build c4cb80d0 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 308 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: igel/igel-os locale: en labels: vendor: IGEL OS capability/modern-workplace: 1.72 capability/endpoint-security: 2.90 vendor/igel: 3.14 annotations: source: src/content/solutions/en/igel/igel-os.md route: /en/solutions/igel/igel-os/ schema: /nerd/schema/solutions.json markdown: /en/solutions/igel/igel-os.mdspec: title: IGEL OS tags: [modern-workplace, endpoint-security] vendors: [igel] summary: >- A read-only Linux as the endpoint operating system. Turns existing hardware into a managed access point and extends how long it stays useful. photoNeed: >- An IGEL endpoint in place: a UD Pocket in a laptop, or a thin client at a working desk stub: false draft: false kind: platform addon: false sourceNote: >- soultec.ch/solutions/igel, read 2026-08-30, for the IGEL OS 12 behaviour and the three deployment modes; igel.com, read the same day, for «The Secure Endpoint OS Platform» vendorName: IGEL OS status: current practice: >- Draft, not yet reviewed. The reason IGEL gets adopted here is almost never security, it is the procurement cycle: laptops that have become too slow for Windows will serve as access points for years. The security argument convinces people afterwards, but it rarely opens the door. practiceReview: true sections: - heading:

What it is

body: | IGEL OS is a lean Linux that runs on the endpoint and stores nothing permanently. After every restart the machine is back in its defined state. Configuration comes from a central management server rather than from the device. With version 12 the base operating system ships with **no applications at all**. Everything a person actually uses, the Citrix client, the Horizon client, the AVD client, a browser, arrives from the App Portal as a separate package and updates on its own schedule. That is the part that changes how you run it: an application no longer waits for an OS release. IGEL OS, the Universal Management Suite and the cloud services together are what IGEL calls the Secure Endpoint OS Platform. None of the three is much use alone. - heading:

What it is for

body: | Workplaces whose real environment runs somewhere else: virtual desktops, published applications, web applications. The device becomes an access point and stops being a computer that needs maintaining. The second use case is extending life. Hardware too weak for a current Windows is still perfectly adequate for this. - heading:

Three ways to run it

body: | **Installed on the device**, replacing the local operating system. This is the standard case and the one that gets managed centrally from day one. **Booted from USB**, with nothing installed and the existing operating system and local data untouched. A machine becomes a managed workplace in minutes and goes back to being itself when the stick comes out. This is what makes it useful for contractors, for bring-your-own-device, and for a disaster recovery plan that has to work on whatever hardware is to hand. **On a thin client**, which is the classic deployment and where the supported client list matters: Azure Virtual Desktop, Omnissa Horizon, Citrix and the rest. - heading:

