Skip to content

Building a Context Aware Ecosystem with IGEL Insights

Deeper integration opportunities across the IGEL Ready ecosystem

Modern organizations rarely lack data. What they often lack is the ability to connect endpoint, identity, network, application, and security data in a way that supports timely decisions.

IGEL Insights helps close that gap by making detailed IGEL OS endpoint intelligence available to the broader IGEL Ready ecosystem. Through the IGEL Insights APIs, partners can access information concerning device inventory, user sessions, system performance, network quality, application versions, firmware, removable-media activity, remote-resource access, and device trust.

The immediate opportunity is better analytics. The larger opportunity is creating closed-loop integrations in which IGEL endpoint context contributes to access decisions, security investigations, automated remediation, support workflows, and infrastructure optimization.

In that model, IGEL Insights is more than a reporting interface. It becomes a contextual data layer for the secure digital workspace.

The Data Foundation

The released IGEL Insights APIs expose four principal categories of endpoint intelligence that partners can consume and correlate with their own platforms.

Data category Representative IGEL Insights signals
Device identity and inventory UMS and device information; device counts and metadata; hardware manufacturer and OS distributions; firmware; installed applications and versions; device ownership
Device health and performance CPU utilization, performance, and overheating; memory and disk utilization; battery health; boot latency; crashes; top processes; device activity; user-session history
Network experience Network quality and latency; highest-latency devices; packet-loss distribution and trends; Wi-Fi signal strength; quality history and threshold violations
Security and trust Device trust scores and detail; firmware trust context; USB attachment and file-copy activity; remote-resource access; user sessions; crash and process activity

Moving from API Access to Closed Loop Integration

A basic integration periodically retrieves IGEL Insights data and displays it in a partner dashboard. A deeper integration uses that information as part of an automated decision and response process.

  1. Observe IGEL Insights provides endpoint health, security, configuration, and experience data.
  2. Correlate A partner combines that data with identity, network, application, threat, or infrastructure telemetry.
  3. Decide The partner applies analytics, policy, or AI to determine the appropriate response.
  4. Act The partner enforces a control through its own platform or initiates an approved endpoint action through IGEL UMS.
  5. Verify IGEL Insights confirms whether the endpoint returned to an acceptable state.

This model allows IGEL and its partners to create integrated outcomes rather than simply exchange data.

CrowdStrike Endpoint Context for Next Generation SIEM

The CrowdStrike Falcon sensor can provide runtime security telemetry from IGEL OS. IGEL Insights can add complementary information about the device’s configuration, performance, network experience, USB activity, and user-session history.

Imagine that CrowdStrike identifies suspicious activity associated with a user account accessing a sensitive cloud application. CrowdStrike Next-Gen SIEM could query IGEL Insights and determine:

  • Which IGEL OS endpoint was involved
  • The device’s current trust score
  • Whether its firmware and applications were current
  • Whether removable media had recently been attached or file-copy activity had occurred
  • Which remote resources the endpoint had accessed
  • Whether the device had experienced unusual crashes or process activity
  • Whether the user’s current session differed from prior sessions

CrowdStrike could combine those signals with Falcon telemetry, identity events, threat intelligence, and cloud-application activity to produce a richer incident timeline.

If the combined risk exceeded a defined threshold, CrowdStrike Fusion SOAR could initiate a workflow to restrict the user, isolate another affected workload, notify the security operations center, and request an endpoint-side response through IGEL UMS.

The UMS action might assign a restrictive profile, disable selected USB capabilities, limit available applications, or move the device into a designated investigation group. IGEL Insights could then verify the device’s resulting state and provide that confirmation back to the incident record. This would create a security lifecycle spanning detection, enrichment, response, and validation.

Zscaler Adaptive Access Based on Endpoint and Network Context

Zscaler could combine IGEL Insights with identity, application, and security information available through Zscaler Internet Access, Zscaler Private Access, and related Zero Trust services.

Consider a remote employee requesting access to a sensitive private application. In addition to validating the user and applying Zscaler policy, a contextual integration could evaluate the IGEL device identity and ownership, trust score, firmware and required application versions, recent USB activity, network health, and prior resource access.

A trusted corporate device with the expected configuration and a healthy connection could receive standard ZPA access. A device with an outdated application, unexpected USB activity, or reduced trust score could be required to complete stronger authentication or receive access to a browser-isolated version of the application. A device presenting multiple high-risk indicators could be denied access and referred for investigation.

Network telemetry could also improve the user experience. If Zscaler observes poor application performance, IGEL Insights could help determine whether the problem originates from weak Wi-Fi, local packet loss, the internet path, or the application itself. A support workflow might then recommend a wired connection or automatically open a service ticket containing both Zscaler and IGEL diagnostic data.

