Disclosure: We may earn commissions from partner links on this site. This does not affect our independent editorial reviews. All opinions are our own. Full disclosure.
Zero-Trust Secure Access
Deliver secure, clientless access to internal resources — RDP desktops, SSH servers, and web applications — through any browser. No VPN, no client install, zero-trust architecture.
The Zero-Trust Access Challenge
Traditional VPNs create broad network access — once connected, users can reach everything. In a zero-trust world, access must be granular, identity-based, and continuously verified. Parallels Secure Workspace (formerly Awingu) solves this with a clientless, browser-based gateway that enforces least-privilege access to published resources without exposing the network. For organizations that prefer an installed-client approach with higher streaming fidelity, Splashtop provides an alternative zero-trust architecture with 4K/60fps performance and on-premise deployment options.
What Is Parallels Secure Workspace?
Parallels Secure Workspace is a zero-trust network access (ZTNA) solution that publishes internal resources — RDP desktops, SSH servers, VNC, and web applications — through a unified, browser-based workspace. Users authenticate once (with MFA), then access authorized resources directly in their browser via HTML5. No VPN client, no RDP client, no SSH client — just a browser.
Acquired by Parallels in 2023 (formerly Awingu), it extends the Parallels portfolio into the zero-trust secure access space, complementing Parallels RAS (VDI/app virtualization) and Parallels DaaS (managed cloud desktops).
Key Capabilities
- Clientless Browser Access: HTML5-based RDP, SSH, VNC, and web app rendering. Works in Chrome, Edge, Firefox, Safari — no plugins, no installs.
- Zero-Trust Architecture: Identity-first access. Integrates with Entra ID (Azure AD), Okta, Ping, Keycloak, and SAML/OIDC providers. Enforces MFA, device posture, and conditional access policies per resource.
- No VPN Required: Eliminates the VPN attack surface. No split-tunneling risks, no lateral movement. Users access only published apps/desktops.
- Granular Access Policies: Define who can access what, when, from where, and on what device. Time-based, location-based, and device-compliance conditions.
- Session Recording & Audit: Full RDP/SSH session recording with playback. Meets compliance requirements for privileged access monitoring.
- Secure File Access: Browser-based file manager for SMB/CIFS and WebDAV shares — download, upload, preview without mapping drives.
- Lightweight Deployment: Single virtual appliance (OVA/VMware/Hyper-V/Azure) or container. Connects to internal resources via connectors — no inbound firewall ports.
- Parallels RAS Integration: Publish RAS farms directly into Secure Workspace for unified access to VDI desktops and zero-trust apps.
Use Cases
- Contractor & Third-Party Access: Grant time-limited, resource-specific access without VPN credentials or device management.
- BYOD / Unmanaged Devices: Employees or partners use personal devices — browser-only access keeps data in the browser, not on the endpoint.
- Legacy App Publishing: Publish RDP/SSH-based legacy apps to modern browsers without rewriting or virtualizing.
- Privileged Access Management: Secure, audited access for admins to servers (RDP/SSH) with session recording.
- VDI Alternative for Light Workloads: Replace full VDI for task workers who only need a few published apps.
Parallels Secure Workspace vs. Traditional VPN & ZTNA Alternatives
| Capability | Parallels Secure Workspace | Traditional VPN | Cloud ZTNA (Zscaler, Cloudflare, etc.) |
|---|---|---|---|
| Client Install | None (browser only) | Required | Usually required (agent) |
| Protocol Support | RDP, SSH, VNC, Web, File | All (network-level) | Primarily HTTP/HTTPS |
| Session Recording | Built-in (RDP/SSH) | No | Limited / add-on |
| Deployment Model | On-prem appliance or cloud | On-prem gateway | Cloud-only (mostly) |
| Integration with VDI | Native Parallels RAS | Separate | Separate |
| Pricing Model | Per-user subscription | Per-user + hardware | Per-user/month |
Deployment Architecture
- Deploy Appliance: OVA/VMware/Hyper-V/Azure image. Single VM, ~4 vCPU / 16GB RAM for up to 500 concurrent users.
- Configure Identity: Connect to Entra ID, Okta, SAML/OIDC provider. Enable MFA.
- Deploy Connectors: Lightweight agents on internal network (no inbound ports). Connectors reach RDP/SSH/web targets.
- Publish Resources: Define applications (RDP, SSH, web, file shares) and assign to user groups.
- Apply Policies: Conditional access (location, device, time), session recording, watermarking, clipboard/file transfer controls.
- User Access: Users browse to workspace URL, authenticate, and launch apps in new tabs.
Integration with Parallels Ecosystem
- Parallels RAS: Publish RAS farms as resources in Secure Workspace. Users get unified access to full VDI desktops and zero-trust apps.
- Parallels DaaS: Secure Workspace can front DaaS desktops for contractor/BYOD scenarios where full DaaS entitlement isn't needed.
- Parallels Desktop for Mac: Mac users access Secure Workspace resources via browser — complementary to local Windows VMs.
Licensing & Pricing
Per-user subscription with volume tiers. Includes appliance license, connectors, session recording, and support. No per-connector or per-resource fees. Contact Parallels or authorized partners for quote.
Explore Parallels Secure Workspace →
For zero-trust alternatives, see our Splashtop Secure Workspace guide, Splashtop vs VPN comparison, and secure VPN alternatives.