub client messaging. The value false enables messaging. Defaults to true.

Trigger Agent Sound Suppression

  • Enables or disables Secure Hub client sounds. The value false enables sounds. Defaults to true.

Unauthenticated App Download for Android Devices

  • If True, you can download self-hosted apps to Android devices running Android Enterprise. Endpoint Management needs this property if the Android Enterprise option to provide a download URL in the Google Play Store statically is enabled. In that case, download URLs can’t include a one-time ticket (defined by the XAM One-Time Ticket server property) which has the authentication token. Defaults to False.

Unauthenticated App Download for Windows Devices

  • Used only for older Secure Hub versions which don’t validate one-time tickets. If False, you can download unauthenticated apps from Endpoint Management to Windows devices. Defaults to False.

Use ActiveSync ID to Conduct an ActiveSync Wipe Device

  • If true, Endpoint Management connector for Exchange ActiveSync uses the ActiveSync identifier as an argument for the asWipeDevice method. Defaults to false.

Users only from Exchange

  • If true, disables user authentication for ActiveSync Exchange users. Defaults to false.

Volume purchase baseline interval

  • The minimum interval that Endpoint Management reimports volume purchase licenses from Apple. Refreshing license information ensures that Endpoint Management reflects all changes, such as when you manually delete an imported app from volume purchase. By default, Endpoint Management refreshes the volume purchase license baseline a minimum of every 1440 minutes.

    • If you have many volume purchase licenses installed (for example, more than 50,000): Citrix recommends that you increase the baseline interval to reduce the frequency and overhead of importing licenses.

    • If you expect frequent volume purchase license changes from Apple: Citrix recommends that you lower the value to keep Endpoint Management updated with the changes.

    • The minimum interval between two baselines is 60 minutes. In addition, Endpoint Management performs a delta import every 60 minutes, to capture the changes since the last import. Therefore, if the volume purchase baseline interval is 60 minutes, the interval between baselines might be delayed up to 119 minutes.

WebServices Timeout Type

  • Specifies how to expire an authentication token retrieved from the public API.
    • If STATIC_TIMEOUT: Endpoint Management considers a token expired, based on the value of the server property Static Timeout in Minutes.

    • If INACTIVITY_TIMEOUT: Endpoint Management considers a token expired, based on the value of the server property Inactivity Timeout in Minutes. Defaults to STATIC_TIMEOUT.

Windows Tablet MDM Certificate Extended Validity (5y)

  • The validity period of the device certificate issued by MDM for Windows Tablet. Devices use a device certificate to authenticate to the MDM server during device management. If true, the validity period is five years. If false, the validity period is two years. Defaults to true.

Windows WNS Channel - Number of Days Before Renewal

  • The renewal frequency for the ChannelURI. Defaults to 10 days.

Windows WNS Heartbeat Interval

  • How long Endpoint Management waits before connecting to a device after connecting to it every three minutes five times. Defaults to 6 hours.

XAM One-Time Ticket

  • The number of milliseconds that a one-time authentication token (OTT) is valid for downloading an app. This property and the properties Unauthenticated App download for Android and Unauthenticated App download for Windows work together. Those properties specify whether to allow unauthenticated app downloads. Defaults to 3600000.

Endpoint Management MDM Self-Help Portal console max inactive interval (minutes)

  • This property name reflects the older Endpoint Management versions. The property controls the Endpoint Management console max inactive interval. That interval is the number of minutes after which Endpoint Management logs an inactive user out of the Endpoint Management console. A time-out of 0 means that an inactive user remains logged in. Default is 30.
Server properties