Citrix Secure Private Access™ Hybrid Deployment

Browser policies

Citrix Secure Private Access supports security policies that are delivered to and enforced by the Citrix Secure Access browser extension for Google Chrome Enterprise Premium (CEP). You can configure these policies from the Secure Private Access admin console (Policies > Browser policies). Administrators can add policies based on context and assign priority order for evaluation.

Supported deployments:

Browser policies are supported for both hybrid and service-based Secure Private Access deployments with Chrome Enterprise Premium (CEP).

Policy evaluation:

Browser policies are evaluated using the following rules:

  • Policies are evaluated in the priority order, where the lowest number indicates the highest priority.
  • The first policy that matches the current user’s conditions is applied.
  • If no policy matches, no browser security controls are enforced.
  • User identity is determined from the authenticated session established through the CEP Partner Connector. The identity in the request payload is not used for evaluation.

Verify browser policy enforcement:

To confirm that anti-keylogging policies are delivered and enforced:

  1. Sign in to a CEP-managed endpoint where a browser policy is expected to apply.
  2. Open a web application published through Secure Private Access.
  3. Verify that the Citrix native agent indicator appears, confirming that anti-keylogging is active.
  4. If the policy is not applied, check the following:

    • The browser extension is installed and enabled.
    • The Citrix native agent is installed on the endpoint.
    • The CEP Partner Connector is operational.
    • The user is a member of a group matched to a configured policy.
    • For hybrid deployments, ensure that the Secure Private Access plug-in is communicating with Citrix Cloud and that configuration synchronization is current.

Configure a browser policy in the Secure Private Access admin console:

  1. Log in to the Secure Private Access admin console.
  2. Go to Policies > Browser Policies.
  3. Click Create browser policy and then select the required setting.

    Select the browser policy setting

  4. Click Next.
  5. Choose a condition for the policy.
  6. Click Next.
  7. Enter a policy name and a brief description.
  8. Click Save.

Modify the browser policy priority:

You can change browser policy priority from the Browser Policy page. Lower numbers indicate higher priority. After you change a policy’s priority, the change takes effect the next time the Citrix Secure Access browser extension requests a policy update from the Secure Private Access service.

Note:

If multiple policies match a user, the policy with the highest priority (lowest number) is applied. Only one policy is active per user at any given time.

Browser policy priority

Edit a browser policy:

  1. Navigate to Secure Private Access > Policies > Browser Policies.
  2. Click the edit icon for the policy you want to modify.
  3. Modify the policy settings.
  4. Click Save.

Delete a browser policy:

  1. Navigate to Secure Private Access > Policies > Browser Policies.
  2. Click the delete icon for the policy you want to remove.
  3. Click Delete and confirm the action.

Note:

Deleting a policy does not immediately stop enforcement on user endpoints. The change takes effect when the browser extension next requests a policy update.

Anti-keylogging with Citrix Secure Access

Cybercriminals use malicious software such as keyloggers to steal sensitive information, including passwords, credit card numbers, and confidential company data.

The Citrix Secure Access browser extension for Chrome Enterprise Premium (CEP) supports anti-keylogging to help protect your data. This feature scrambles keystrokes so that if a malicious program attempts to capture typed input, it records only unreadable characters while the actual text is securely delivered to your work applications.

Prerequisites:

Ensure that the following prerequisites are met before enabling anti-keylogging:

  • CWA version 2603 and later is installed.
  • Integration between Citrix Secure Access and Chrome Enterprise Premium (CEP) is complete.

Configure the anti-keylogging policy:

  1. Log in to the Secure Private Access admin console.
  2. Go to Policies > Browser Policies, and then click Create browser policy.
  3. Select Anti-keylogging, and then click the edit icon to enable it.

    Anti-keylogging policy

  4. Click Next.
  5. Choose a condition for the policy.

    Anti-keylogging policy condition

  6. Click Next.
  7. Enter a policy name and a brief description.

    Anti-keylogging policy name

  8. Click Save.
Browser policies