Mobile Device Support

In IGEL OS 12, you can use the Mobile Device Access app to access files on supported Android, iOS, and iPadOS devices connected by USB. The app integrates mobile-device storage with the Thunar file manager and can make the storage available in supported virtual desktop infrastructure (VDI) sessions. In this article, you can find how to configure the app and how to use it to access mobile devices from the endpoint.


Requirements

  • The Mobile Device Support app is imported to your Universal Management Suite (UMS). For details on app import, see How to Import IGEL OS Apps from the IGEL App Portal.

  • IGEL OS 12.10.0 or higher

  • The USB cable used with the mobile device supports data transfer. A charging-only cable cannot provide file access.

  • The mobile device is unlocked and the user authorizes access on the mobile device.

  • If USB Access Control is enabled, its rules permit the mobile device.

  • For access in a virtual session, client drive mapping is enabled for the applicable session.

Configure the App

Assign the Mobile Device Support App to Devices

  1. Assign the imported app to the required device or device directory.

  2. Apply the changes to the device.

  3. Verify that the app and its dependencies are installed on the device.

No Profile Configuration Required

The Mobile Device Support app does not have any configurable parameters or app profile settings. Assigning and deploying the app installs the required framework components, including GVFS backends, udisks2, GVFS volume daemons, and the Thunar file manager integration.

Depending on your environment, you might need to configure settings that control USB access, file permissions, and session redirection in an IGEL OS Base System profile. These are explained below.

Configure USB Access

By default, USB Access Control is inactive. You only need to configure it only when your security policy restricts USB devices.

USB Access Control governs access to the device at the operating-system level. It is separate from USB redirection and client drive mapping in remote sessions. For details, see USB Access Control in IGEL OS 12.

If USB Access Control is enabled and Default rule is set to Deny, create an appropriate allow rule for the mobile device:

  1. In the profile configurator go to Devices > USB Access Control.

  2. Review the default rule and existing class or device rules.

  3. If required, add an Allow rule for the mobile device.

  4. Set the required permission:

    • Read only

    • Read/Write

  5. Save and apply the configuration.

Enabling USB Access Control with a default rule of Deny can block devices required by users. Configure USB Access Control only when required by your security policy and test all affected peripherals before deployment.

Configure Mobile Device Redirection

Configure these settings only when files from the mobile device must be available inside a supported virtual session.

  1. In the profile configurator, go to Devices > Storage Devices > Storage Hotplug.

  2. Enable Enable dynamic client drive mapping.

  3. Configure Default permission according to your security requirements:

    • Read only

    • Read/Write

  4. Save and apply the configuration.

The Enable dynamic client drive mapping setting controls drive creation in supported sessions. It does not determine whether Thunar can access the mobile device locally. For more information, see Storage Hotplug in IGEL OS 12.

To configure the use in the session:

  1. In the Citrix Workspace app, Omnissa Horizon Client, or IGEL for Windows configuration, enable the applicable client drive mapping.

  2. If the session requires an explicit local path, map:

/media/mobile-devices/

The Mobile Device Support app automatically creates Windows-compatible subdirectory names for connected mobile devices. There is no separate app setting for predictable mount point names.

Access Mobile Devices from the Endpoint

Supported Devices and Access Methods

Device

Access method

Available content

Android phone or tablet

Media Transfer Protocol (MTP)

Storage made available after the user enables file transfer

iPhone or iPad

gphoto2://

Photos and videos from the camera roll

iPhone or iPad

Apple File Conduit (afc://)

App-shared documents made available through iOS or iPadOS file sharing

Supported digital camera

gphoto2://

Photos and videos exposed by the camera

Android devices normally appear as one MTP storage location. An iPhone or iPad can appear as separate entries for camera media and app-shared documents.

The content and available operations can differ according to the device model, mobile operating system, application permissions, and device authorization state.

Access an Android Device

  1. Connect the Android device with a data-capable USB cable.

  2. Unlock the device.

  3. Select File transfer, Transfer files, or the equivalent MTP option on the device.

  4. Double-click Mobile Device Support to open Thunar.

  5. Under Devices, select the Android device.

  6. Browse or transfer the available files.

image-20260904-112214.png


If the Android device remains in charging mode, its storage does not appear in Thunar.

Access an iPhone or iPad

  1. Connect the iPhone or iPad with a data-capable USB cable.

  2. Unlock the device.

  3. Select Trust when prompted.

  4. Complete device authentication if requested.

  5. Wait for IGEL OS to refresh the available device services.

  6. Start Mobile Device Support to open Thunar.

image-20260904-112419.png
  1. Select the entry that provides the required content:

    • Use the gphoto2:// entry for camera-roll photos and videos.

    • Use the afc:// entry, often displayed as Documents on iPhone, for app-shared documents.

The AFC connection does not expose the complete iOS or iPadOS filesystem. It shows only content shared by applications that support Apple file sharing.

Seeing separate gphoto2:// and afc:// entries for the same device is expected.

Troubleshooting

If the device does not appear in Thunar:

  1. Confirm that the Mobile Device Support app and its dependencies are installed.

  2. Confirm that the USB cable supports data transfer.

  3. Unlock the mobile device.

  4. On Android, enable file transfer or MTP mode.

  5. On an iPhone or iPad, confirm that the device trusts the endpoint.

  6. Disconnect and reconnect the mobile device.

  7. Close and restart Mobile Device Support.

  8. Check the rules under Devices > USB Access Control.

If local access works but session mapping does not:

  1. Confirm that Enable dynamic client drive mapping is enabled.

  2. Verify that the device has a directory below /media/mobile-devices/.

  3. Confirm that client drive mapping is enabled for the remote session.

  4. Confirm that the session can access /media/mobile-devices/.

  5. Verify that the current Mobile Device Support app and its dependencies are installed.

After a device is disconnected, a remote Windows session might temporarily continue to show its directory because of client-side caching. Access to files in the disconnected directory fails, and the local directory is removed automatically.