Your VPN stays up for software pushes and a few old apps. The rest of your users shouldn’t be on the network at all — Citrix SecurAccess ZTNA joins each user to the private web, TCP/UDP and virtual apps they are allowed — agent or agentless, including server-to-client traffic — as part of the Citrix subscription you may already hold.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Citrix SecurAccess ZTNA — formerly Secure Private Access, including the Chrome Enterprise path. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A broker checks the user and the device, then connects them to one application, never to the network.
What consolidation actually replaces, dimension by dimension.
| Dimension | A VPN onto the network | Citrix SecurAccess ZTNA |
|---|---|---|
| What a remote user can see | The subnet the VPN drops them onto | Only the applications policy assigns |
| Software pushes to laptops | Wait until the user dials the VPN | Server-to-client app type, since 2408 |
| Contractor access | A VPN client on a laptop you don’t own | Agentless, through Chrome Enterprise |
| Device health | Checked once, at connection | Assessed through the session; revocable |
| Virtual apps and private apps | A gateway for one, a VPN for the other | One policy, with StoreFront integration |
| What it is NOT | — | A standalone SKU, an SSE suite, or India-hosted |
The cheapest test is a pilot beside the VPN: one web app, one TCP app and one server-to-client app for a single team.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Runs in Citrix Cloud or in a hybrid model, checks identity and device, then joins the user to one authorised application instead of placing the device on a network segment.
The agent path keeps assessing device posture through the session and tunnels TCP and UDP traffic, so ERP clients, database tools and file shares work beside web apps.
The agentless path, built on Chrome Enterprise Premium, opens internal web apps and supported RDP and SSH targets in Chrome, replacing the older Citrix Enterprise Browser.
Rules combine the IdP sign-in, MFA, CrowdStrike or Intune posture and geolocation, can revoke a live session, and can apply data-leak controls to what the user sees.
A cloud or hybrid broker that judges identity and posture — agent for managed laptops, Chrome Enterprise for the rest.
Citrix SecurAccess ZTNA connects users to applications, not to the network, with or without an agent.
Users reach only the private applications they are authorised for, so the rest of the estate stays invisible to them.
The agent tunnels TCP and UDP applications, so thick clients and internal tools move off the VPN, not only browser apps.
Since 2408 a server-to-client app type covers MECM software pushes, GPO updates and remote assistance to remote laptops.
Sign-in federates with Entra ID, Okta, Google Identity, Active Directory or any SAML 2.0 provider, with MFA on top.
CrowdStrike and Intune feed device state into each decision, beside machine-based authentication of the device itself.
Geolocation joins identity and posture in policy, so a sign-in from an unexpected country can be blocked or restricted.
Dynamic access revocation ends a live session when posture or risk changes, rather than waiting for the next sign-in.
Adaptive data-leak controls can restrict what a user does with an app’s content once inside, set per application.
Administrators and vendors open RDP and SSH targets from Chrome, so server access needs neither a VPN nor a client.
Citrix’s own overview, agentless RDP and SSH for administrators, access from personal devices, and the Chrome Enterprise path.
Citrix’s own introduction to the renamed product and its per-application model.
Admin RDP and SSH sessions opened in a browser, with no agent and no VPN.
How personal and contractor devices are handled without managing them.
The Chrome Enterprise path that is replacing the Citrix Enterprise Browser.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Release 2408 added an app type for connections that start on the server: MECM software distribution, Group Policy pushes and remote assistance, the traffic that keeps many VPNs alive. It needs Windows client 24.6.1.18 or macOS 24.06.2 and later, so check versions first.
SecurAccess covers private web, TCP and UDP apps and SaaS, and StoreFront integration brings Citrix virtual apps under the same policy. A DaaS estate can leave the VPN without adding a second access vendor, client or admin console.
Managed laptops use the agent, which checks posture continuously and can draw on CrowdStrike and Intune. Contractors and personal devices use SecurAccess with Chrome Enterprise, with nothing to install. Both run beside the existing VPN, so apps move one at a time.
It is not sold alone: UHMC caps it at one ZTNA user per licence, the Citrix Platform licence makes it unlimited, and the Chrome path needs the Platform licence. Citrix Cloud has no Indian region, no ZTNA customer is named, and no analyst placement exists.
List every app still on the VPN as web, TCP/UDP, RDP/SSH, virtual app or server-to-client, and note who uses each.
Check whether you hold UHMC or the Platform licence, how many ZTNA users that gives, and if the Chrome path is in it.
Connect the IdP, add CrowdStrike or Intune posture, and move one web app and one TCP app for a pilot group first.
Upgrade clients to 24.6.1.18 or later, publish MECM and remote-assistance apps as server-to-client, and test them.
Give contractors the Chrome Enterprise path for web, RDP and SSH, then shrink the VPN user list by named group.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“MECM pushes to home laptops were our reason to keep the VPN. The server-to-client app type finally let us switch it off.”
“We already had UHMC for virtual desktops, so private web apps moved over with no new contract and the same StoreFront.”
