The announcements in this article are advanced notice of the Citrix Endpoint Management features that are being phased out, so that you can make timely business decisions. Citrix monitors customer use and feedback to determine when they are withdrawn. Announcements can change in subsequent releases and might not include every deprecated feature or functionality. For details about product lifecycle support, see the Product Lifecycle Support Policy article.
Deprecations and removals
The following list shows the Citrix Endpoint Management features that are deprecated or removed.
Deprecated items are not removed immediately. Citrix continues to support a deprecated item until removing it in a future release.
Removed items are either removed, or are no longer supported, in Citrix Endpoint Management.
For information about the mobile productivity apps that reached End of Life, see EOL and deprecated apps.
|MDX Toolkit||Deprecated support for the MDX Toolkit in favor of the Mobile App Management (MAM) SDK. During the transition period, you can use both MDX wrapped apps and MAM SDK developed apps.||March 2020||Target: March 2022||To continue managing your enterprise applications, use the MAM SDK.|
|Enrollment invitation setup in the Self-Help Portal||Deprecated support for users to generate enrollment invitations from the Self-Help Portal.||July 2021||July 2021||Contact your administrator to generate enrollment invitations in the Endpoint Management console.|
|High Security enrollment mode||Deprecated support for generating enrollment invitations with the High Security enrollment security mode.||July 2021||Target: Q3 2021||See Enrollment invitations for a list of supported enrollment security modes.|
|Enrollment invitation setup||Deprecated support for using a device IMEI, serial number, and UDID to create an enrollment invitation.||April 2021||July 2021||When you create an enrollment invitation, configure the available settings under Manage > Enrollment Invitations in the Endpoint Management console.|
|Certificate-based authentication signature algorithms (non-FIPS and weak ciphers)||Deprecated support for the following signature algorithms: SHA1withRSA, SHA224withRSA, SHA1withECDSA, SHA224withECDSA, SHA1withDSA, RIPEMD160withRSA, RIPEMD128withRSA, RIPEMD256withRSA.||May 2020||June 2021||When you create a CSR for a credential provider in the Endpoint Management console (Settings > Credential Providers > Certificate Signing Request), choose a stronger cipher.|
|Knox Mobile Enrollment (legacy DA)||Deprecated support for Knox Mobile Enrollment (KME) in the legacy Device Administrator mode on all Android versions.||May 4, 2021||Target: Q3 2021||Use KME to enroll in Android Enterprise mode. Android 8, 9, 10, 11 support Android Enterprise.|
|Citrix mobility apps and Workspace apps for Android 7.x and iOS 12.x||Deprecated support for the Android 7.x and iOS 12.x versions of Secure Hub, Secure Mail, Secure Web, and Citrix Workspace app.||April 2021||June 2021||Use, at a minimum, the current and prior version of each major operating system platform. Older devices remain enrolled. However, Citrix doesn’t test or support the legacy devices.|
|Derived credentials||Deprecated support for derived credentials and the Citrix Derived Credential Manager app.||March 25, 2021||Target: Q2 2021||See iOS for a list of authentication types supported for iOS.|
|Internet Explorer 11||Deprecated support of Internet Explorer use with the Endpoint Management console.||January 2021||January 2021||Use the latest version of these web browsers: Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari|
|RSA soft token support for Android||Deprecated support for the direct import of RSA soft tokens into Secure Hub for Android.||January 2021||February 2021||You can import the RSA soft token inside the RSA secure ID app available in Google Play. You can then use the token for Citrix Gateway authentication.|
|Android - Sony||Deprecated support for Android Sony devices and Sony-specific policies.||January 2021||Target: Q3 2021||Use Android Enterprise|
|Android - HTC||Deprecated support for Android HTC devices and HTC-specific policies.||January 2021||Target: Q3 2021||Use Android Enterprise|
|Gateway configuration checks in Endpoint Management Analyzer||Deprecated support for the Gateway configuration check option.||November 2020||November 2020||Use the Citrix Insight Services check in Analyzer to check your Citrix ADC configurations for Endpoint Management deployment readiness. See Endpoint Management Analyzer.|
|API sign in using local accounts||Administrators will no longer be able to sign in to the REST API using a local account.||October 2020||Administrators can log in using a Citrix Cloud account. See REST API.|
