deviceTRUST

Integration of deviceTRUST with Citrix Workspace app for ChromeOS

Starting with version 2511, Citrix Workspace app for ChromeOS supports deviceTRUST integration, enhancing security through continuous device posture checks within sessions. This integration ensures only compliant ChromeOS devices can access Citrix Virtual Apps and Desktops.

About the feature

deviceTRUST provides continuous device posture monitoring and assessment capabilities for ChromeOS devices accessing Citrix environments. The integration uses Google Chrome Enterprise APIs to collect device information and enforce security policies based on device compliance status.

Note:

For more information about deviceTRUST, see deviceTRUST Platform.

Supported device properties

The following device properties (signals) are available for ChromeOS platform configuration in the deviceTRUST console:

ChromeOS properties
  • Asset ID - Administrator-assigned asset identifier
  • Directory Device ID - Unique identifier for the device
  • Location - Administrator-annotated device location
Hardware properties
  • BIOS Serial Number - Device BIOS serial number
  • CPU - CPU model name
  • CPU Count - Number of CPU cores
Device name
  • Name - Device host name
Operating system properties
  • Name - Operating system name (ChromeOS)
  • Platform - OS architecture
  • Type - Client device type
  • Version - ChromeOS version
User properties
  • Name - Email address of the user logged into the Chrome device
  • SID - Unique identifier for the user account

Enterprise API requirements

deviceTRUST uses Google Chrome Enterprise APIs that are only available to managed, force-installed Citrix Workspace app instances. The following properties require force installation:

ChromeOS properties (force install required)
  • Asset ID
  • Directory Device ID
  • Location
Hardware properties (force install required)
  • BIOS Serial Number
Device name (force install required)
  • Name

Additional device properties

Starting with version 2607, Citrix Workspace app for ChromeOS adds on new properties support.

Display
  • Count: No of display units connected to device
  • BPP: Color detail per pixel (color depth)
  • DPI: Pixel density; sharpness of the display
  • Height: Vertical pixel or physical size of the screen
  • Width: Horizontal pixel or physical size of the screen
  • Monitor External: Any external monitor connected to device

Note:

This is a real-time property that is updated whenever there is any any external monitor is attached or detached.

Location
  • Position: The reported geographic location (latitude, longitude)
  • Accuracy: Value indicating how precise the position

Note:

This is a real-time property that is updated whenever there is any change in the location.

Input
  • Keyboard: Indicates whether the keyboard is connected in the device
  • Mouse: Indicates whether the mouse is connected to the device
  • Pen: Indicates whether the device has pen connected
  • Touch: Indicates whether the device supports touch functionality
Power
  • AC: Indicates whether power adapter is connected to device
  • Battery: Indicates battery level (Critical/ High/ Medium/ Low)
Region
  • Locale: Regional settings that define formats for language
  • Language: The language used for text and UI Timezone Offset
Session properties
  • Idle Period: Indicates the time interval for which there is no user interaction with Citrix session. The interval span is set by admins through device trust console

Configuration in Google Admin Console

To configure device properties in the Google Admin Console:

  1. Sign in to the Google Admin Console.
  2. Navigate to Chrome > Devices.
  3. Select the device whose properties you want to set or view.
  4. Edit the Asset ID or Location property in the Custom fields section.
  5. View the Directory Device ID and BIOS Serial Number properties in the Basic Info section.
  6. Click Save to apply changes.

Benefits

This integration provides:

  • Continuous security monitoring - Real-time device posture assessment during active sessions
  • Policy enforcement - Automated responses based on device compliance status
  • Enhanced visibility - Comprehensive device information for security administrators
  • Seamless user experience - Transparent security checks without user intervention

Limitations

The following properties are not available for ChromeOS devices due to API limitations:

  • Hardware Model property
  • Hardware Vendor property
deviceTRUST