Unified SASE Context

Similar integration patterns could be developed with Netskope, Palo Alto Networks, Cato Networks, and Fortinet. A SASE platform already has visibility into users, applications, traffic, data movement, and security policy. IGEL Insights can add endpoint-specific context that may not otherwise be visible to the network enforcement plane.

A SASE partner could incorporate device trust, ownership, firmware compliance, security application versions, current network quality, USB activity, and resource-access history into its policy engine. This could enable policies that:

  • Permit normal application access from trusted and compliant IGEL devices
  • Require browser isolation for unmanaged or lower-trust situations
  • Prevent downloads when recent removable-media activity raises risk
  • Restrict sensitive applications when a required security client is outdated
  • Change the preferred point of presence or network path when latency exceeds a threshold
  • Trigger additional authentication when endpoint context materially changes
  • Restore normal access automatically after compliance is re-established

This turns endpoint posture into an active input for SASE policy rather than a static check performed only when a session begins.

Cisco ISE and Forescout Continuous Device Aware Network Access

Network access control platforms such as Cisco ISE and Forescout could use IGEL Insights to supplement device identification and posture assessment. When an IGEL device connects to a clinical, financial, or manufacturing network, the NAC platform could retrieve device ownership, hardware and firmware information, application inventory, the IGEL trust score, and recent USB or resource-access activity.

The deeper opportunity is continuous evaluation. If the trust score changes, an unauthorized peripheral is attached, or the configuration no longer meets policy, the NAC platform could dynamically change network access. The device might be placed into a remediation VLAN, restricted to approved applications, or prevented from communicating with high-value systems.

After remediation through IGEL UMS, IGEL Insights could confirm that the endpoint had returned to compliance. The NAC platform could then restore normal network permissions without waiting for manual review, creating a continuous comply-to-connect model rather than a one-time posture check.

Island and Enterprise Browser Partners

Enterprise browsers already apply granular controls to SaaS and web applications. IGEL Insights could give those browsers additional information about the endpoint on which the browser session is running.

An enterprise browser such as Island could combine browser-level information with IGEL device identity, ownership, trust, firmware and application compliance, USB activity, network quality, and recent resource access.

A financial-services organization might permit employees to view sensitive information on any authorized IGEL endpoint but allow downloading, printing, clipboard use, or file uploads only when the endpoint meets a higher trust threshold. A contact-center organization might allow access to customer records while dynamically disabling downloads or removable-media transfers if IGEL Insights reports a recent USB event.

The browser could also adapt the experience. If IGEL Insights shows significant packet loss or weak Wi-Fi, the browser or collaboration application could reduce video quality, prioritize audio, or alert the user before the session degrades. This creates a policy relationship between the secure operating system and the application access layer without requiring every web application to understand endpoint posture independently.

Imprivata Clinical Access Informed by Device Context

Healthcare provides another compelling opportunity. Imprivata could combine identity, authentication, and workflow information with IGEL endpoint intelligence.

When a clinician authenticates at a shared workstation, the workflow could evaluate the clinician’s identity and role, the device and its ownership model, device trust and firmware status, the workstation’s organizational assignment, endpoint health, recent user sessions, and unusual USB or resource-access activity.

A trusted nursing-station device could provide rapid access to the standard clinical workspace. A device in a public or less-controlled area might receive a more restrictive session. A device showing an unexpected configuration change could require additional authentication or be removed from clinical service.

IGEL Insights could also help maintain workstation availability. Excessive boot times, crashes, CPU issues, or network degradation could trigger proactive service before the endpoint disrupts patient care. Correlating authentication and clinical workflow data with endpoint health could improve both security and clinical efficiency.

Omnissa, ControlUp and DEX Partners

A DEX platform such as Omnissa DEX and ControlUp can see virtual sessions, applications, and infrastructure. IGEL Insights adds the physical endpoint and local network perspective.

If a user reports that a Citrix, Microsoft AVD, Windows 365, or Omnissa Horizon session is slow, the integrated platform could compare local resource utilization, Wi-Fi strength, packet loss and latency, IGEL boot and crash history, remote display protocol performance, hosted desktop utilization, application response time, and infrastructure health.

The analytics engine could then identify the probable fault domain:

  • High local CPU with normal session latency suggests an endpoint-side issue
  • Weak Wi-Fi and packet loss suggest a local connectivity problem
  • Healthy endpoint metrics with high protocol latency suggest a network-path issue
  • Healthy endpoint and network data with high virtual machine utilization suggest a hosted-workload problem

The platform could execute the appropriate workflow—guide the user to a better connection, restart a remote session, resize a cloud desktop, open a network ticket, or request an endpoint action through UMS. IGEL Insights could also support predictive models that identify combinations of battery degradation, overheating, crash frequency, and performance decline that commonly precede endpoint failure.

