How to Configure Persona Profiles for IGEL Contextual Access

IGEL Contextual Access (ICA) extends the IGEL Adaptive Secure Desktop by using contextual signals to determine what a user should receive when they connect to an IGEL OS device. Instead of treating every device the same way, ICA enables IT to deliver workspace controls and resources based on the user’s context. Persona Profiles enables the persona-based layer of ICA through the IGEL Universal Management Suite (UMS).

With Persona Profiles, configurations and applications are assigned to user personas rather than individual devices. When a user signs in to an IGEL OS 12 device through Single Sign-On (SSO), the IGEL UMS uses role information from the Identity Provider (IdP) to activate the appropriate persona profile. This allows different user types to receive a personalized, role-specific desktop with the applications and settings they need. Through Persona Profiles, IT can manage access at the persona level instead of device by device.


How Persona Profiles Work

  1. The administrator configures persona profiles in the UMS. See the How to Configure Persona Profile section below.

  2. The user logs in to an IGEL OS 12 device via SSO.

  3. The Identity Provider authenticates the user and provides role information to the UMS.

  4. The IGEL UMS evaluates the user’s role and applies the persona profile based on the role and the device.

  5. Assigned configurations and applications are dynamically applied based on the persona profile.

When multiple persona profiles are assigned to a device, the applications from all assigned profiles are downloaded to the device. At login, only the applications associated with the user's matching persona profile are activated.

  1. On logout, the session is cleared and settings are removed.

Configuring Fallback Login Option

A persistent connection to the IGEL UMS is required for Persona Profiles to function correctly. During a UMS update, the UMS is temporarily unavailable and cannot deliver configurations to devices.

It is recommended to configure a fallback user at the device level to ensure continued access when the UMS is temporarily unreachable.

Unsupported Apps with Persona Profiles

Some of the apps offered in the IGEL App Portal are not yet supported in combination with Persona Profiles.

Apps not yet supported with Persona Profiles are listed below. Support for these apps is planned to be covered with future releases. The list will be updated accordingly.

Click to see the list of apps...

Amazon WorkSpaces Client
Chromium Browser
Citrix Workspace App
Firefox ESR
IGEL for Windows
IGEL Remote Desktop
Microsoft Edge
NCP Secure Enterprise Client
NoMachine NX Client
Omnissa Horizon Client
Progressive Web App
Remote Desktop Web Access
ThinLinc
Zoom Media Plugins for VDI

Prerequisites

External IdP Configuration

  • Supported cloud IdP providers with Persona Profiles:

    • Okta

    • Ping

    • Microsoft Entra ID

Feature Enablement

Version Requirements

  • IGEL UMS 12.12.100 or higher

  • IGEL OS 12.9.0 or higher

How to Configure Persona Profiles

The following steps provide an overview of how the persona profile is configured:

Step 1: Configure Cloud IdP in the UMS

→ Configure the cloud IdP the same way as for the UMS Login with SSO. For details, see https://kb.igel.com/en/universal-management-suite/current/how-to-set-up-ums-login-with-sso .

The section “Configuring Your Connection to Microsoft Entra ID in the UMS Web App” is not required for Persona Profiles.

Step 2: Configure SSO Login on IGEL OS

→ Use the configured IdP to enable SSO Login on the device. For details, see https://kb.igel.com/en/igel-os-base-system/current/how-to-configure-single-sign-on-sso-on-igel-os-12.

Step 3: Configure Token Trust in UMS

To ensure that UMS trusts the authentication tokens issued by the IdP for the persona profile login:

  1. In the UMS Web App, go to System > Settings > Network.


  1. Define the claim that contains the roles of the users. (Default if left empty: roles)
    The UMS will read the role of the user from this claim when the user logs in.

    image-20260518-160945.png


  1. Click Manage under Allowed Issuer for Persona Desktop login.

    image-20260518-161007.png


  1. Add the issuer URI of the IdP configured for SSO Login on IGEL OS.

    image-20260127-131222.png


Step 4: Create and Persona Profiles for IdP Roles

  1. In the UMS Web App, go to Configuration Objects > Persona Profiles

    image-20260519-100016.png


  1. Create a new persona profile.

    image-20260518-160342.png


  1. Enter Name and Description for easy profile management.


  1. List the IdP role names separated by commas under IDP Role to connect the persona profile to these IdP roles.


  1. Click Next.


Step 5: Assign Configuration Objects to Persona Profiles

→ Assign configuration objects to the persona profile, like profiles, apps, etc. For more information on configuration objects, see Configuration - Centralized Management of Device Settings in the IGEL UMS Web App.
These configurations will be applied to all users mapped to the corresponding IdP roles.

image-20260127-131629.png

Once the persona profile is saved, you can assign/remove objects through the Assign Object action.

You can see assigned objects in the Assigned Objects tab.

image-20260519-101044.png

Step 6: Assign Persona Profiles to Devices

→ Select the devices or device directories for which this persona profile should be active.

image-20260127-131815.png

This way, the persona profile controls which users can access specific devices.

Example:

  • A persona profile linked to a specific IdP role is only active on the assigned devices.

  • Users without a matching persona profile cannot log in to the device.

Once the persona profile is saved, you can assign/remove devices through the Assign Device action button.

You can check on the assigned devices in the Assigned Devices tab.

image-20260522-084735.png