Give users access to apps, not your network

Citrix SecurAccess ZTNA, helps organizations replace broad network access with secure, application-level access. Users, contractors, partners, and third parties connect only to the specific applications they are authorized to use — without exposing the broader corporate network.

Secure access for the applications people actually need

Citrix SecurAccess ZTNA helps IT teams provide access at the right level: the application. Instead of extending trust across the network, organizations can connect users to approved private, web, SaaS, and hybrid applications based on identity, device, and context. 

Compared to a VPN, Citrix SecurAccess ZTNA delivers more flexible connectivity and better security

Three avatars together icon

Remote and hybrid work

Liberate your workers from slow and glitchy VPNs with fast direct access to applications based on their identity

A phone, tablet and laptop in front one another icon

BYOD programs

Give your workers the freedom to use their personal devices (bring your own device, or BYOD) to securely access corporate resources in compliance with corporate security policies

Cloud on top of two stacked servers icon

Hybrid environments

Ensure consistent security policies for worker access to applications hosted across on-premises and cloud environments

Capabilities of Citrix SecurAccess ZTNA

Identity aware

Before establishing a session, Citrix SecurAccess ZTNA evaluates user identity and device posture to inform contextual access policies and single sign-on.

Citrix StoreFront integration

Citrix SecurAccess ZTNA integrates with Citrix StoreFront to provide a single access point for approved applications. Users can access web, SaaS, virtual applications, and desktops through a consistent SSO experience.

Adaptive authentication

Identity-aware authentication, including MFA, helps verify users before access is granted. Authentication requirements can adapt based on risk, with additional verification applied when users access sensitive applications or higher-risk resources.

Logging and monitoring

Detailed logging and monitoring help you meet regulatory requirements and improve your overall security posture.

Zero trust context

Citrix SecurAccess ZTNA continuously evaluates access based on identity, device posture, location, and network context. Policies can dynamically allow, restrict, or require additional authentication as risk changes.

User identity

  • Identity integration: Integrates with IAM providers including Cisco Duo, Ping, Entra ID, and Okta, with support for SSO and MFA.
  • Role-based access: Applies least-privilege access based on user roles and permissions.

Device posture

  • Continous assesment: Evaluates device security and compliance signals, such as OS status and endpoint security, before and during access.

Location and network context

  • Location-aware access: Adjusts policies based on geographic location and associated risk.
  • Network trust: Applies additional controls or blocks access from unknown or untrusted networks.

Flexible access

Citrix SecurAccess ZTNA supports both agent-based and agentless access, so you can apply the right level of control for different users, devices, and applications.

Agent-based secure access

Best for managed devices and environments requiring deeper endpoint controls.

  • Continuous device posture assesment
  • Advanced endpoint and access controls
  • Dynamic access enforcement
  • Secure tunneling and encryption

Agentless browser-based secure access

Best for unmanaged devices, contractors, partners, and temporary access.

  • No software installation required
  • Browser-based access to approved applications
  • Faster onboarding for BYOD and third parties
  • Continuous policy enforcement

 

Application aware

Instead of granting broad network access, Citrix SecurAccess ZTNA provides access only to authorized applications, reducing exposure to unnecessary network resources.

Application-specific access controls include:

  • Granular access: Grant access to specific applications based on user authorization.
  • Contextual policy enforcement: Apply policies based on identity, device posture, role, and other risk signals.
  • Continuous monitoring: Reevaluate access as context changes and require additional verification or revoke access when needed.

ANALYST REPORT

Careful considerations for choosing a zero trust network access product and vendor

IDC logo

What makes ZTNA with Citrix different

Citrix SecurAccess ZTNA extends zero trust access across virtual, web, SaaS, and client-server applications without adding another point solution.

Faster deployment

  • Deploy as a cloud service or in a hybrid model.

Simpler management

  • Manage secure access and application delivery through familiar Citrix tools.
  • Gain end-to-end visibility and troubleshooting with Citrix Director and  Citrix uberAgent® .

