Server properties are global properties that apply to operations, users, and devices across an entire Endpoint Management instance. Citrix recommends that you evaluate for your environment the server properties covered in this article. Be sure to consult with Citrix before changing other server properties.
Some server properties help improve performance and stability. For details, see Tuning Endpoint Management operations.
Server Property Definitions
Add Device Always
- If true, Endpoint Management adds a device to the Endpoint Management console, even if it fails enrollment, so you can see which devices attempted to enroll. Defaults to false.
AG Client Cert Issuing Throttling Interval
- The grace period between generating certificates. This interval prevents Endpoint Management from generating multiple certificates for a device in a short time period. Citrix recommends that you don’t change this value. Defaults to 30 minutes.
Audit Log Cleanup Execution Time
- The time to start the audit log cleanup, formatted as HH:MM AM/PM. Example: 04:00 AM. Defaults to 02:00 AM.
Audit Log Cleanup Interval (in Days)
- The number of days that Endpoint Management retains the audit log. Defaults to 1.
- If False, does not log user interface (UI) events. Defaults to False.
Audit Log Retention (in Days)
- The number of days that Endpoint Management retains the audit log. Defaults to 7.
Block Enrollment of Rooted Android and Jailbroken iOS Devices
When this property is true, Endpoint Management blocks enrollments for rooted Android devices and jailbroken iOS devices. Recommended setting is true for all security levels. Defaults to true.
Certificate Renewal in Seconds
- The number of seconds before a certificate expires that Endpoint Management starts to renew certificates. For example, if a certificate will expire December 30 and this property is set to 30 days: If the device connects between December 1 and December 30, Endpoint Management attempts to renew the certificate. Defaults to 2592000 seconds (30 days).
- The session inactivity timeout, in minutes, after which Endpoint Management closes the TCP connection to a device. The session remains open. Applies to Android and Windows CE devices. Defaults to 5 minutes.
Connection Timeout to Microsoft Certification Server
- The number of seconds that Endpoint Management waits for a response from the certificate server. If the certificate server is slow and has much traffic, increase this value to 60 seconds or more. A certificate server that doesn’t respond after 120 seconds requires maintenance. Defaults to 15000 milliseconds (15 seconds).
Default deployment channel
- Determines how Endpoint Management deploys a resource to a device: At the user-level (DEFAULT_TO_USER) or device-level. Defaults to DEFAULT_TO_DEVICE.
Deploy Log Cleanup (in Days)
- The number of days that Endpoint Management retains the deployment log. Defaults to 7.
Disable Hostname Verification
- By default, hostname verification is enabled on outgoing connections except for the Microsoft PKI server. When hostname verification fails, the server log includes errors such as: “Unable to connect to the VPP Server: Host name ‘192.0.2.0’ does not match the certificate subject provided by the peer”. If hostname verification breaks your deployment, change this property to true. Defaults to false.
Disable SSL Server Verification
- If True, disables SSL server certificate validation when all the following conditions are met:
- You enabled certificate-based authentication on Endpoint Management
- The Microsoft CA server is the certificate issuer
- An internal CA, whose root Endpoint Management doesn’t trust, signed your certificate.
Defaults to True.
- If true, enables user access to the Self Help Portal Console. Defaults to true.
Enable Crash Reporting
- If true, Citrix collects crash reports and diagnostics to help troubleshoot issues with Secure Hub for iOS and Android. If false, no data is collected. Default value is true.
Enable/Disable Hibernate statistics logging for diagnostics
- If True, enables Hibernate statistics logging to assist with troubleshooting application performance issues. Hibernate is a component used for Endpoint Management connections to Microsoft SQL Server. By default, the logging is disabled because it impacts application performance. Enable logging only for a short duration to avoid creating a huge log file. Endpoint Management writes the logs to /opt/sas/logs/hibernate_stats.log. Defaults to False.
Enable macOS OTAE
- If false, prevents the use of an enrollment link for macOS devices, meaning macOS users can enroll only by using an enrollment invitation. Defaults to true.
Enable Notification Trigger
- Enables or disables Secure Hub client notifications. The value true enables notifications. Defaults to true.
This property, which applies only when the Endpoint Management server Mode is ENT, specifies whether you require users to enroll in MDM. The property applies to all users and devices for the Endpoint Management instance. Requiring enrollment provides a higher level of security; however, that decision depends on whether you want to require MDM. By default, enrollment is not required.
When this property is False, users can decline enrollment, but may still access apps on their devices through the app store. When this property is True, any user who declines enrollment is denied access to apps.
If you change this property after users enroll, the users must re-enroll.