What to watch

body: | Anything that has to run locally will not run here. Peripherals are the usual obstacle, particularly specialist equipment in labs, on production lines and in medical practices. That inventory belongs at the start of the project, not in the pilot.status: corpus: 308 services: - {ref: services/modern-workplace, score: 0.49} - {ref: services/security, score: 0.21} posts: - {ref: posts/how-to-igel-ud-pocket-bios-uefi-settings, score: 0.41} - {ref: posts/how-to-fix-workspace-one-admin-assistant-parsing-failed-macos, score: 0.41} - {ref: posts/how-to-enterprise-wipe-vs-device-wipe-vs-unenroll-vs-delete-device-in-workspace-one-uem, score: 0.41} - {ref: posts/how-to-enroll-windows-server-2025-in-omnissa-workspace-one-uem, score: 0.41} - {ref: posts/send-workspace-one-hub-notifications, score: 0.41} - {ref: posts/how-to-intelligent-hub-macos-not-synchronizing-after-active-directory-user-name-change, score: 0.34} neighbours: - {ref: solutions/igel/addon/igel-contextual-access, score: 0.79} - {ref: solutions/igel, score: 0.79} - {ref: solutions/igel/igel-ums, score: 0.73}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "igel/igel-os", "locale": "en", "labels": { "vendor": "IGEL OS", "capability/modern-workplace": "1.72", "capability/endpoint-security": "2.90", "vendor/igel": "3.14" }, "annotations": { "source": "src/content/solutions/en/igel/igel-os.md", "route": "/en/solutions/igel/igel-os/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/igel/igel-os.md" } }, "spec": { "title": "IGEL OS", "tags": [ "modern-workplace", "endpoint-security" ], "vendors": [ "igel" ], "summary": "A read-only Linux as the endpoint operating system. Turns existing hardware into a managed access point and extends how long it stays useful.", "photoNeed": "An IGEL endpoint in place: a UD Pocket in a laptop, or a thin client at a working desk", "stub": false, "draft": false, "kind": "platform", "addon": false, "sourceNote": "soultec.ch/solutions/igel, read 2026-08-30, for the IGEL OS 12 behaviour and the three deployment modes; igel.com, read the same day, for «The Secure Endpoint OS Platform»", "vendorName": "IGEL OS", "status": "current", "practice": "Draft, not yet reviewed. The reason IGEL gets adopted here is almost never security, it is the procurement cycle: laptops that have become too slow for Windows will serve as access points for years. The security argument convinces people afterwards, but it rarely opens the door.\n", "practiceReview": true }, "sections": [ { "heading": "

What it is

",
"body": "IGEL OS is a lean Linux that runs on the endpoint and stores nothing permanently. After\nevery restart the machine is back in its defined state. Configuration comes from a central\nmanagement server rather than from the device.\n\nWith version 12 the base operating system ships with **no applications at all**. Everything\na person actually uses, the Citrix client, the Horizon client, the AVD client, a browser,\narrives from the App Portal as a separate package and updates on its own schedule. That is\nthe part that changes how you run it: an application no longer waits for an OS release.\n\nIGEL OS, the Universal Management Suite and the cloud services together are what IGEL calls\nthe Secure Endpoint OS Platform. None of the three is much use alone." }, { "heading": "

What it is for

",
"body": "Workplaces whose real environment runs somewhere else: virtual desktops, published\napplications, web applications. The device becomes an access point and stops being a\ncomputer that needs maintaining.\n\nThe second use case is extending life. Hardware too weak for a current Windows is still\nperfectly adequate for this." }, { "heading": "

Three ways to run it

",
"body": "**Installed on the device**, replacing the local operating system. This is the standard\ncase and the one that gets managed centrally from day one.\n\n**Booted from USB**, with nothing installed and the existing operating system and local\ndata untouched. A machine becomes a managed workplace in minutes and goes back to being\nitself when the stick comes out. This is what makes it useful for contractors, for\nbring-your-own-device, and for a disaster recovery plan that has to work on whatever\nhardware is to hand.\n\n**On a thin client**, which is the classic deployment and where the supported client list\nmatters: Azure Virtual Desktop, Omnissa Horizon, Citrix and the rest." }, { "heading": "

