Citrix Secure Private Access™

Access mode-based policy enforcement

Access mode-based policy enforcement lets administrators restrict how a user connects to an application. The connection can be through a browser-based client or the Citrix Secure Access client. Previously, Secure Private Access had no way to restrict access based on which a client initiates the session. Access mode adds that capability.

For example, administrators can configure that SSH and RDP applications are only reachable through a browser, such as Chrome Enterprise Premium, and not tunneled through the Citrix Secure Access client. This ensures that browser-based security controls always apply.

Note:

Access mode is a restricting condition only. It can narrow down the access but cannot grant access on its own. All other conditions in the policy are still evaluated.

How it works

Access mode is configured in the Secure Private Access admin console and can be added to a rule in any of the three policy types.

The following figure displays a sample acess policy rule condition.

Access mode condition

End-user experience

Based on the access mode, application enumeration and launch are either allowed or restricted.

  • Matching client — The application is enumerated and launches normally.
  • Non-matching client — The application is not shown in the app list during enumeration, and a launch attempt is blocked. The user is sent to the standard access-denied page. No new denial message is introduced.
  • Undeterminable session — When the access mode cannot be determined (for example, some mobile Secure Access sessions), the access mode condition is skipped and the session is unaffected. All other conditions still apply.
Access mode-based policy enforcement