Consistent security

  • Apply common identity, device posture, and contextual access policies across application types.
  • Integrate with leading identity providers and enforce granular, least-privilege access.

Better end-user experience

  • Give users SSO access to approved applications through a consistent Citrix experience.
  • Provide secure access from different devices and locations without relying on traditional network-level VPN access.

Why Citrix SecurAccess ZTNA is different

Give users access to apps, not the network

Provide application-level access to private, web, SaaS, and virtual applications without exposing the broader network. Support employees, contractors, partners, and other third parties with least-privilege access based on what they actually need.

Modernize access without rebuilding your environment

Extend zero trust access to both modern and legacy applications, including apps that rely on existing authentication methods. Run ZTNA alongside VPN infrastructure and migrate users and applications at your own pace instead of requiring a disruptive replacement.

Get more from your existing Citrix investment

Extend secure access through the Citrix environment customers already use for application delivery and management. Bring access, administration, visibility, and troubleshooting into familiar Citrix workflows while reducing the need for additional point solutions.

Key use cases for Citrix SecurAccess ZTNA

Secure employee access to private applications

Give employees access to the specific private web, TCP, and UDP applications they need without extending broad network access. Apply identity, device posture, and contextual policies while supporting both managed devices and existing enterprise applications.

Controlled access for contractors, partners, and BYOD

Provide third parties and users on unmanaged devices with access only to authorized applications, without placing their devices on the corporate network. Agentless browser-based access can simplify onboarding while reducing unnecessary exposure.

Modernize VPN access without a disruptive migration

Move applications and users from network-level VPN access to application-level ZTNA incrementally. Organizations can run VPN and ZTNA alongside one another while transitioning appropriate workloads to least-privilege access.

Capabilities of Citrix SecurAccess ZTNA

Before initiating a session, Citrix SecurAccess ZTNA verifies a user's identity using single sign-on, device posture assessment, multi-factor authentication (MFA), and adaptive authentication. After establishing a secure session, continuous monitoring ensures adherence to security policies.

  • Acts as an identity broker for M&A scenarios
  • User authentication across Microsoft Entra ID, Okta, Google Identity, Active Directory, SAML 2.0 IdP, and more
  • Attribute-based IdP selection for authentication
  • Conditional-authentication with multi-factor authentication MFA
  • Machine-based authentication

Citrix SecurAccess ZTNA employs the zero trust principle of "never trust, always verify" to continually validate access to applications and data. Access policies adapt dynamically based on contextual factors such as user location, device status, and network trust. For instance, access may be restricted or additional authentication required if a user connects from an untrusted network.

  • Device posture checks
  • Generic and vendor-specific checks
  • CrowdStrike and Intune integration
  • Network location and geolocation
  • Continuous monitoring and enforcement
  • Dynamic access revocation
  • Adaptive data leak security controls

Citrix SecurAccess ZTNA offers flexible choices for secure access with both agent-based and agentless options, providing a balance between advanced security and convenience for the user.

  • Agentless with Citrix SecurAccessTM with Chrome Enterprise for web and SaaS applications
  • Agentless with native browser for web applications
  • Agent-based for TCP and UDP applications
  • Managed and unmanaged devices
  • Employees, partners, and contractors

Citrix SecurAccess ZTNA enforces policies that provide access to specific applications rather than broad network access. This approach minimizes the attack surface by ensuring that users can only access the applications necessary for their job roles.

  • FQDN, IP: port: protocol, IP range, CIDR block, domain name (single or wildcard)
  • Automated application discovery and publishing
  • Policy definitions, intuitive rule builder
  • Single sign-on support (SSO)
  • SAML
  • Kerberos
  • Form-based
  • Basic

RESOURCES

Learn more about Citrix SecurAccess ZTNA

Purple diagram
Technical brief
Tech brief: Citrix SecurAccess ZTNA
Woman on laptop with city night view
Blog
How to set up BYOD users with cloud-hosted virtual desktops for zero trust network access to private applications
Blue diagram
Data sheet
Data sheet: Citrix SecurAccess ZTNA