Skip to main content

Essential Guide: Citrix SecurAccess with Chrome Enterprise

The way we access applications has changed. For decades, enterprise security architectures were built around a relatively simple model. Applications and data were centrally controlled, users connected from known locations and IT had a clearly defined perimeter to protect.

Cloud, SaaS, hybrid working and increasingly diverse endpoints have fundamentally changed that model. Today, the user sits at the centre of the digital workspace. Applications might be delivered through Citrix, accessed directly as SaaS services or consumed through a browser. Users move between corporate and personal devices, trusted and untrusted networks, offices, homes and public locations. That creates a different security challenge.

In the Essential Guide: Citrix SecurAccess with Chrome Enterprise, Al Taylor and Vipin Borkar explore these changes in more detail, including the evolution of VDI, the growth of SaaS, the importance of Chrome Enterprise, Zero Trust, device posture, browser security, AI and the opportunity to optimise the digital workspace.

If you’re responsible for Citrix, EUC, security or digital workspace strategy, it’s a conversation worth watching.

Watch the Essential Guide: Citrix SecurAccess with Chrome Enterprise:

Watch the Citrix SecurAccess with Chrome Enterprise podcast

The digital workspace is becoming user-centric

One of the biggest themes explored in the podcast is the change in where the enterprise security boundary sits.

Historically, organisations concentrated applications and data inside the corporate environment and provided controlled mechanisms for users to access them. VDI became an important part of that strategy because it allowed applications and desktops to remain centrally managed while being securely presented to remote users.

That model remains extremely valuable, particularly for Windows applications, sensitive workloads and applications that require centralised management. But the application landscape surrounding it has changed.

An increasing proportion of everyday business applications are now delivered through SaaS and the web. Microsoft 365, Salesforce, ServiceNow and thousands of other services are accessed primarily through a browser. Rather than replacing VDI, this creates an opportunity to rethink where VDI is necessary and where a different security model may be more appropriate.

 

The browser is becoming part of the enterprise security architecture

As applications move towards SaaS, the browser becomes significantly more important. It isn’t simply the application used to access the internet. For many employees, the browser is effectively becoming their primary enterprise workspace. That makes browser security increasingly important too.

Traditional security controls can determine whether somebody should be able to access an application. Modern organisations increasingly need to consider what happens once that access has been granted. What device is being used? What is its security posture? Where is the user connecting from? What application are they accessing? How sensitive is the data? What should that particular user be permitted to do with it? This is where the combination of Citrix SecurAccess and Chrome Enterprise becomes particularly interesting.

 

Moving from binary access decisions to dynamic security

Zero Trust is built around a simple principle: access should not automatically be trusted simply because somebody has successfully authenticated. Citrix SecurAccess extends this principle into application access. Instead of providing broad network-level connectivity, organisations can create application-specific access policies based upon identity, device posture and context. Access can therefore become much more closely aligned with the user and the application they actually need. Chrome Enterprise adds another layer of control at the browser.

Together, these technologies create the potential for organisations to make security decisions dynamically according to the user, endpoint, application and associated risk. A managed corporate endpoint accessing a relatively low-risk SaaS application may require very little intervention. The same application being accessed from an unmanaged device, unusual location or higher-risk context could require additional controls. The objective is not simply to block more activity. It is to apply the right level of security to the right user at the right time.

 

Rethinking the role of VDI

Perhaps one of the most interesting discussions in the podcast is what this means for VDI itself and the answer isn’t that VDI disappears. Windows applications, specialist workloads, legacy applications, sensitive datasets and applications requiring tightly controlled environments continue to make virtual desktops and applications extremely valuable, but organisations can begin to be more selective.

If an employee spends most of their working day inside SaaS applications, does every interaction necessarily need to take place inside a complete Windows virtual desktop? For some personas, the answer will remain yes. For others, Citrix SecurAccess with Chrome Enterprise could provide another approach.

This in turn opens the door to a more persona-led workspace strategy where the technology delivered to an employee is determined by what they actually need to do. That could mean a full Citrix virtual desktop for one user, published applications for another and secure browser-based SaaS access for somebody else.

 

Security and cost optimisation can work together

This has an important commercial dimension. VDI remains one of the most effective ways of centrally securing and delivering applications, but organisations shouldn’t necessarily use the same delivery model for every application and every user. Understanding which workloads genuinely require a virtual desktop and which can be securely delivered through the browser can create opportunities to optimise infrastructure and operational costs.

The important point is that this shouldn’t simply be a cost-reduction exercise. The goal is to create an architecture where the security controls follow the application, user and risk. Citrix SecurAccess with Chrome Enterprise gives organisations another option within that architecture.

 

AI makes the browser even more important

There is another reason this conversation matters now. AI is rapidly becoming embedded into everyday applications and increasingly into the browser itself. Employees are interacting with generative AI tools, copilots and AI-enabled SaaS services through the same browser they use to access corporate information. That makes understanding browser activity, controlling access and protecting sensitive information increasingly important.

As AI changes how users interact with applications and data, the browser is likely to become an even more significant enterprise security control point.

 

Start with personas, not products

For cloudDNA, one of the most important conclusions is that organisations shouldn’t begin this conversation by deciding which technology every user should receive. Start with the user…

Understand the applications they access, the devices they use, where they work, the sensitivity of the information they handle and the risks associated with their role. From there, organisations can determine the most appropriate combination of Citrix DaaS, published applications, SecurAccess and Chrome Enterprise.

This is why persona mapping is becoming increasingly important to modern Citrix strategy. Rather than treating every employee in the same way, organisations can build a workspace and security architecture around genuine user requirements and dynamically apply controls according to risk.

 

Considering how Citrix SecurAccess and Chrome Enterprise could fit into your existing Citrix strategy?

Get in touch to learn more about our Persona Mapping services and building a user-centric approach to application delivery and security powered by Citrix SecurAccess with Chrome Enterprise. Call 0330 010 3443 or mail hello@clouddnagroup.com.