|APNs outgoing ports||Apple support for the APNs legacy binary protocol ends as of March 31, 2021. Apple recommends that you use the HTTP/2-based APNs provider API instead. As part of this change, we are deprecating support for ports 2195 and 2196, used to send APNs notifications to
||October 2020||Target: March 31, 2021||Use port 443 instead. See Network and firewall requirements.|
|Apps published for the legacy Device Administrator mode on Android Enterprise devices||We no longer deliver apps published for the legacy DA platform to devices enrolled in Android Enterprise.||October 2020||November 2020||For Android Enterprise devices, publish apps for the Android Enterprise platform. To continue to publish legacy DA apps to devices in DA mode, create a separate delivery group for those apps.|
|Samsung SEAMS container||Deprecated support for the Samsung SEAMS container.||June 2020||August 2020||Use the Samsung Knox Service Plugin (KSP) app for Android Enterprise. See Add the Knox service plug-in app.|
|Self-signed Secure Sockets Layer (SSL) certificates||Deprecated support for self-signed SSL certificates for all device platforms.||May 2020||Replace your existing self-signed certificate with a trusted SSL certificate from a well-known certificate authority (CA).|
|Citrix mobility apps and Workspace apps for Android 6.x and iOS 11.x||Deprecated support for the Android 6.x and iOS 11.x versions of Secure Hub, Secure Mail, Secure Web, and Citrix Workspace app.||April 2020||June 2020||Use, at a minimum, the current and prior version of each major operating system platform. Older devices remain enrolled. However, Citrix doesn’t test or support the legacy devices.|
|MDX Service||Deprecated support for the MDX Service in favor of the Mobile App Management (MAM) SDK. During the transition period, you can use both MDX wrapped apps and MAM SDK developed apps.||March 2020||Target: September 2021||To continue managing your enterprise applications, use the MAM SDK.|
|MDX: Alternative Gateway Server||Deprecated step-up authentication for iOS and Android devices.||March 2020||Target: September 2021||No alternative|
|MDX: Micro VPN (full tunnel mode)||Deprecated a full virtual private network (VPN) tunnel for iOS and Android devices.||March 2020||Target: September 2021||Use the MAM SDK Web SSO mode or create a per-app VPN policy with the Citrix SSO connection type.|
|MDX: PAC file support||Deprecated support for a Proxy Automatic Configuration (PAC) file with a full VPN tunnel deployment for iOS and Android devices.||March 2020||Target: September 2021||Use Citrix Gateway to connect through a proxy server for access to internal networks.|
|MDX shared device support||Deprecated shared device support for MDX apps.||March 2020||Target: June 2021 for new deployments. September 2021 for existing deployments using the feature.||For Android Enterprise, use shared devices enrolled as dedicated devices. For iOS, use Apple School Manager or GroundControl.|
|New Device Administrator enrollments for Android 10||Deprecated support for new enrollments or re-enrollments into the legacy Device Administrator mode on Android 10 devices. Already enrolled devices continue to work.||February 2020||September 2020||Enroll new Android 10+ devices into Android Enterprise.|
|Legacy Device Administrator mode for Android 10 devices||Google deprecated some Device Administrator APIs. Citrix doesn’t support Android 10 devices enrolled into Device Administrator mode as of the upgrade to Citrix Secure Hub that targets Android API level 29.||February 2020||November 2020||Migrate Android 10 devices to Android Enterprise.|
|MDX encryption||Deprecated MDX encryption and the MDX encryption feature in the Endpoint Management console.||October 2019||September 2020||Enable iOS or Android platform encryption using our Encryption Management feature with added compliance checking. Ensure you have tested and planned for migration off MDX encryption by July 2020.|
|Remote Support||Deprecated the Remote Support client.||January 2019||August 2020||No alternative|
|Secure Hub Network Extensions for iOS||Deprecated the Network Extension framework that allowed you to customize networking features for iOS devices. Secure Hub release 20.3.0.||October 2018||March 2020||No alternative|
|Android TouchDown||DigiCert stopped supporting Android TouchDown. Citrix removed the Android TouchDown platform page from the Exchange device policy.||July 2018||November 2020||Recommendation: Use Citrix Secure Mail.|
|Windows Mobile/CE||Deprecated support for Windows Mobile/CE devices.||April 2018||September 2020||Use Windows 10 Desktop and Laptop.|