Citrix · Software · YoctoIT tech page

Secure Private Access

Zero Trust Network Access for web apps and SaaS: access by identity and context — the VPN sent into retirement.

FOCUS · AFTER THE VPNAccess to the single app, not to the network: the ZTNA that reduces the surface
YoctoIT material for clients and partners · Citrix, NetScaler, HDX and the other products mentioned are trademarks of Cloud Software Group, Inc.
01 · What it is

Secure Private Access, made clear.

The VPN gives access to the NETWORK — too much trust, too much surface. Secure Private Access gives access to the single APP: the user authenticated (MFA) and evaluated (device, location, risk) reaches that internal web app or that SaaS, with adaptive security policies — watermark, no-download, closed clipboard — where the context requires it.

App-level
access to the app, not to the subnet: the lateral movement dies here
Adattivo
device and context decide the policies: trust earned, not presumed
Agentless
the web apps even without a client: the consultant served safely
Secure Private Access
OFFICIAL CITRIX BRANDING · SECURE PRIVATE ACCESS
CONSOLE REALE · SECURE PRIVATE ACCESS DASHBOARD · FONTE: CITRIX DOCS
REAL CONSOLE · SECURE PRIVATE ACCESS DASHBOARD · SOURCE: CITRIX DOCS
02 · How to use it well

The things that make the difference.

The ZTNA

Users and third partiesemployees, consultants, suppliers
Identity & MFA
Device posture
Policy adattive
who · with what · with what limits
Connectors toward the appsno ports open inbound
Internal web apps & SaaSthe application perimeter
The trust, verified at every access

The apps' inventory

Which internal apps serve whom: the map that turns the VPN into precise policies.

Civilized third parties

The supplier sees THEIR app and nothing else: external access without anxiety.

Security posture in the middle

Watermark, downloads and clipboard per context: the sensitive data watched closely.

Coexistence with the VPN

The transition in steps: first the web apps, then the rest — the VPN switches off last.

03 · In depth

Zero trust for web and SaaS: policy-driven access

Secure Private Access gives zero-trust access to the internal web apps and SaaS without a VPN: the adaptive policies (identity, device posture, network) decide per app (not per whole network), the session controls limit downloads, printing and clipboard on the sensitive apps, the browser isolation opens the risky remotely, the device posture check verifies the endpoint; the BYOD and the third parties access what's necessary and nothing else: the lateral movement dies at the start.

  • Per-app access — the app, not the network: the supplier sees one thing only
  • Policy adattive — identity+device+context: the access proportional to the risk
  • Session control — downloads and clipboard blocked on the sensitive apps
  • Browser isolation — the suspicious link detonated remotely: the endpoint doesn't touch
  • Device posture — patches and antivirus verified before the entrance
  • No VPN — no full-network tunnel: the per-application perimeter
04 · Numbers and lifecycle

The numbers that matter.

0
access to the network: only to the authorized apps
100%
of the sessions with channel controls
BYOD
covered without MDM: the posture suffices
terze parti
the prime use case: the supplier in the pen
The VPN is the legacy to overcome: app census, policies and rollout — zero trust in stages, guided by us.
05 · Use cases

Where it really pays off.

VPN replacement

Less surface, more control, happier users.

Supplier accesses

Maintainers and consultants, perimetered.

Fast M&A

The acquired company accesses the apps without merging the networks.

The VPN is wholesale trust; ZTNA is retail: we do the detailing — app by app.