- Enables the forced deployment of required apps on Android and iOS devices in situations such as the following:
- You upload a new app and mark it as required.
- You mark an existing app as required.
- As user deletes a required app.
- A Secure Hub update is available.
Forced deployment of required apps is false by default. Create the custom key and set Value to true to enable forced deployment. During forced deployment, MDX-enabled required apps, including enterprise apps and public app store apps, upgrade immediately. The upgrade occurs even if you configure an MDX policy for an app update grace period and the user chooses to upgrade the app later.
- Key: Custom Key
- Key: force.server.push.required.apps
- Value: false
- Display Name: force.server.push.required.apps
- Description: Force required apps to deploy
Full Pull of ActiveSync Allowed and Denied Users
- The interval in (in seconds) that Endpoint Management pulls a complete list (baseline) of ActiveSync allowed and denied users. Defaults to 28800 seconds.
This property, a Custom Key, determines the idle time in seconds before a connection is automatically validated. Configure the key as follows. Default is 30.
- Key: Custom Key
- Key: hibernate.c3p0. idle_test_period
- Value: 30
- Display Name: hibernate.c3p0. idle_test_period =nnn
- Description: Hibernate idle test period
This Custom Key determines the maximum number of connections that Endpoint Management can open to the SQL Server database. Endpoint Management uses the value you specify for this custom key as an upper limit. The connections open only if you need them. Base your settings on the capacity of your database server. Configure the key as follows. Default is 1000.
- Key: hibernate.c3p0.max_size
- Value: 1000
- Display Name: hibernate.c3p0.max_size
- Description: DB connections to SQL
This Custom Key determines the minimum number of connections that Endpoint Management opens to the SQL Server database. Configure the key as follows. Default is 100.
- Key: hibernate.c3p0.min_size
- Value: 100
- Display Name: hibernate.c3p0.min_size
- Description: DB connections to SQL
This Custom Key determines the idle time-out, in seconds. Default is 120.
- Key: Custom Key
- Key: hibernate.c3p0.timeout
- Value: 120
- Display Name: hibernate.c3p0.timeout
- Description: Database idle timeout
Identifies if telemetry is enabled or not
- Identifies if telemetry (Customer Experience Improvement Program, or CEIP) is enabled. You can opt in to CEIP when you install or upgrade Endpoint Management. If Endpoint Management has 15 consecutive failed uploads, it disables telemetry. Defaults to false.
Inactivity Timeout in Minutes
The number of minutes after which Endpoint Management logs out an inactive user who used the Endpoint Management Public API to access the Endpoint Management console or any third-party app. A time-out value of 0 means an inactive user remains logged in. For third-party apps that access the API, remaining logged in is typically necessary. Default is 5.
If the WebServices timeout type server property is INACTIVITY_TIMEOUT: This property defines the number of minutes after which Endpoint Management logs out an inactive administrator who did the following:
- Used the Public API for REST Services to access the Endpoint Management console
- Used the Public API for REST Services to access any third-party app. A timeout of 0 means that an inactive user remains logged in.
- Specifies the number of days after which an offline iOS or macOS device is considered unreachable. When an iOS or macOS device reaches the limit specified, they stop checking back with Endpoint Management. Both properties default to 45 days.
iOS Device Management Enrollment Auto-Install Enabled
- If true, this property reduces the amount of user interaction required during device enrollment. Users must click Root CA install (if needed) and MDM Profile install.
iOS Device Management Enrollment Install Root CA if Required
If True, Endpoint Management checks if the user has the root CA installed on the device and, if the root certificate is missing, installs it. A third-party public certificate trusted by iOS is required. Default is True.
If you are using trusted certificates and the iOS device trusts the issuer, setting this property to False improves the MDM user enrollment experience because Secure Hub doesn’t prompt the user to install another certificate and enter their PIN. However, we don’t recommend setting the property to False if you are using a self-signed SSL Listener certificate on the Endpoint Management server.
iOS Device Management Enrollment First Step Delayed
- After a user enters their credentials during device enrollment, this value specifies how long to wait before prompting for the root CA. Citrix recommends that you edit this property only for network latency or speed issues. In that case, don’t set to the value to more than 5000 milliseconds (5 seconds). Defaults to 1000 milliseconds (1 second).
iOS Device Management Enrollment Last Step Delayed
- During device enrollment, this property value specifies the amount of time to wait between installing the MDM profile and starting the Agent on the device. Citrix recommends that you edit this property only for network latency or speed issues. In that case, don’t set to the value to more than 5000 milliseconds (5 seconds). Defaults to 1000 milliseconds (1 second).
