Zero-Trust Secure Access

Deliver secure, clientless access to internal resources — RDP desktops, SSH servers, and web applications — through any browser. No VPN, no client install, zero-trust architecture.

The Zero-Trust Access Challenge

Traditional VPNs create broad network access — once connected, users can reach everything. In a zero-trust world, access must be granular, identity-based, and continuously verified. Parallels Secure Workspace (formerly Awingu) solves this with a clientless, browser-based gateway that enforces least-privilege access to published resources without exposing the network. For organizations that prefer an installed-client approach with higher streaming fidelity, Splashtop provides an alternative zero-trust architecture with 4K/60fps performance and on-premise deployment options.

What Is Parallels Secure Workspace?

Parallels Secure Workspace is a zero-trust network access (ZTNA) solution that publishes internal resources — RDP desktops, SSH servers, VNC, and web applications — through a unified, browser-based workspace. Users authenticate once (with MFA), then access authorized resources directly in their browser via HTML5. No VPN client, no RDP client, no SSH client — just a browser.

Acquired by Parallels in 2023 (formerly Awingu), it extends the Parallels portfolio into the zero-trust secure access space, complementing Parallels RAS (VDI/app virtualization) and Parallels DaaS (managed cloud desktops).

Key Capabilities

  • Clientless Browser Access: HTML5-based RDP, SSH, VNC, and web app rendering. Works in Chrome, Edge, Firefox, Safari — no plugins, no installs.
  • Zero-Trust Architecture: Identity-first access. Integrates with Entra ID (Azure AD), Okta, Ping, Keycloak, and SAML/OIDC providers. Enforces MFA, device posture, and conditional access policies per resource.
  • No VPN Required: Eliminates the VPN attack surface. No split-tunneling risks, no lateral movement. Users access only published apps/desktops.
  • Granular Access Policies: Define who can access what, when, from where, and on what device. Time-based, location-based, and device-compliance conditions.
  • Session Recording & Audit: Full RDP/SSH session recording with playback. Meets compliance requirements for privileged access monitoring.
  • Secure File Access: Browser-based file manager for SMB/CIFS and WebDAV shares — download, upload, preview without mapping drives.
  • Lightweight Deployment: Single virtual appliance (OVA/VMware/Hyper-V/Azure) or container. Connects to internal resources via connectors — no inbound firewall ports.
  • Parallels RAS Integration: Publish RAS farms directly into Secure Workspace for unified access to VDI desktops and zero-trust apps.

Use Cases

  • Contractor & Third-Party Access: Grant time-limited, resource-specific access without VPN credentials or device management.
  • BYOD / Unmanaged Devices: Employees or partners use personal devices — browser-only access keeps data in the browser, not on the endpoint.
  • Legacy App Publishing: Publish RDP/SSH-based legacy apps to modern browsers without rewriting or virtualizing.
  • Privileged Access Management: Secure, audited access for admins to servers (RDP/SSH) with session recording.
  • VDI Alternative for Light Workloads: Replace full VDI for task workers who only need a few published apps.

Parallels Secure Workspace vs. Traditional VPN & ZTNA Alternatives

Capability Parallels Secure Workspace Traditional VPN Cloud ZTNA (Zscaler, Cloudflare, etc.)
Client Install None (browser only) Required Usually required (agent)
Protocol Support RDP, SSH, VNC, Web, File All (network-level) Primarily HTTP/HTTPS
Session Recording Built-in (RDP/SSH) No Limited / add-on
Deployment Model On-prem appliance or cloud On-prem gateway Cloud-only (mostly)
Integration with VDI Native Parallels RAS Separate Separate
Pricing Model Per-user subscription Per-user + hardware Per-user/month

Deployment Architecture

  1. Deploy Appliance: OVA/VMware/Hyper-V/Azure image. Single VM, ~4 vCPU / 16GB RAM for up to 500 concurrent users.
  2. Configure Identity: Connect to Entra ID, Okta, SAML/OIDC provider. Enable MFA.
  3. Deploy Connectors: Lightweight agents on internal network (no inbound ports). Connectors reach RDP/SSH/web targets.
  4. Publish Resources: Define applications (RDP, SSH, web, file shares) and assign to user groups.
  5. Apply Policies: Conditional access (location, device, time), session recording, watermarking, clipboard/file transfer controls.
  6. User Access: Users browse to workspace URL, authenticate, and launch apps in new tabs.

Integration with Parallels Ecosystem

  • Parallels RAS: Publish RAS farms as resources in Secure Workspace. Users get unified access to full VDI desktops and zero-trust apps.
  • Parallels DaaS: Secure Workspace can front DaaS desktops for contractor/BYOD scenarios where full DaaS entitlement isn't needed.
  • Parallels Desktop for Mac: Mac users access Secure Workspace resources via browser — complementary to local Windows VMs.

Licensing & Pricing

Per-user subscription with volume tiers. Includes appliance license, connectors, session recording, and support. No per-connector or per-resource fees. Contact Parallels or authorized partners for quote.

Explore Parallels Secure Workspace →

For zero-trust alternatives, see our Splashtop Secure Workspace guide, Splashtop vs VPN comparison, and secure VPN alternatives.

Compare Secure Access Solutions

See how Parallels Secure Workspace stacks up against VPNs, legacy ZTNA, and browser isolation platforms in our detailed comparison.

View Comparison