PoC Guide: POC Guide Citrix Analytics for Security

Overview

Citrix Analytics for Security continuously assesses the behavior of Citrix Virtual Apps and Desktops users and Citrix Workspace users and applies actions to protect sensitive corporate information. The aggregation and correlation of data across networks, virtualized applications and desktops, and content collaboration tools enables the generation of valuable insights and more focused actions to address user security threats. More information on Citrix Analytics for Security can be foundhereand videos demonstrating the Citrix Analytics for Security can be foundhere.

Citrix Security Analytics

Pre-requistes

On-premises Citrix Virtual Apps and Desktops Sites

  • Delivery Controller 7.16 or later
  • Director 7.16 or later
  • Citrix Cloud account with Citrix Analytics entitlements
  • If you are using StoreFront, StoreFront 1906 or later is required

On-premises Citrix Gateway

  • Subscribe to Citrix ADM service offered on Citrix Cloud. To learn how to get started with Citrix ADM service, see让明星ted.
  • Review thesystem requirementsand ensure that the requirements are met.

Deployment Steps

Citrix Virtual Apps and Desktops on-premises using Workspace

Connecting to on-premises StoreFront

Log into Citrix Cloud and clickManageunder the Analytics console from your StoreFront server

Citrix Security Analytics

ClickManage

Citrix Security Analytics

Clicksettingsand then clickdata sources

Citrix Security Analytics

Click the ellipses next to Virtual Apps and Desktops and selectConnect to StoreFront Deployment

Citrix Security Analytics

Clickdownload file

Citrix Security Analytics

Open powershell and run the following command: Import-STFCasConfiguration -Path “configuration file path”

Citrix Security Analytics

You can see that the StoreFront database has been added

Citrix Security Analytics

Connecting to on-premises sites using Workspace

Site needs to be added to Citrix Workspace usingSite Aggregationbeforehand

Log into Citrix Cloud from one of your delivery controllers

Citrix Security Analytics

Selectmanageunder Security Analytics

Citrix Security Analytics

SelectData sourcesunderSettings

Citrix Security Analytics

clickPolicy Incompleteunder Virtual Apps and Desktops

Citrix Security Analytics

click the drop down under your site name and then clickcontinue

Citrix Security Analytics

Selectdownload agent

Citrix Security Analytics

Complete the installation

Citrix Security Analytics

clickConnect to Installed Agent. This process can take a few minutes.

Citrix Security Analytics

Enter the information for your site administrator

Citrix Security Analytics

Enter your Director’s URL

Citrix Security Analytics

Click done after reviewing your information

Citrix Security Analytics

Citrix Gateway on-premises using Citrix ADM service

Gateway data sources added to Citrix ADM

Gateway data sources not added to Citrix ADM

Watch the onboarding video

Risk Indicators

User risk indicators are user activities that look suspicious or can pose a security threat to your organization. User risk indicators span across all Citrix products used in your deployment. The indicators are based on user behavior and are triggered where the user’s behavior deviates from the normal. User risk indicators help in determining the user’s risk score.

ClickCustom Risk Indicators and Policiesunder Settings

Citrix Security Analytics

Turn on the risk indicators by clicking the toggle. Then clickCreate Indicator

Citrix Security Analytics

Here you can create custom indicators

Citrix Security Analytics

Clickpolicies. A policy is a set of conditions that must be met to apply an action. A policy contains one or more conditions and a single action. You can create a policy with multiple conditions and one action that can be applied to a user’s account.

Citrix Security Analytics

ClickCreate policy

Citrix Security Analytics

Select the condition and then the action you want

Citrix Security Analytics

Make sure that the policy is enabled and clickCreate policy

Citrix Security Analytics

Dashboards

The user dashboard provides visibility into user-behavior patterns across an organization. Using this data, you can proactively monitor, detect, and flag behavior that fall outside the norm, such as phishing or ransomware attacks. click a specific user

Citrix Security Analytics

This dashboard provides a risk timeline of what the user is doing and what source it is coming from.

Citrix Security Analytics

clickAccess assurance

Citrix Security Analytics

The Access Assurance Location dashboard provides an overview of the locations from where your users are accessing their Citrix Virtual Apps and Desktops environment.

Citrix Security Analytics

PoC Guide: POC Guide Citrix Analytics for Security