Download the Citrix Workspace App
Citrix Workspace app is the easy-to-install client software that provides seamless secure access to everything you need to get work done.
Citrix SecurAccess ZTNA, helps organizations replace broad network access with secure, application-level access. Users, contractors, partners, and third parties connect only to the specific applications they are authorized to use — without exposing the broader corporate network.
Citrix SecurAccess ZTNA helps IT teams provide access at the right level: the application. Instead of extending trust across the network, organizations can connect users to approved private, web, SaaS, and hybrid applications based on identity, device, and context.
Liberate your workers from slow and glitchy VPNs with fast direct access to applications based on their identity
Give your workers the freedom to use their personal devices (bring your own device, or BYOD) to securely access corporate resources in compliance with corporate security policies
Ensure consistent security policies for worker access to applications hosted across on-premises and cloud environments
Before establishing a session, Citrix SecurAccess ZTNA evaluates user identity and device posture to inform contextual access policies and single sign-on.
Citrix SecurAccess ZTNA integrates with Citrix StoreFront™ to provide a single access point for approved applications. Users can access web, SaaS, virtual applications, and desktops through a consistent SSO experience.
Identity-aware authentication, including MFA, helps verify users before access is granted. Authentication requirements can adapt based on risk, with additional verification applied when users access sensitive applications or higher-risk resources.
Detailed logging and monitoring help you meet regulatory requirements and improve your overall security posture.
Citrix SecurAccess ZTNA continuously evaluates access based on identity, device posture, location, and network context. Policies can dynamically allow, restrict, or require additional authentication as risk changes.
Citrix SecurAccess ZTNA supports both agent-based and agentless access, so you can apply the right level of control for different users, devices, and applications.
Best for managed devices and environments requiring deeper endpoint controls.
Best for unmanaged devices, contractors, partners, and temporary access.
Instead of granting broad network access, Citrix SecurAccess ZTNA provides access only to authorized applications, reducing exposure to unnecessary network resources.
Application-specific access controls include:
ANALYST REPORT
Citrix SecurAccess ZTNA extends zero trust access across virtual, web, SaaS, and client-server applications without adding another point solution.
Routes traffic entirely through your on-premises Citrix DaaS environment, making it easier to get security approval because it uses existing approved components
Works seamlessly with modern authentication methods as well as legacy authentication methods like Kerberos and NTLM; supports form-based authentication; and eliminates the need to rewrite authentication protocols for legacy applications
Supports attribute-based identity providers, which is a common use case for M&A
Provides secure access on a per-application basis from cloud VDI to internal applications in a data center or private cloud without using Azure ExpressRoute or any other VPN solution; uses microsegmentation for granular access control to on-premises resources from cloud VDI; and supports single and multi-session VDI
Provides a seamless workflow for admins to configure end-user access permissions for launching web applications in a remote browser in the cloud
Integrates with Citrix StoreFront — a secure portal that uses SSO to enforce access policies at a single point — which conveniently allows users to access all of their approved applications, including web and SaaS applications as well as VDI applications, in one place
Provides a much simpler admin experience because admins can click a button in Citrix Web Studio to access the Citrix SecurAccess ZTNA UI to configure access to web and SaaS applications
Makes it easy to pinpoint issues because a single admin portal for management and operations and the use of a single tool, Citrix Director, streamlines help desk triage and the troubleshooting of virtual and private applications
Enables a seamless transition from VPN to ZTNA on an end-user device because NetScaler Gateway (configured as a VPN) and the Citrix SecurAccess ZTNA agent are built with the same code base, allowing for a smooth and phased VPN-to-ZTNA migration instead of a forklift approach
Complements secure web gateway (SWG) and cloud access security broker (CASB) controls offered by SASE/SSE vendors for securing external traffic
Provides secure access to all applications — including web and SaaS applications in addition to proprietary applications and VDI applications — on-premises and in the cloud, effectively reducing the complexity of managing multiple ZTNA solutions
Comes included in the Citrix Platform and Universal Hybrid Multi-Cloud License, providing the opportunity for both vendor and cost consolidation
A modern zero-trust security model is preferable to traditional perimeter security, but you can begin implementing zero-trust capabilities in a phased approach while also using a VPN. It’s common to start with ZTNA for unmanaged devices for remote and hybrid employees and contractors as a first step.
Citrix SecurAccess ZTNA provides better company data protection and context-based authentication to provide just-enough access rights to employees' required resources. Allowing employees to access private web applications using their preferred browsers improves the user experience. Employees can also access client-server (TCP and UDP) applications without any additional setup by admins, making the access process seamless and hassle free for IT and employees.
Citrix SecurAccess ZTNA provides secure and contextual-based access to SaaS and internal web applications through a unified portal or direct link using a native browser. Applications configured with contextual policies will launch in an isolated remote browser to mitigate threats, enforce additional security policies, and protect sensitive data by creating an air gap between the user's device and the application.
Allowing employees, partners, and contractors to use their own devices can pose a security risk. To mitigate this risk, companies deploy VDI in the cloud, isolated from their company networks. After users log on to their cloud desktops, Citrix SecurAccess ZTNA automatically establishes a secure connection to the company network, granting the user access to private applications using a zero-trust approach. This robust security measure ensures data security and provides an air gap between the user's device and the company network.
Maintaining and securing company devices can be difficult, especially the devices of remote employees and employees who travel frequently. Citrix SecurAccess ZTNA helps IT admins establish a zero-trust-based machine tunnel after the device starts, which allows devices to remain compliant so that company application and data access can be granted.
Before initiating a session, Citrix SecurAccess ZTNA verifies a user's identity using single sign-on, device posture assessment, multi-factor authentication (MFA), and adaptive authentication. After establishing a secure session, continuous monitoring ensures adherence to security policies.
Citrix SecurAccess ZTNA employs the zero trust principle of "never trust, always verify" to continually validate access to applications and data. Access policies adapt dynamically based on contextual factors such as user location, device status, and network trust. For instance, access may be restricted or additional authentication required if a user connects from an untrusted network.
Citrix SecurAccess ZTNA offers flexible choices for secure access with both agent-based and agentless options, providing a balance between advanced security and convenience for the user.
Citrix SecurAccess ZTNA enforces policies that provide access to specific applications rather than broad network access. This approach minimizes the attack surface by ensuring that users can only access the applications necessary for their job roles.
RESOURCES