Disclosure: We may earn commissions from partner links on this site. This does not affect our independent editorial reviews. All opinions are our own. Full disclosure.
Splashtop Secure Workspace: Zero Trust, Device Identity & Access Control
Splashtop Secure Workspace is a zero-trust remote access solution that verifies device identity, certificate status, and compliance posture before granting access to corporate resources. It replaces traditional VPN with identity-first access controls and integrates with Foxpass Cloud RADIUS for certificate-based Wi-Fi and VPN authentication.
How Secure Workspace Works
Secure Workspace implements the core principles of zero-trust network access (ZTNA): no implicit trust based on network location, continuous device verification, and least-privilege access. Every access request is evaluated against real-time device state before being allowed or denied.
- Device identity: Each managed device receives an X.509 certificate from the Splashtop PKI (or an integrated enterprise CA)
- Posture verification: OS version, patch status, security software, and compliance state are checked before access is granted
- Certificate-based authentication: Devices present certificates for EAP-TLS Wi-Fi authentication and VPN access — no passwords
- Continuous trust: Device posture is re-evaluated during each session; non-compliant devices are disconnected
Key Capabilities
Device Identity & PKI
- Managed PKI for issuing, renewing, and revoking device certificates
- Integration with existing enterprise CAs (Active Directory CS, EJBCA)
- Automated certificate lifecycle management
- BYOD certificate installer for non-managed devices
Network Access Control
- Device posture-based access decisions (OS, patches, security software)
- Group-based access policies per resource or network segment
- Time-based and location-based access restrictions
- Micro-segmentation for granular resource control
Foxpass Integration
- Cloud RADIUS for certificate-based Wi-Fi authentication (EAP-TLS)
- Cloud LDAP for legacy application authentication
- Directory sync with Entra ID, Google Workspace, Okta, OneLogin
- Group-based VLAN assignment and network segmentation
Secure Workspace vs. Enterprise vs. ZTNA Solutions
| Feature | Splashtop Secure Workspace | Splashtop Enterprise | Citrix Zero Trust | Zscaler Private Access | Action |
|---|---|---|---|---|---|
| Zero-Trust Architecture | Yes (identity-first) | Partial (remote desktop only) | Yes (full ZTNA) | Yes (ZTNA) | |
| Device Identity/Certificates | Yes (X.509 PKI) | Device authentication | Yes | Yes (client cert) | |
| Network Access Control | Yes (posture-based) | IP allowlist, time-based | Yes | Yes | |
| MDM Integration | Intune, Jamf, Addigy | Limited | Intune, Workspace ONE | No (agent-based) | |
| Cloud RADIUS | Yes (Foxpass) | No | No | No | |
| Certificate-Based Auth | Yes (EAP-TLS) | No | Yes | Yes | |
| On-Premise Option | Yes | Yes (on-prem gateway) | Yes | No (cloud only) | |
| Wi-Fi Authentication | Yes (EAP-TLS via Foxpass) | No | No | No | |
| VPN Replacement | Yes | No | Yes | Yes | |
| Pricing | Custom (contact sales) | Custom | Enterprise pricing | Per-user pricing |
Deployment Architecture
- Cloud deployment: Splashtop hosts the identity verification and certificate management infrastructure
- On-premise: Deploy the Secure Workspace gateway behind your firewall for air-gapped or data-sovereignty environments
- Hybrid: Cloud-based identity verification with on-premise resource access — the gateway connects to your internal resources while Splashtop handles identity
Frequently Asked Questions
What is Splashtop Secure Workspace?
Splashtop Secure Workspace is a zero-trust remote access solution that combines device identity, certificate-based authentication, and network access control. It provides identity-first access to corporate resources — replacing traditional VPN with device posture verification and continuous trust assessment. Secure Workspace is built on the Splashtop platform and integrates with Foxpass Cloud RADIUS for Wi-Fi and VPN authentication.
How does Secure Workspace differ from Splashtop Enterprise?
Splashtop Enterprise focuses on remote desktop access (connecting to a specific computer). Secure Workspace focuses on zero-trust network access — verifying device identity, certificate status, and compliance posture before granting access to any resource. Enterprise provides remote desktop; Secure Workspace provides network-level zero-trust controls. They can be deployed together for a complete remote access + zero-trust architecture.
Does Secure Workspace support zero-trust network access?
Yes. Secure Workspace implements zero-trust principles: no implicit trust based on network location, continuous device verification, least-privilege access, and micro-segmentation. Devices must present valid certificates and meet compliance posture requirements before accessing resources. Access decisions are made per-session, per-resource, based on real-time device state.
What is device identity in Secure Workspace?
Device identity uses X.509 certificates to uniquely identify and authenticate devices. Each managed device receives a certificate from the Splashtop PKI (or an integrated enterprise CA). The certificate is presented during authentication, and the device's compliance posture (OS version, patch status, security software) is verified before access is granted. This replaces password-based authentication with cryptographically verified device identity.
How does Secure Workspace integrate with Foxpass?
Secure Workspace integrates with Foxpass Cloud RADIUS for Wi-Fi and VPN authentication. Foxpass provides the RADIUS infrastructure that validates device certificates and enforces network access policies. Devices managed by Secure Workspace receive certificates that are trusted by Foxpass RADIUS, enabling certificate-based Wi-Fi authentication (EAP-TLS) and VPN access without passwords.