This message was deleted.
# citrix-wem
s
This message was deleted.
r
I know in Assignment Targets, you can hit the built-in\Administrator group, but wondering if it could be done with other groups and with conditions instead.
r
Add a Condition matching and Active Directory Group. Then use that condition in the filter.
r
If I wanted to target local groups, though, what would I put in the Matching Result? For instance, if I wanted to target the local Administrators group, would I put BUILT-IN\Administrators?
r
Sorry Rich I missed the local acct part let me see
j
WMI query filter would probably do the job, but it's going to be messy. What's the scenario/outcome you are trying to achieve?
r
You know, I thought about WMI query, but I agree that it's going to be messy. For now, the scenario is that they want to default to having a session locked down using registry key actions assigned to everyone, but they they have the inverse of those lockdown reg keys as actions that they want to assign to users in the local Administrators group. Their business process of application installations/management on the persistent images is, they add the app owner to the local administrator's group and have them do their thing, then they take them out when they're done. They're moving over from Ivanti (AppSense) and they had that functionality in one of their nodes and wanted WEM to work the same way. I tried working with them to create AD groups that would allow the lockdowns to be lifted, but they're more...universal over the entire configuration set. We have it working with their AD Groups that they use for Citrix Admins and a few other Administrative AD groups, but we couldn't figure out the local administrators group. I figured that if WEM could analyze it for Assignment Targets, then it should be able to see it for conditions as well.
@James Kindon - I actually read through your blog about the dynamic tokens and strings a few times hoping that it would spark some imagination on figuring it out, but I couldn't see anything.
j
hrmmm, to be fair, I had absolutely no idea you could target local groups as primary assignment targets - that one is new to me I feel like the smartest way (customer might not think so, but security probably would), would be to have an AD group specifically for this, and then that AD group (or groups) nested into the appropriate local group on the endpoint That way you have auditing, you have filtering, and you still have the outcome, just no need to touch "local groups" outside of initial setup?
I've asked the WEM folk as well just to see if there is a direct answer on your scenario though
r
Well, with the assignment targets, it's just the one built-in Administrators group. Am I not understanding that correctly? I assumed that meant users in the local administrators group.
And I agree and we talked through that scenario, however, they have one configuration set managing a bunch of machines and putting the user in an AD group would give that user elevated access to all machines and allow them to use the sessions without being locked down.
Let me ask you this - we tried to create a unique group for every computer called SA_%computername% and put that group in the respective local admins group. We tried creating a condition for that group and it didn't work. Thinking about your article on dynamic tokens, I believe you mentioned that WEM doesn't expand the variable and would read it literal. If I made the condition using the ##computername## syntax, do you think that would work?
j
Well, with the assignment targets, it's just the one built-in Administrators group. Am I not understanding that correctly? I assumed that meant users in the local administrators group.
hrmm, doesn't this just resolve to the domain equivalent?
I don't believe its supported for dynamic tokens on Group Match https://docs.citrix.com/en-us/workspace-environment-management/current-release/reference/dynamic-tokens#supportability-matrix-for-filter-conditions Would a logic of a filter rule containing AD Group Match (
Domain\SA_Server1
) and ComputerName Match (
Domain\Server1
) do the job?
You might even be able to simplify the number of conditions as the AD Group Match is OR capable - so you could have a master AD Group Match Condition, and a per server condition, and then a filter rule per server - not sure which path is the least evil
r
Yea I got no answer yet from engineering hopefully overnight
r
Condition rules with static group names would work, but it's not very sustainable. The list of conditions would always have to be manipulated whenever a new machine comes online or an old machine is taken offline. Was looking for a more dynamic approach. That's why I thought the local group would work. Honestly, in the legacy console, where they have the tabs for lockdown policies (not in front of a computer so I don't recall the exact name of the section), they have a checkbox to process settings and another checkbox to exclude administrators for the lockdowns. With the web console, that section isn't there and I've been replicating those configs with the GPOs, but there's no way to exclude anyone, which is why I went to registry actions so I can filter on the assignment. Just seems overly complex to get a result that I would think is a common request.
j
You should have like-for-like between web and legacy console in that regard?
I don't want to speak out of turn but I think the WEM teams approach on this is more looking at privilege elevation mechanisms and avoiding admin access altogether, there are tools out there which would likely hit your need in a more secure focused fashion - CyberArc etc are specifically designed for this sort of "temporary access" style control
r
I was talking about the Policies and Profiles tab:
In there, I can do a bunch of lockdowns and exclude Administrators.
j
Oh I see what you mean, yeah I don't think those have been ported over yet (you can still configure them in the old console if you want too, including the exemption). I tend to them via the reg keys as required https://docs.citrix.com/en-us/workspace-environment-management/service/reference/environmental-settings-registry-values and https://github.com/JamesKindon/WEMHydrationKit/tree/master/Environmental%20Settings%20Reg%20Module
s
@richminichiello if you'd like, you can create the RFE for the local group support in the filter/condition and we will evaluate it. thanks!
And I agree with James that seems the privilege elevation is a possible solution.