What to watch

",
"body": "Anything that has to run locally will not run here. Peripherals are the usual obstacle,\nparticularly specialist equipment in labs, on production lines and in medical practices.\nThat inventory belongs at the start of the project, not in the pilot." } ], "status": { "corpus": 308, "services": [ { "ref": "services/modern-workplace", "score": "0.49" }, { "ref": "services/security", "score": "0.21" } ], "posts": [ { "ref": "posts/how-to-igel-ud-pocket-bios-uefi-settings", "score": "0.41" }, { "ref": "posts/how-to-fix-workspace-one-admin-assistant-parsing-failed-macos", "score": "0.41" }, { "ref": "posts/how-to-enterprise-wipe-vs-device-wipe-vs-unenroll-vs-delete-device-in-workspace-one-uem", "score": "0.41" }, { "ref": "posts/how-to-enroll-windows-server-2025-in-omnissa-workspace-one-uem", "score": "0.41" }, { "ref": "posts/send-workspace-one-hub-notifications", "score": "0.41" }, { "ref": "posts/how-to-intelligent-hub-macos-not-synchronizing-after-active-directory-user-name-change", "score": "0.34" } ], "neighbours": [ { "ref": "solutions/igel/addon/igel-contextual-access", "score": "0.79" }, { "ref": "solutions/igel", "score": "0.79" }, { "ref": "solutions/igel/igel-ums", "score": "0.73" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "igel/igel-os"locale = "en"[metadata.labels]vendor = "IGEL OS""capability/modern-workplace" = "1.72""capability/endpoint-security" = "2.90""vendor/igel" = "3.14"[metadata.annotations]source = "src/content/solutions/en/igel/igel-os.md"route = "/en/solutions/igel/igel-os/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/igel/igel-os.md"[spec]title = "IGEL OS"tags = ["modern-workplace", "endpoint-security"]vendors = ["igel"]summary = "A read-only Linux as the endpoint operating system. Turns existing hardware into a managed access point and extends how long it stays useful."photoNeed = "An IGEL endpoint in place: a UD Pocket in a laptop, or a thin client at a working desk"stub = falsedraft = falsekind = "platform"addon = falsesourceNote = "soultec.ch/solutions/igel, read 2026-08-30, for the IGEL OS 12 behaviour and the three deployment modes; igel.com, read the same day, for «The Secure Endpoint OS Platform»"vendorName = "IGEL OS"status = "current"practice = '''Draft, not yet reviewed. The reason IGEL gets adopted here is almost never security, it is the procurement cycle: laptops that have become too slow for Windows will serve as access points for years. The security argument convinces people afterwards, but it rarely opens the door.'''practiceReview = true[[sections]]heading = "

What it is

"
body = '''IGEL OS is a lean Linux that runs on the endpoint and stores nothing permanently. Afterevery restart the machine is back in its defined state. Configuration comes from a centralmanagement server rather than from the device.With version 12 the base operating system ships with **no applications at all**. Everythinga person actually uses, the Citrix client, the Horizon client, the AVD client, a browser,arrives from the App Portal as a separate package and updates on its own schedule. That isthe part that changes how you run it: an application no longer waits for an OS release.IGEL OS, the Universal Management Suite and the cloud services together are what IGEL callsthe Secure Endpoint OS Platform. None of the three is much use alone.'''[[sections]]heading = "

What it is for

"
body = '''Workplaces whose real environment runs somewhere else: virtual desktops, publishedapplications, web applications. The device becomes an access point and stops being acomputer that needs maintaining.The second use case is extending life. Hardware too weak for a current Windows is stillperfectly adequate for this.'''[[sections]]heading = "

Three ways to run it

"
body = '''**Installed on the device**, replacing the local operating system. This is the standardcase and the one that gets managed centrally from day one.**Booted from USB**, with nothing installed and the existing operating system and localdata untouched. A machine becomes a managed workplace in minutes and goes back to beingitself when the stick comes out. This is what makes it useful for contractors, forbring-your-own-device, and for a disaster recovery plan that has to work on whateverhardware is to hand.**On a thin client**, which is the classic deployment and where the supported client listmatters: Azure Virtual Desktop, Omnissa Horizon, Citrix and the rest.'''[[sections]]heading = "

