---
# source: src/content/solutions/en/igel/igel-os.md
# route:  /en/solutions/igel/igel-os/
title: IGEL OS
tags: [modern-workplace, endpoint-security]
vendors: [igel]
summary: A read-only Linux as the endpoint operating system. Turns existing hardware into a managed access point and extends how long it stays useful.
photoNeed: "An IGEL endpoint in place: a UD Pocket in a laptop, or a thin client at a working desk"
stub: false
draft: false
kind: platform
addon: false
sourceNote: soultec.ch/solutions/igel, read 2026-08-30, for the IGEL OS 12 behaviour and the three deployment modes; igel.com, read the same day, for «The Secure Endpoint OS Platform»
vendorName: IGEL OS
status: current
practice: >
  Draft, not yet reviewed. The reason IGEL gets adopted here is almost never security, it is the procurement cycle: laptops that have become too slow for Windows will serve as access points for years. The security argument convinces people afterwards, but it rarely opens the door.
practiceReview: true
---

## What it is

IGEL OS is a lean Linux that runs on the endpoint and stores nothing permanently. After
every restart the machine is back in its defined state. Configuration comes from a central
management server rather than from the device.

With version 12 the base operating system ships with **no applications at all**. Everything
a person actually uses, the Citrix client, the Horizon client, the AVD client, a browser,
arrives from the App Portal as a separate package and updates on its own schedule. That is
the part that changes how you run it: an application no longer waits for an OS release.

IGEL OS, the Universal Management Suite and the cloud services together are what IGEL calls
the Secure Endpoint OS Platform. None of the three is much use alone.

## What it is for

Workplaces whose real environment runs somewhere else: virtual desktops, published
applications, web applications. The device becomes an access point and stops being a
computer that needs maintaining.

The second use case is extending life. Hardware too weak for a current Windows is still
perfectly adequate for this.

## Three ways to run it

**Installed on the device**, replacing the local operating system. This is the standard
case and the one that gets managed centrally from day one.

**Booted from USB**, with nothing installed and the existing operating system and local
data untouched. A machine becomes a managed workplace in minutes and goes back to being
itself when the stick comes out. This is what makes it useful for contractors, for
bring-your-own-device, and for a disaster recovery plan that has to work on whatever
hardware is to hand.

**On a thin client**, which is the classic deployment and where the supported client list
matters: Azure Virtual Desktop, Omnissa Horizon, Citrix and the rest.

## What to watch

Anything that has to run locally will not run here. Peripherals are the usual obstacle,
particularly specialist equipment in labs, on production lines and in medical practices.
That inventory belongs at the start of the project, not in the pilot.
