Use this page to define a device rule to protect devices mapped to shared Citrix Virtual Apps and Desktops desktop sessions. Citrix device rules can block, monitor, or set devices to read-only.
Category | Option | Definition |
|---|---|---|
Rule name | Enter a unique name for the rule. This field is required. | |
Rule options | Description | Click Edit to open the description text box. The maximum description length is 2000 characters. The character counter in the lower left of the window shows the number of characters still available. This field is optional. |
State | Select Enabled or Disabled from the drop-down list. You can also change this parameter on the DLP Rule Set page by selecting a rule or rules and selecting Actions → Change State. The default is Disabled. | |
Severity | A relative measure of the gravity of violating this rule. The default is Warning. The color code that also appears in the DLP Incident Manager is displayed next to the field | |
Enforce On | Selects the Trellix DLP product enforcing the rule. Citrix Virtual Apps and Desktops device rules are enforced on Trellix DLP Endpoint for Windows only. | |
Condition tab
| End-User | Select a user group from the drop-down list. Using the + icon, you can select multiple groups using AND/OR logic. You can exclude groups using the Exceptions tab. Include at least one group before excluding any groups. |
Resources | Select one or more Citrix resources you want the rule to protect. | |
Exceptions tab
Excluded Users is the only option for Citrix device rules. | Name | Enter a unique name for the exception. This field is required. |
Description | Optional descriptive text. | |
State | Select Enabled or Disabled from the drop-down list. The exception state is independent from the rule state. | |
End-User | Select a user group to exclude from the rule. | |
Reaction tab | Action | The only option for Citrix device rules is Block. No selection is required. |