Policy conditions

User and user groups

User conditions define which users, groups, or identity attributes the access policy applies to. These rules let administrators include or exclude specific identities when determining access to an application.

User conditions consist of three primary components:

Match Type: This drop-down list controls how the list of selected identities is evaluated.

  • Matches any of:
    • Use this when the policy must apply only to the selected users or groups.
    • The condition is satisfied if at least one identity in your list matches.
    • Works like an IN filter.
  • Does not match any
    • Use this to apply the policy to everyone except the selected users or groups.
    • The condition is satisfied only if none of your selected identities match.
    • Works like a NOT IN filter.

Policy condition

Domain Selector:

The Domain drop-down list filters identities by directory or identity source.

  • Identity Selector (user emails, group emails) - This field allows selecting one or more identities, including user emails and group emails.

Network Location

The Network Location Service (NLS) is a policy condition that allows you to restrict access based on the user’s network location. An admin can configure the access policy based on the location from where the user is accessing the application. The location can be the country from where the user is accessing the application or the user’s network location. The network location is defined using an IP address range or subnet addresses.

To configure an access policy based on the location, do the following:

  1. Under Conditions section, click Add condition.
  2. Select Network location.

    Create network location

    If you have configured multiple network locations, then select one of the following as per your requirement.

    • Matches any of – The network locations match any of the network locations configured in the database.
    • Does not match any – The network locations do not match with the network locations configured in the database.

    Note:

    For Network location, you can select an existing network location or create a network location. To create a new network location, click Create network location.

    • Ensure that you have enabled Adaptive Access from Citrix Cloud > Citrix Workspace > Access > Adaptive Access. If not, you cannot add the location tags. For details, see Enable Adaptive Access.

    You can also create a network location from the Citrix Cloud console. For details, see Citrix Cloud network location configuration.

  3. Complete the policy configuration.
Policy conditions