PoC Guide: POC Guide Citrix Analytics for Security

Overview

Citrix Analytics for Security continuously assesses the behavior of Citrix Virtual Apps and Desktops users and Citrix Workspace users and applies actions to protect sensitive corporate information. The aggregation and correlation of data across networks, virtualized applications and desktops, and content collaboration tools enables the generation of valuable insights and more focused actions to address user security threats. More information on Citrix Analytics for Security can be found here and videos demonstrating the Citrix Analytics for Security can be found here.

Citrix Security Analytics

Pre-requistes

On-premises Citrix Virtual Apps and Desktops Sites

  • Delivery Controller 7.16 or later
  • Director 7.16 or later
  • Citrix Cloud account with Citrix Analytics entitlements
  • If you are using StoreFront, StoreFront 1906 or later is required

On-premises Citrix Gateway

  • Subscribe to Citrix ADM service offered on Citrix Cloud. To learn how to get started with Citrix ADM service, see Getting Started.
  • Review the system requirements and ensure that the requirements are met.

Deployment Steps

Citrix Virtual Apps and Desktops on-premises using Workspace

Connecting to on-premises StoreFront

Log into Citrix Cloud and click Manage under the Analytics console from your StoreFront server

Citrix Security Analytics

Click Manage

Citrix Security Analytics

Click settings and then click data sources

Citrix Security Analytics

Click the ellipses next to Virtual Apps and Desktops and select Connect to StoreFront Deployment

Citrix Security Analytics

Click download file

Citrix Security Analytics

Open powershell and run the following command: Import-STFCasConfiguration -Path “configuration file path”

Citrix Security Analytics

You can see that the StoreFront database has been added

Citrix Security Analytics

Connecting to on-premises sites using Workspace

Site needs to be added to Citrix Workspace using Site Aggregation beforehand

Log into Citrix Cloud from one of your delivery controllers

Citrix Security Analytics

Select manage under Security Analytics

Citrix Security Analytics

Select Data sources under Settings

Citrix Security Analytics

click Policy Incomplete under Virtual Apps and Desktops

Citrix Security Analytics

click the drop down under your site name and then click continue

Citrix Security Analytics

Select download agent

Citrix Security Analytics

Complete the installation

Citrix Security Analytics

click Connect to Installed Agent. This process can take a few minutes.

Citrix Security Analytics

Enter the information for your site administrator

Citrix Security Analytics

Enter your Director’s URL

Citrix Security Analytics

Click done after reviewing your information

Citrix Security Analytics

Citrix Gateway on-premises using Citrix ADM service

Gateway data sources added to Citrix ADM

Gateway data sources not added to Citrix ADM

Watch the onboarding video

Risk Indicators

User risk indicators are user activities that look suspicious or can pose a security threat to your organization. User risk indicators span across all Citrix products used in your deployment. The indicators are based on user behavior and are triggered where the user’s behavior deviates from the normal. User risk indicators help in determining the user’s risk score.

Click Custom Risk Indicators and Policies under Settings

Citrix Security Analytics

Turn on the risk indicators by clicking the toggle. Then click Create Indicator

Citrix Security Analytics

Here you can create custom indicators

Citrix Security Analytics

Click policies. A policy is a set of conditions that must be met to apply an action. A policy contains one or more conditions and a single action. You can create a policy with multiple conditions and one action that can be applied to a user’s account.

Citrix Security Analytics

Click Create policy

Citrix Security Analytics

Select the condition and then the action you want

Citrix Security Analytics

Make sure that the policy is enabled and click Create policy

Citrix Security Analytics

Dashboards

The user dashboard provides visibility into user-behavior patterns across an organization. Using this data, you can proactively monitor, detect, and flag behavior that fall outside the norm, such as phishing or ransomware attacks. click a specific user

Citrix Security Analytics

This dashboard provides a risk timeline of what the user is doing and what source it is coming from.

Citrix Security Analytics

click Access assurance

Citrix Security Analytics

The Access Assurance Location dashboard provides an overview of the locations from where your users are accessing their Citrix Virtual Apps and Desktops environment.

Citrix Security Analytics

PoC Guide: POC Guide Citrix Analytics for Security