What to watch

"
body = '''Anything that has to run locally will not run here. Peripherals are the usual obstacle,particularly specialist equipment in labs, on production lines and in medical practices.That inventory belongs at the start of the project, not in the pilot.'''[status]corpus = 308[[status.services]]ref = "services/modern-workplace"score = "0.49"[[status.services]]ref = "services/security"score = "0.21"[[status.posts]]ref = "posts/how-to-igel-ud-pocket-bios-uefi-settings"score = "0.41"[[status.posts]]ref = "posts/how-to-fix-workspace-one-admin-assistant-parsing-failed-macos"score = "0.41"[[status.posts]]ref = "posts/how-to-enterprise-wipe-vs-device-wipe-vs-unenroll-vs-delete-device-in-workspace-one-uem"score = "0.41"[[status.posts]]ref = "posts/how-to-enroll-windows-server-2025-in-omnissa-workspace-one-uem"score = "0.41"[[status.posts]]ref = "posts/send-workspace-one-hub-notifications"score = "0.41"[[status.posts]]ref = "posts/how-to-intelligent-hub-macos-not-synchronizing-after-active-directory-user-name-change"score = "0.34"[[status.neighbours]]ref = "solutions/igel/addon/igel-contextual-access"score = "0.79"[[status.neighbours]]ref = "solutions/igel"score = "0.79"[[status.neighbours]]ref = "solutions/igel/igel-ums"score = "0.73"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>igel/igel-os</name> <locale>en</locale> <labels> <vendor>IGEL OS</vendor> <entry key="capability/modern-workplace">1.72</entry> <entry key="capability/endpoint-security">2.90</entry> <entry key="vendor/igel">3.14</entry> </labels> <annotations> <source>src/content/solutions/en/igel/igel-os.md</source> <route>/en/solutions/igel/igel-os/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/igel/igel-os.md</markdown> </annotations> </metadata> <spec> <title>IGEL OS</title> <tags> <item>modern-workplace</item> <item>endpoint-security</item> </tags> <vendors> <item>igel</item> </vendors> <summary>A read-only Linux as the endpoint operating system. Turns existing hardware into a managed access point and extends how long it stays useful.</summary> <photoNeed>An IGEL endpoint in place: a UD Pocket in a laptop, or a thin client at a working desk</photoNeed> <stub>false</stub> <draft>false</draft> <kind>platform</kind> <addon>false</addon> <sourceNote>soultec.ch/solutions/igel, read 2026-08-30, for the IGEL OS 12 behaviour and the three deployment modes; igel.com, read the same day, for «The Secure Endpoint OS Platform»</sourceNote> <vendorName>IGEL OS</vendorName> <status>current</status> <practice>Draft, not yet reviewed. The reason IGEL gets adopted here is almost never security, it is the procurement cycle: laptops that have become too slow for Windows will serve as access points for years. The security argument convinces people afterwards, but it rarely opens the door. </practice> <practiceReview>true</practiceReview> </spec> <sections> <section> <heading>

What it is

</heading>
<body>IGEL OS is a lean Linux that runs on the endpoint and stores nothing permanently. Afterevery restart the machine is back in its defined state. Configuration comes from a centralmanagement server rather than from the device.With version 12 the base operating system ships with **no applications at all**. Everythinga person actually uses, the Citrix client, the Horizon client, the AVD client, a browser,arrives from the App Portal as a separate package and updates on its own schedule. That isthe part that changes how you run it: an application no longer waits for an OS release.IGEL OS, the Universal Management Suite and the cloud services together are what IGEL callsthe Secure Endpoint OS Platform. None of the three is much use alone. </body> </section> <section> <heading>

What it is for

</heading>
<body>Workplaces whose real environment runs somewhere else: virtual desktops, publishedapplications, web applications. The device becomes an access point and stops being acomputer that needs maintaining.The second use case is extending life. Hardware too weak for a current Windows is stillperfectly adequate for this. </body> </section> <section> <heading>

Three ways to run it

</heading>
<body>**Installed on the device**, replacing the local operating system. This is the standardcase and the one that gets managed centrally from day one.**Booted from USB**, with nothing installed and the existing operating system and localdata untouched. A machine becomes a managed workplace in minutes and goes back to beingitself when the stick comes out. This is what makes it useful for contractors, forbring-your-own-device, and for a disaster recovery plan that has to work on whateverhardware is to hand.**On a thin client**, which is the classic deployment and where the supported client listmatters: Azure Virtual Desktop, Omnissa Horizon, Citrix and the rest. </body> </section> <section> <heading>

