Citrix Workspace

Resource filtering using delivery group access policies

You can configure Access Policies for delivery groups based on Workspace URLs. You can control end users’ access to resources based on the Workspace URL that they’re using. To configure an Access Policy for delivery groups based on Workspace URLs, you need to apply the following SmartAccess filters. The filter values are also sent as SmartAccess tags to the DaaS service. It is applicable in both the scenarios:

  • while listing apps and desktops published by DaaS
  • while launching an app or desktop
Filter Value Description
Citrix.Workspace.UsingDomain example.cloud.com Allows filtering of delivery group resources by Workspace URL. The value is the fully qualified domain name of the Workspace URL.
Citrix-Via-Workspace True Indicates that the end user is using Citrix Workspace, rather than an on-premises StoreFront deployment.

Note:

The SmartAccess tags are sent automatically. If Adaptive Access is enabled then DaaS treats requests from Workspace as being through Citrix Gateway so you must add criteria to the Citrix Gateway Connections rule. If Adaptive Access is disabled then you must add criteria to the Non-Citrix Gateway Connections rule.

DaaS filter

This allows filtering of apps and desktops within a delivery group, based on the following criteria:

  • the workspace URL that is being used by the end users
  • whether users have signed into Workspace or StoreFront

For more information on configuring an access policy for a delivery group, see Manage delivery groups.

Create an access policy rule for multiple URL workflows

  1. To create an access policy rule, go to Edit Delivery Group > Access Policy, and click Add. Access policies can only be changed once a delivery group has been created.
  2. Add a descriptive policy name.
  3. Select one of the following criteria for your filters:
    • Match any: The access policy allows access if any of the given filter criteria matches the incoming request.
    • Match all: The access policy allows access only if all of the given filter criteria match the incoming request.
  4. Add values for the **Citrix.Workspace.UsingDomain** and **Citrix-Via-Workspace** filters.

For example, in the following scenario the use of Match any filter means that this rule allows access from either a user using , or a user connecting from an internal network (as per the Network Location configuration). For more information, see [Adaptive access based on user’s network location](/en-us/citrix-daas/manage-deployment/adaptive-access/adaptive-access-based-on-users-network-location.html).

 Match any filter

Changing the filter to Match all would mean that the rule only allows access to a user using <wspmultiurlmain.cloud.com> from an internal network.

 Match all filters

Once you confirm the changes, the new policy appears on the Access Policy page. For more information, see Manage Delivery Groups

 DaaS access policy

Resource filtering using delivery group access policies