From VPN to Zero Trust with Citrix Secure Private Access

Citrix Secure Private Access with ZTNA access to private apps via hybrid environment

Estimated reading time: 6 minutes

Many organizations have a VPN. But frankly, that thing has worked like an open door for years: anyone who gets through it gets access to the entire network. That used to be acceptable. Now it’s not. Ransomware, data breaches and home workers with unattended laptops have changed the rules of the game. And yet much of SMBs still run on that same old VPN infrastructure.

Citrix has a concrete answer to that: Citrix Secure Private Access (SPA). And recently the entitlement for UHMC (Universal Hybrid Multi-Cloud) customers was expanded considerably. What that means for your organization, we clearly explain here.

What is Citrix Secure Private Access?

Citrix Secure Private Access is a security solution that works on the basis of Zero Trust Network Access (ZTNA). In plain language, users get access only to the specific application they need, not to the broader network behind it.

Compare it to an office building where visitors are not allowed to just walk down all the hallways. They are given a pass for exactly that one meeting room. That’s the principle of least-privilege access: minimum access, maximum control.

SPA is suitable for environments with a mix of on-premises applications, cloud applications and SaaS services. And also for employees logging in from unmanaged devices, such as home laptops or remote partner devices.

VPN versus Zero Trust: what’s the difference?

This is the question we hear most often from IT managers. Here’s the gist of it:

  • VPN provides network access. Once connected, you can access anything on that network.
  • ZTNA provides application access. You get access only to what you need at the time.
  • VPN trusts everyone who connects. ZTNA continuously verifies: who are you, what device are you logging in from, and what are you allowed to see?
  • In a VPN breach, an attacker can move laterally through the network. With ZTNA, the blast radius is limited to the application to which the compromised user had access.

That last point is crucial. IBM research shows that the average dataBreach will cost organizations more than $4.8 million by 2024. Much of that damage occurs because attackers can move unhindered through the network once they are inside.

What has changed for UHMC customers?

In early March 2026, Citrix announced that UHMC customers will now have full access to Citrix Secure Private Access. Previously, the use of SPA within the UHMC license was limited to Windows 365 scenarios. That has now been extended to broader ZTNA and VPN replacement.

Specifically, UHMC customers can now do the following:

  • Extend ZTNA access to private apps, allowing users to access only at the application level rather than at the network level.
  • Provide access to external partners and contractors with fine-grained, controlled access patterns.
  • Apply a consistent security approach across hybrid environments, including on-premises data paths and cloud services.
  • Phase out VPN dependence step by step without disrupting continuity for legacy applications that still need VPN-like connections.

No action is required from the customer: the extended rights are immediately available within the existing UHMC license.

The risks of doing nothing

Many organizations know that their VPN infrastructure no longer fits their current workflow. Yet they continue to work with it because the move to something new feels uncertain. We understand that. But the risks of sitting still are now greater than the risks of changing.

  • Larger attack surface: a VPN gives direct access to the entire network if misused.
  • Little visibility: with traditional VPNs, it is difficult to see who accessed which systems when.
  • Compliance risk: increasing regulations (NIS2, ISO 27001, AVG) require demonstrable management of access rights.
  • Poor user experience: VPNs are slower, more prone to failure and more difficult to manage than modern ZTNA solutions.

What does work: a phased approach

The beauty of Citrix Secure Private Access is that it doesn’t require a big-bang migration. You can make the switch in phases. In practice, that often looks like this:

  1. Start with new use cases: give external employees or contractors ZTNA access while existing internal users still work through VPN.
  2. Extend to critical applications: migrate the applications most at risk to ZTNA first.
  3. Keep legacy in the air: for legacy systems that still need VPN-like connections, SPA also supports VPN replacement scenarios.
  4. Phase out VPN completely: once all applications are migrated, disable the VPN infrastructure.

This is exactly what Citrix means by a ZTNA-first approach that still provides continuity for existing environments. You don’t have to break anything to get started.

Common objections, answered honestly

“We have no capacity for such a migration.”

Understandable. But because SPA can run alongside your existing VPN, you don’t have to flip everything at once. You can start small, with a specific group of users or a set of applications.

“Our employees already complain about Citrix, why would this be better?”

We hear that more often than not. And frankly, the problem rarely lies with Citrix itself. Slow login? That’s usually a problem with profiles, storage or an antivirus package scanning everything in the background. Citrix is the endpoint where problems become visible, not where they originate. SPA solves the security side; you do the performance analysis separately.

“We want to switch to AVD, then we don’t need this, do we?”

AVD and ZTNA are not alternatives to each other. AVD replaces your virtual desktop platform, but the question of how to securely control access remains. Indeed, in an AVD environment, you want ZTNA precisely to prevent unmanaged devices from gaining wide network access.

“This sounds complex and expensive.”

For UHMC customers, the expansion is immediately available at no additional cost. And the complexity is not so bad if you do it in phases with a partner who knows the environment.

Practical checklist: are you ready for ZTNA?

  • Check if you have an active UHMC license. If so, SPA is already available.
  • Map which user groups are most at risk (remote workers, contractors, users on unattended devices).
  • Inventory which applications are now accessible via VPN and which ones can go to ZTNA first.
  • Look at your current access policies: are there roles that have more access than necessary?
  • Verify that your environment meets the minimum version requirements for SPA (see Citrix documentation).
  • Plan a pilot group and set measurable goals for the pilot (fewer VPN incidents, faster access provisioning, better compliance reporting).

From VPN to Zero Trust: how New Yard is tackling it

At New Yard, we always look at the entire digital workplace, not individual products. In that, security is not a department in itself, but a feature of your entire environment. From the Identity to the application, from the network to the endpoint.

We help organizations move from traditional VPN to Zero Trust in a way that fits their pace and infrastructure. No forced big-bang migrations, but an approach that works in the real world: with legacy systems, limited IT capacity and users who just want to be able to work.

Want to know what this means for your area?

We are happy to schedule a no-obligation introductory meeting with you. No sales talk, but an honest conversation about where you are now and what step makes sense first. Contact us via newyard.nl.