App Protection

App Protection is a feature for the Citrix Workspace app that provides enhanced security when using Citrix Virtual Apps and Desktops published resources. App Protection is supported for on-premises Citrix Virtual Apps and Desktops deployments, and Citrix DaaS (formerly Citrix Virtual Apps and Desktops service) with StoreFront and Workspace. It means that App Protection is supported on all cloud environments, on-premises environments, and hybrid environments. App Protection is also supported when you are connecting to StoreFront or Workspace via ADC Gateway.

Two policies provide anti-keylogging and anti-screen-capturing capabilities for a Citrix HDX session. The policies along with a minimum of Citrix Workspace app 2203.1 LTSR for Windows, Citrix Workspace app 2001 for Mac, or Citrix Workspace app 2108 for Linux can help protect data from keyloggers and screen scrapers.

When you enable anti-keylogging:

  • A keylogger sees encrypted keystrokes.
  • This feature is active only when a protected window is in focus.

Anti-screen-capturing when enabled:

  • On Windows OS and macOS, when you capture a screen, only the content of the protected window is blank. This feature is active when a protected window isn’t minimized. On the Linux OS, the entire capture is blank. This feature is active whether a protected window is minimized or not.
  • When using the Print Screen button in Windows OS to take screenshots, the data is not copied to the clipboard. To take screenshots using the Print Screen button, minimize any protected apps.

You can configure the policies through PowerShell and through Web Studio. For more information, see Configure App Protection for virtual apps and desktops.

After buying this feature, make sure you enable the App Protection license.

Disclaimer:

App Protection policies work by filtering access to required functions of the underlying operating system (specific API calls required to capture screens or keyboard presses). Doing so means that App Protection policies can provide protection even against custom and purpose-built hacker tools. However, as operating systems evolve, new ways of capturing screens and logging keys might emerge. While we continue to identify and address them, we can’t guarantee full protection in specific configurations and deployments.

Citrix App Protection policies work effectively with underlying operating system components, including ICA files. Citrix might not provide support if intentional tampering or modification of the underlying components is detected, to provide the integrity of policies applied.

Check if App Protection is installed

Citrix Workspace app for Windows

Starting with Citrix Workspace app version 2212, App Protection is installed by default. However, the component might be in an active or dormant state depending on whether the user selected the Start App Protection after installation checkbox.

  • For Citrix Workspace app versions before 2311:

    Start App Protection after installation - Citrix Workspace app versions before 2311

  • From Citrix Workspace app version 2311 onwards:

    Start App Protection after installation - Citrix Workspace app version 2311 onwards

For Citrix Workspace app versions before 2212, App Protection is installed and be in the active state only if you select the Enable App Protection checkbox while installing Citrix Workspace app.

Enable App Protection after installation

App Protection can either be in the STOPPED state or RUNNING state. To check the status of the service, do one of the following steps:

  • For Citrix Workspace app version 2206 or later, run the following command:

     sc query appprotectionsvc
     <!--NeedCopy-->
    

    App Protection status 2206 or later

  • For Citrix Workspace app versions before 2206, run the following command:

     sc query entryprotectsvc
     <!--NeedCopy-->
    

    App Protection status before 2206

Note:

In Citrix Workspace app versions before 2212, if you didn’t select the Enable App Protection checkbox while installing Citrix Workspace app and run the preceding command to check the status, then it displays the following error message:

App Protection status check error message

App Protection behavior on different environments

The behavior of App Protection depends on how you access the resources that are configured with App Protection policies. These resources include Virtual Apps and Desktops, internal web apps, and SaaS apps. You can access these resources using a supported native Citrix Workspace app client or a web browser. App Protection performs varyingly on different environments:

  • Unsupported Citrix Receivers or Citrix Workspace apps - The resources that are configured with App Protection policies are not available.
  • Supported Citrix Workspace app versions - The resources that are configured with App Protection policies are available and launches properly.
  • Hybrid launch using Workspace store URL - The resources that are configured with App Protection policies are always available. To successfully launch the resources on a web browser using the Workspace store URL, see App Protection for hybrid launch for Workspace.
  • Hybrid launch using StoreFront store URL - The resources that are configured with App Protection policies are not available if the StoreFront customization is not deployed. To successfully launch the resources on a web browser using the StoreFront store URL, see App Protection for hybrid launch for StoreFront.

Protection is applied under the following conditions:

  • Anti-screen capture – For Citrix Workspace app for Windows and Citrix Workspace app for Mac, it is enabled if any protected window is visible on the screen. To disable protection, minimize all protected windows. For Citrix Workspace app for Linux, it is enabled if any protected window is active. To disable protection, close all protected windows.
  • Anti-keylogging – Enabled if a protected window is in focus. To disable protection, change focus to another window.

What does App Protection protect?

App Protection protects the following Citrix windows:

  • Citrix sign in windows

    Citrix sign in window - protected

  • Citrix Workspace app HDX session windows (For example, managed desktop)

    Citrix Virtual Apps and Desktops Standard for Azure window - protected

  • Self-Service (Store) windows

    Citrix Self-Service Store window - protected

  • Web and SaaS apps

    • Citrix Workspace app for Windows and Citrix Workspace app for Mac - Web and SaaS apps open in the Citrix Enterprise Browser. If the apps are configured to have the App Protection policies through the Citrix Secure Private Access, then App Protection is applied on a per tab basis.

      App Protection for Web and SaaS apps

    • Citrix Workspace app for Linux - Citrix Enterprise Browser is not supported.

What doesn’t App Protection protect?

  • The following items under the Citrix Workspace apps icon in the navigation bar:

    • Connections Center
    • All links under Advanced Preferences
    • Personalize
    • Check for Updates
    • Sign Out
  • If you choose to protect a virtual desktop with anti-screen-capturing, users can still screen share from apps within the virtual desktop. However, for the apps outside of the virtual desktop, you can’t take screenshots, or record the virtual desktop.

Limitations

The following limitations exist by design:

  • App Protection enabled virtual apps and desktops are blocked from launching when accessed within RDP sessions.
  • App Protection is not supported in double-hop and multiple-hop scenarios.
  • App Protection is not supported if you’re on an unsupported version of the Citrix Workspace app or Citrix Receiver. In that case, resources are hidden.
  • When the App Protection features are applied to virtual apps and desktops, outgoing screen sharing might be affected if optimization is used.
  • Citrix Workspace app with App Protection might not be compatible with some other security solutions or apps using similar underlying technology.
  • App Protection is not supported when you launch resources from within the Citrix Secure Browser, or with Remote Browser Isolation.
  • In Citrix Workspace app for Linux, you’re unable to use snap applications when App Protection is installed.

Contextual App Protection

Contextual App Protection provides the granular flexibility to apply the App Protection policies conditionally for a subset of users - based on users, their device, and the network posture. For more information, see the following articles:

App Protection for hybrid launch

Hybrid launch of Citrix Virtual Apps and Desktops is when you log in to Citrix Workspace app through the browser (Citrix Workspace for Web), and use the applications through the native Citrix Workspace app. The term hybrid is the result of users applying the combination Citrix Workspace app for Web and the native Citrix Workspace app to connect and use the resources. App Protection supports hybrid launch in Workspace and StoreFront. For more information, see the following articles:

App Protection