Citrix launched its cloud-based zero-trust network access (ZTNA) platform today, which it claims is completely transparent to remote users.

The service, dubbed Citrix Secure Private Access, is the latest in the vendor’s arsenal of secure access service edge (SASE) software. The platform is designed to protect access to applications and services regardless of whether the end user is working in the branch, remotely, or from a managed or unmanaged device.

A ZTNA Dimmer Switch

Most vendors think of zero trust as an on and off switch, Vishal Ganeriwala, VP of product marketing at Citrix, told SDxCentral in an interview.

“Either you as a user have access to an application or you don’t,” he said. “We looked at this problem slightly differently. … What if we change that from this on and off switch to more of a dimmer switch?”

Citrix’s approach is to provide access to applications and application functionality — copy and paste for example — based on factors like user identity, location, and whether they’re using a managed or unmanaged device. This, Ganeriwala explained, allows IT teams to assign policies that provide unlimited access to most applications while restricting access to sensitive data to certain environments like managed devices or a corporate office.

“If you are working on a corporate-managed device with proper endpoint management software installed and all the agents, you'll be able to cut, copy, paste, and other activities you would likely do,” he explained.

And access can be revoked on the fly if the user exhibits suspicious behavior.

Citrix Champions Flexible Deployment

The service includes a bevy of security functionality including application watermarking, clipboard restrictions, keylogging and screen capture prevention, and integrated browser isolation, which can be delivered in both agent and agentless models.

“With an agent, you obviously get deeper functionality and more functionality,” Ganeriwala said, adding that without the agent the service acts as a cloud-based reverse proxy, which while unable to block access to things like copy and paste, can still apply conditional access based on the user’s identity and location.

The ZTNA service is hosted in 40 points of presence (PoPs) running in Google Cloud Platform (GCP), Microsoft Azure, and Amazon Web Services (AWS). For customers that aren’t ready to embrace cloud-based security, the platform can also be deployed as an on-premises appliance.

According to Ganeriwala, some larger customers are using a combination of cloud and on-premises deployments to address regional and geographic challenges, which make a fully cloud-delivered ZTNA impractical.

Citrix Gets SASE-er

This is Citrix's latest move toward a SASE architecture. The company already offers SD-WAN, secure web gateway, and web application and API protections as standalone applications. Together, these services form the basis of Citrix's SASE bundle.

Gartner recently ranked Citrix a “challenger” in its latest WAN Edge Infrastructure Magic Quadrant report.

“Citrix has one of the broadest set of capabilities, including SD-WAN, application performance optimization, security, and cloud connectivity of any vendor in this market,” the report read.

However, Gartner warned that the company’s go-to-market strategy is geographically limited when it comes to service providers, which could hurt its growth potential. Additionally, Gartner found that Citrix's market visibility is not as strong as its competitors, and the company isn’t seen as a networking vendor.