iOS Device Management Identity Delivery Mode
- Specifies whether Endpoint Management distributes the MDM certificate to devices using SCEP (recommended for security reasons) or PKCS12. In PKCS12 mode, the key pair is generated on the server and no negotiation is performed. Defaults to SCEP.
iOS Device Management Identity Key Size
- Defines the size of private keys for MDM identities, iOS profile service, and Endpoint Management iOS agent identities. Defaults to 1024.
iOS Device Management Identity Renewal Days
- Specifies the number of days before the certificate expiration that Endpoint Management starts renewing certificates. For example: If a certificate expires in 10 days and this property is 10 days, when a device connects 9 days before expiration, Endpoint Management issues a new certificate. Defaults to 30 days.
iOS MDM APNS Private Key Password
- This property contains the APNs password, which is required for Endpoint Management to push notifications to Apple servers.
Length of Inactivity Before Device Is Disconnected
- Specifies how long a device can remain inactive, including the last authentication, before Endpoint Management disconnects it. Defaults to 7 days.
MAM Only Device Max
This Custom Key limits the number of MAM-only devices that each user can enroll. Configure the key as follows. A Value of 0 allows unlimited device enrollments.
- Key = number.of.mam.devices.per.user
- Value = 5
- Display name = MAM Only Device Max
- Description = Limits the number of MAM devices each user can enroll.
- The number of threads used when importing many VPP licenses. Defaults to 3. If you need further optimization, you can increase the number of threads. However, with a larger number of threads, such as 6, a VPP import results in very high CPU usage.
NetScaler Single Sign-On
- If False, disables the Endpoint Management callback feature during single sign-on from NetScaler to Endpoint Management. If the NetScaler Gateway configuration includes a callback URL, Endpoint Management uses the callback feature to verify the NetScaler Gateway session ID. Defaults to False.
Number of consecutive failed uploads
- Displays the number of consecutive failures during Customer Experience Improvement Program (CEIP) uploads. Endpoint Management increments the value when an upload fails. After 15 upload failures, Endpoint Management disables CEIP, also called telemetry. For more information, see the server property Identifies if telemetry is enabled or not. Endpoint Management resets the value to 0 when an upload succeeds.
Number of Users Per Device
- The maximum number of users who can enroll the same device in MDM. The value 0 means that an unlimited number of users can enroll the same device. Defaults to 0.
Pull of Incremental Change of Allowed and Denied Users
- The number of seconds that Endpoint Management waits for a response from the domain when executing a PowerShell command to get a delta of ActiveSync devices. Defaults to 60 seconds.
Read Timeout to Microsoft Certification Server
- The number of seconds that Endpoint Management waits for a response from the certificate server when performing a read. If the certificate server is slow and has much traffic, you can increase this value to 60 seconds or more. A certificate server that doesn’t respond after 120 seconds requires maintenance. Defaults to 15000 milliseconds (15 seconds).
REST Web Services
- Enables the REST Web Service. Defaults to true.
Retrieves devices information in chunks of specified size
- This value is used internally for multithreading during device exports. If the value is higher, a single thread parses more devices. If the value is lower, more threads fetch the devices. Reducing the value might increase the performance of exports and device list fetches, yet might reduce available memory. Defaults to 1000.
Session Log Cleanup (in Days)
- The number of days that Endpoint Management retains the session log. Defaults to 7.
ShareFile configuration type
- Specifies the ShareFile storage type. ENTERPRISE enables ShareFile Enterprise mode. CONNECTORS provides access only to StorageZone Connectors that you create through the Endpoint Management console. Defaults to NONE, which shows the initial view of the Configure > ShareFile screen where you choose between ShareFile Enterprise and Connectors. Defaults to NONE.
Static Timeout in Minutes
- If the WebServices timeout type server property is STATIC_TIMEOUT: This property defines the number of minutes after which Endpoint Management logs out an administrator after using the following:
- The Public API for REST Services to access the Endpoint Management console.
- The Public API for REST Services to access any third-party app.
Defaults to 60.
Trigger Agent Message Suppression
- Enables or disables Secure Hub client messaging. The value false enables messaging. Defaults to true.
Trigger Agent Sound Suppression
- Enables or disables Secure Hub client sounds. The value false enables sounds. Defaults to true.
Unauthenticated App Download for Android Devices
- If True, you can download self-hosted apps to Android devices running Android Enterprise. Endpoint Management needs this property if the Android Enterprise option to provide a download URL in the Google Play Store statically is enabled. In that case, download URLs can’t include a one-time ticket (defined by the XAM One-Time Ticket server property) which has the authentication token. Defaults to False.