“Auditors open two web apps through Chrome Enterprise with nothing installed. The approval took a day, not a laptop shipment.”
“Intune compliance feeds the policy, so a lapsed laptop loses ERP access by itself; we no longer chase people by email.”
“Check client versions first. Older agents ignored the server-initiated apps until we upgraded the fleet to 24.6.”
“Good product, but you price a whole Citrix subscription to get it. Without DaaS in the estate the maths was hard to justify.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the zero trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Inside UHMC or the Citrix Platform licence; never sold alone.
The grid nobody publishes — how much traffic the broker can carry, server-initiated included, vs how much Indian presence is documented.
Server-to-client apps native since 2408; no Indian region.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler Private Access, Netskope One Private Access, Palo Alto Prisma Access, Cloudflare Access and Akamai EAA — on reach, posture, price, bundling and India.
| Dimension | Citrix SecurAccess ZTNA | Zscaler Private Access (ZPA) | Netskope One Private Access | Palo Alto Prisma Access (ZTNA) | Cloudflare Access (Cloudflare One) | Akamai Enterprise Application Access |
|---|---|---|---|---|---|---|
| What it is | Citrix’s ZTNA component | Zscaler’s VPN successor | Netskope One module | Half of Prisma Access | Part of Cloudflare One | Akamai’s per-app access |
| Deployment and connectors | Cloud or hybrid | Outbound App Connectors | Brokered in NewEdge | Prisma cloud locations | Cloudflare Tunnel | VMs or containers |
| Access modes | Agent + Chrome path | Client + browser | Universal ZTNA | GlobalProtect + browser | WARP + browser | Clientless + client |
| Apps and protocols | Web, TCP/UDP, virtual | Web, SSH, RDP, desktop | Broadest documented | Web, SSH, RDP, desktop | Web plus SSH and RDP | Web, RDP, SSH, TCP/UDP |
| Server-initiated traffic | Native since 2408 | Extra appliance | Documented natively | Not established | Not established | Not documented |
| Device posture | Continuous, EDR + MDM | Re-evaluated in session | Every request checked | Agent and browser | Per-app posture rules | Client checks + EDR |
| Identity and SSO | SAML, conditional MFA | SAML, OIDC, SCIM | SAML, OIDC, SCIM | Plus conditional access | SAML, OIDC, SCIM | SAML, OIDC, SCIM |
| Data controls in session | Adaptive leak controls | Separate product line | Shared DLP rules | In the same service | Elsewhere in the suite | Other Akamai products |
| Scale evidence | No ZTNA customer named | Widest deployment | Past 5,000 users | Past 5,000 users | Past 5,000 users | One name, no size |
| Pricing model | Inside a subscription | Per user, by edition | Per user, platform-tied | Per user a year | Free tier, then per user | Quote, unit unstated |
| Published entry price | Not published | ~$6–11 reported | Not published | Not published | $0 to 50, then $7 | Not published |
| Standalone or bundled | Not standalone | Standalone | Platform module | Not standalone | Standalone | Own product, free trial |
| India presence | No Indian region | Cities unconfirmed | 8 Indian data centres | Mumbai since 2021 | 6 Indian cities | No EAA PoP named |
| Best fit | Citrix DaaS estates | Large VPN retirements | Awkward app lists | Palo Alto NGFW shops | Fast, priced start | Akamai customers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Citrix SecurAccess ZTNA is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (remote users still on the VPN; IT staff-hour cost). Estimates model IT time spent on VPN tickets, access requests, client fixes and off-network patching at an assumed 1.5 hours per remote user a year, with 70% of it removed by per-app access. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not sold on its own: Citrix publishes no price for any current offering. SecurAccess ZTNA comes inside Universal Hybrid Multi-Cloud, limited to one ZTNA user per UHMC licence, or unlimited in the Citrix Platform licence, both quoted per user; the agentless Chrome Enterprise path needs the Platform licence or Platform Flex. TechBag checks your existing entitlement first, then quotes any change in INR with GST.
Best for DaaS estates moving some users
Best for a broader rollout
Best for estates retiring the VPN fully
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do you hold UHMC or the Citrix Platform licence? UHMC caps ZTNA users at your UHMC count; the Platform licence does not.
Will contractors use Chrome Enterprise? That path needs the Platform licence, and US public sector cannot use it.
Which VPN apps are web, TCP/UDP, RDP/SSH or server-to-client? Each type needs its own pilot test.
Are Windows clients at 24.6.1.18 and macOS at 24.06.2 or later? Server-to-client apps need those versions.
Which IdP will you federate — Entra ID, Okta, Google, AD or another SAML 2.0 source — and which MFA rules apply?
Will CrowdStrike, Intune or both feed device state, and what should happen to a session when posture fails?
Is a US, EU or Asia Pacific South control plane acceptable to your auditors? Citrix Cloud offers no Indian region.
Which apps stay on the VPN, and by when will that list be empty? Write the date into the project plan.
Model how many remote users still depend on the VPN first, or let a TechBag advisor check what your Citrix subscription already entitles you to.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.