What to watch

</heading>
<body>Anything that has to run locally will not run here. Peripherals are the usual obstacle,particularly specialist equipment in labs, on production lines and in medical practices.That inventory belongs at the start of the project, not in the pilot. </body> </section> </sections> <status> <corpus>308</corpus> <services> <item> <ref>services/modern-workplace</ref> <score>0.49</score> </item> <item> <ref>services/security</ref> <score>0.21</score> </item> </services> <posts> <item> <ref>posts/how-to-igel-ud-pocket-bios-uefi-settings</ref> <score>0.41</score> </item> <item> <ref>posts/how-to-fix-workspace-one-admin-assistant-parsing-failed-macos</ref> <score>0.41</score> </item> <item> <ref>posts/how-to-enterprise-wipe-vs-device-wipe-vs-unenroll-vs-delete-device-in-workspace-one-uem</ref> <score>0.41</score> </item> <item> <ref>posts/how-to-enroll-windows-server-2025-in-omnissa-workspace-one-uem</ref> <score>0.41</score> </item> <item> <ref>posts/send-workspace-one-hub-notifications</ref> <score>0.41</score> </item> <item> <ref>posts/how-to-intelligent-hub-macos-not-synchronizing-after-active-directory-user-name-change</ref> <score>0.34</score> </item> </posts> <neighbours> <item> <ref>solutions/igel/addon/igel-contextual-access</ref> <score>0.79</score> </item> <item> <ref>solutions/igel</ref> <score>0.79</score> </item> <item> <ref>solutions/igel/igel-ums</ref> <score>0.73</score> </item> </neighbours> </status></manifest>
Solution · IGEL

IGEL OS

A read-only Linux as the endpoint operating system. Turns existing hardware into a managed access point and extends how long it stays useful.

Topics Modern Workplace 1.72 Endpoint Security 2.90
Vendors IGEL 3.14
02Services
06Posts
02Capabilities
308Corpus

What it is

IGEL OS is a lean Linux that runs on the endpoint and stores nothing permanently. After every restart the machine is back in its defined state. Configuration comes from a central management server rather than from the device.

With version 12 the base operating system ships with no applications at all. Everything a person actually uses, the Citrix client, the Horizon client, the AVD client, a browser, arrives from the App Portal as a separate package and updates on its own schedule. That is the part that changes how you run it: an application no longer waits for an OS release.

IGEL OS, the Universal Management Suite and the cloud services together are what IGEL calls the Secure Endpoint OS Platform. None of the three is much use alone.

What it is for

Workplaces whose real environment runs somewhere else: virtual desktops, published applications, web applications. The device becomes an access point and stops being a computer that needs maintaining.

The second use case is extending life. Hardware too weak for a current Windows is still perfectly adequate for this.

Three ways to run it

Installed on the device, replacing the local operating system. This is the standard case and the one that gets managed centrally from day one.

Booted from USB, with nothing installed and the existing operating system and local data untouched. A machine becomes a managed workplace in minutes and goes back to being itself when the stick comes out. This is what makes it useful for contractors, for bring-your-own-device, and for a disaster recovery plan that has to work on whatever hardware is to hand.

On a thin client, which is the classic deployment and where the supported client list matters: Azure Virtual Desktop, Omnissa Horizon, Citrix and the rest.

What to watch

Anything that has to run locally will not run here. Peripherals are the usual obstacle, particularly specialist equipment in labs, on production lines and in medical practices. That inventory belongs at the start of the project, not in the pilot.

What we do with it

Draft, unreviewed

Draft, not yet reviewed. The reason IGEL gets adopted here is almost never security, it is the procurement cycle: laptops that have become too slow for Windows will serve as access points for years. The security argument convinces people afterwards, but it rarely opens the door.

This paragraph is a draft and nobody at soulTec has confirmed it yet. Everything above it describes the product and is checkable against the vendor.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.