Unauthenticated App Download for Windows Devices
- Used only for older Secure Hub versions which don’t validate one-time tickets. If False, you can download unauthenticated apps from Endpoint Management to Windows devices. Defaults to False.
Use ActiveSync ID to Conduct an ActiveSync Wipe Device
- If true, Endpoint Management connector for Exchange ActiveSync uses the ActiveSync identifier as an argument for the asWipeDevice method. Defaults to false.
User-Defined Device Properties N
Used for Windows CE devices only. This custom key enables you to obtain properties that you create in the registry of Windows CE devices. After those properties are in the Endpoint Management database, you can create deployment rules based on the value of the properties.
- Key: Custom Key
- Key: device.properties.userDefinedN
- Value: administrator-defined
- Display Name: administrator-defined
- Description: administrator-defined
Users only from Exchange
- If true, disables user authentication for ActiveSync Exchange users. Defaults to false.
VPP baseline interval
The minimum interval that Endpoint Management reimports VPP licenses from Apple. Refreshing license information ensures that Endpoint Management reflects all changes, such as when you manually delete an imported app from VPP. By default, Endpoint Management refreshes the VPP license baseline a minimum of every 720 minutes.
If you have many VPP licenses installed (for example, more than 50,000): Citrix recommends that you increase the baseline interval to reduce the frequency and overhead of importing licenses. If you expect frequent VPP license changes from Apple: Citrix recommends that you lower the value to keep Endpoint Management updated with the changes. The minimum interval between two baselines is 60 minutes. In addition, Endpoint Management performs a delta import every 60 minutes, to capture the changes since the last import. Therefore, if the VPP baseline interval is 60 minutes, the interval between baselines might be delayed up to 119 minutes.
WebServices Timeout Type
Specifies how to expire an authentication token retrieved from the public API. If STATIC_TIMEOUT, Endpoint Management considers an authentication token as expired after the value specified in the server property Static Timeout in Minutes.
If INACTIVITY_TIMEOUT, Endpoint Management considers an authentication token as expired after the token is inactive for the value specified in the server property Inactivity Timeout in Minutes. Defaults to STATIC_TIMEOUT.
Windows Phone MDM Certificate Extended Validity (5y)
- The validity period of the device certificate issued by MDM for Windows Phone and Tablet. Devices use a device certificate to authenticate to the MDM server during device management. If true, the validity period is five years. If false, the validity period is two years. Defaults to true.
Windows WNS Channel - Number of Days Before Renewal
- The renewal frequency for the ChannelURI. Defaults to 10 days.
Windows WNS Heartbeat Interval
- How long Endpoint Management waits before connecting to a device after connecting to it every three minutes five times. Defaults to 6 hours.
XAM One-Time Ticket
- The number of milliseconds that a one-time authentication token (OTT) is valid for downloading an app. This property and the properties Unauthenticated App download for Android and Unauthenticated App download for Windows work together. Those properties specify whether to allow unauthenticated app downloads. Defaults to 3600000.
Endpoint Management MDM Self Help Portal console max inactive interval (minutes)
- This property name reflects the older Endpoint Management versions. The property controls the Endpoint Management console max inactive interval. That interval is the number of minutes after which Endpoint Management logs an inactive user out of the Endpoint Management console. A time-out of 0 means an inactive user remains logged in. Default is 30.
Adding, Editing, or Deleting Server Properties
In Endpoint Management, you can apply properties to the server.
In the Endpoint Management console, click the gear icon in the upper-right corner. The Settings page appears.
Under Server, click Server Properties. The Server Properties page appears. You can add, edit, or delete server properties from this page.
To add a server property
Click Add. The Add New Server Property page appears.
Configure these settings:
- Key: In the list, select the appropriate key. Keys are case-sensitive. Contact Citrix Support before you edit property values or to request a special key.
- Value: Enter a value depending on the key you selected.
- Display Name: Enter a name for the new property value that appears in the Server Properties table.
- Description: Optionally, type a description for the new server property.
To edit a server property
In the Server Properties table, select the server property you want to edit.
When you select the check box next to a server property, the options menu appears above the server property list. Click anywhere else in the list to open the options menu on the right side of the listing.
Click Edit. The Edit New Server Property page appears.
Change the following information as appropriate:
- Key: You cannot change this field.
- Value: The property value.
- Display Name: The property name.
- Description: The property description.
Click Save to save your changes or Cancel to leave the property unchanged.
To delete a server property
In the Server Properties table, select the server property you want to delete.
You can select more than one property to delete by selecting the check box next to each property.
Click Delete. A confirmation dialog box appears. Click Delete again.