ServiceNow Automated Service Operations

ServiceNow could use IGEL Insights to create a richer configuration and operational record for IGEL endpoints. Instead of requiring an analyst to collect basic information manually, an incident could automatically include device model, firmware and application versions, ownership, hardware health, recent crashes, network-quality history, user sessions, and relevant USB or resource-access events.

The more advanced opportunity is workflow automation. If IGEL Insights identifies recurring thermal events, deteriorating battery health, or repeated network violations, ServiceNow could proactively create and route an incident, associate it with the correct configuration item, and recommend remediation based on similar resolved cases.

Following remediation, ServiceNow could query IGEL Insights to confirm that the original condition no longer existed and automatically close the ticket after an appropriate validation period. Security incidents could follow a similar process: a SIEM alert enriched with IGEL data generates a Security Operations case, initiates an approved UMS action, documents the response, and verifies the resulting endpoint state.

Citrix Microsoft and Omnissa Adaptive Workspace Delivery

Workspace platforms could use IGEL Insights to make better decisions about how applications and desktops are delivered. A broker or workspace service might evaluate device performance and network conditions before launching a resource. Based on the result, it could:

  • Select an appropriate remote display policy
  • Reduce multimedia quality on constrained networks
  • Prefer a browser-based application over a full virtual desktop
  • Direct the user to a geographically closer resource
  • Select a lower-resource desktop configuration
  • Warn the user of poor local connectivity
  • Restrict higher-risk resources on a lower-trust device

IGEL Insights could also help these platforms compare experience across endpoint models, firmware versions, locations, and application releases, making it easier to determine whether a client update or infrastructure change improved or degraded the user experience.

Hardware Partners and Predictive Lifecycle Management

Hardware partners such as HP, Lenovo, and LG could use appropriately governed IGEL Insights data to support device-health and lifecycle services. Battery condition, CPU temperature, boot latency, memory pressure, storage utilization, crash frequency, and workload history could help estimate the remaining useful life of a device.

A joint analytics model could distinguish between a device requiring replacement, one that only needs a new battery, one affected by a firmware or configuration issue, and one that remains fully capable of supporting its assigned workload. This could reduce unnecessary replacement and give customers measurable evidence of the sustainability and financial value of extending device life with IGEL OS.

Managed Service Providers and Cross Customer Intelligence

Managed service providers could use IGEL Insights to create a centralized operational view across multiple customer environments while maintaining strict tenant separation. An MSP dashboard could identify devices with declining health, unusual increases in packet loss, application or firmware inconsistencies, high-risk USB activity, recurring location-level performance problems, and devices falling below defined trust thresholds.

The MSP could combine these signals with service-level agreements and customer-specific policies. High-priority issues could generate automated tickets, while lower-priority trends could be summarized in service reviews. This creates an opportunity to build managed DEX, managed security, compliance monitoring, and endpoint-lifecycle services around IGEL Insights.

Building the Integration Architecture

Deeper integrations generally require four complementary capabilities:

  • IGEL Insights for observation. Supplies endpoint inventory, health, experience, security, and trust context.
  • Partner analytics for correlation. Combines IGEL data with identity, threat, application, network, session, or infrastructure telemetry.
  • A policy or automation engine. Determines whether to alert, restrict, remediate, optimize, or escalate.
  • IGEL UMS or partner controls. Applies the action through the appropriate authorized control plane.

IGEL Insights can then verify the outcome, completing the loop.

A Path Toward an Adaptive Secure Desktop

The strategic value of IGEL Insights is not limited to giving partners another dashboard or source of telemetry. Its greater potential is enabling the endpoint to participate in continuous enterprise decision-making.

A contextual ecosystem can ask:

  • Is this the expected device?
  • Is it healthy and appropriately configured?
  • Is its behavior consistent with policy?
  • Can the current network support the requested workload?
  • Should the user receive normal, restricted, isolated, or denied access?
  • Did the remediation return the device to an acceptable state?

No single platform can answer all of those questions independently. IGEL provides essential endpoint context, while IGEL Ready partners contribute identity, networking, application delivery, security analytics, automation, and enforcement.

By connecting those capabilities, IGEL Insights can help move the ecosystem from compatible products to coordinated outcomes, and from a managed endpoint to a truly adaptive secure desktop.

Public Resources

IGEL Insights API Details  — API documentation and specification

IGEL Ready Partner Showcase  — IGEL Ready ecosystem overview

Jaime Halscott

Senior Alliance Technologist at IGEL
Back To Top