FortressPoint. Strong foundations. Clear governance. Confident security.
Cloud & Azure SecurityAzure Virtual DesktopCitrixCloud MigrationZscaler

From Citrix to Azure Virtual Desktop: security architecture considerations

Published 17 August 20267 min readFortressPoint
From Citrix to Azure Virtual Desktop: security architecture considerations

The migration from Citrix Virtual Apps and Desktops to Microsoft Azure Virtual Desktop (AVD) is one of the most common infrastructure transformation projects in the enterprise market today. For security architects, this migration represents both a significant risk if security controls are not replicated or enhanced, and an opportunity to modernise the security posture of the virtual desktop environment.

The most important architectural decision in a Citrix-to-AVD migration from a security perspective is how to handle network security and internet access control. In many Citrix environments, internet traffic from virtual desktops is routed through on-premises proxy infrastructure or Citrix Cloud Connectors. In AVD, the equivalent control is typically provided by Zscaler Internet Access (ZIA) deployed via the Zscaler Client Connector (ZCC) agent on each AVD session host.

The ZCC agent approach for AVD differs fundamentally from the Cloud Connector approach used in Citrix environments. Where Cloud Connectors are agentless infrastructure components, ZCC is a per-user agent that must be installed on each AVD session host and roams with the user profile via FSLogix. This means FSLogix profile management becomes effectively mandatory in pooled AVD host pools where ZCC is deployed without roaming profiles, ZCC registration state is lost between sessions.

For personal AVD host pools, the FSLogix dependency is less critical since users are assigned to specific VMs. However, for pooled host pools where users may land on any available session host FSLogix is essential for maintaining ZCC registration and ensuring consistent security policy enforcement regardless of which host the user connects to.

Identity security in AVD is significantly enhanced compared to traditional Citrix deployments because AVD integrates natively with Microsoft Entra ID. Conditional Access policies can be applied to AVD connections, requiring compliant devices, MFA, and enforcing session controls. This level of identity-aware access control is more difficult to achieve in on-premises Citrix environments.

FortressPoint's approach to Citrix-to-AVD security migrations follows a structured assess-design-deploy methodology. We begin with a security architecture review of the existing Citrix environment, identify all security controls that must be replicated in AVD, and produce a delta guide documenting net-new controls required. This ensures no security capability is lost in the transition.

Related services

All insights

Have a security question?

Speak with a FortressPoint consultant. We engage with specific questions, not just general enquiries.