
JPS.92699 (Customer) asked a question.
We're looking to deploy Okta Verify for Windows and implement device management attestation through Okta CA-issued certs, pushed to devices via Intune and SCEP. After deploying it, we plan to use it to limit unmanaged device access to our corporate apps, like M365, etc. The tricky part of this is with our non-persistent Citrix VDIs. My understanding of the non-persistent VDIs is that, even if Okta Verify for Windows was installed on them, the app configuration would be wiped as soon as the VDI was torn down after the user ended his/her session, requiring the user to re-enroll that factor every time. Also, our Citrix VDIs are not managed by Intune. How have others worked out conditional access policies requiring device management on non-persistent VDIs, while using the Okta CA for management attestation? My initial thought is to have Citrix traffic egress from a dedicated IP address, separate from the rest of the network traffic, and then exclude that address from the device management requirement.

Hi, @JPS.92699 (Customer)
Thank you for posting on our Community page!
Sounds like you are on the right track with identifying a workaround, as there is no way to "fix" them wiping an entire device of all device specific config. Therefore a means to specifically identify these machines so that they may be directed to alternate policies that do not require device management / registration would be the way to go. Network zones configured for those VDI machines seems like a reasonable workaround to accomplish that as well.
I will leave this question open so that others can contribute with their solutions.
Thank you for reaching out to our Community and have a great day!
_____________________________________________________________________________
Community members help others by clicking Like or Select as Best on responses. Try it today.
_____________________________________________________________________________
Follow us at OktaSupport
_____________________________________________________________________________