Ebook VDI Challenges For A Secure Remote Workforce 1
Ebook VDI Challenges For A Secure Remote Workforce 1
VDI (on-premise) and now DaaS (cloud- In another 2 years, 80% of these on-prem At least 50% of enterprises rely on VDI for
hosted) technologies can be found in over virtual desktops will be migrated to
their workforce.
30% of companies around the globe. the cloud.
These are serious numbers that have tripled during the height of the pandemic.
The need to retrofit an existing solution for the rapid remote employee growth has
pushed desktop virtualization beyond its intent.
02 02
In this Ebook we will explore how VDI and DaaS may be past its
prime and not always the ideal solution for remote workers.
The cost to deploy and support a VDI platform is often quite higher
than anticipated as shown.
03 02
Table of Contents
VDI UX 14
04
Retrofit Existing Tools
1 VPN
(Virtual Private Network) creates an encrypted tunnel from your
laptop back to the company’s office.
05 02
VDI
2 VDI
VDI, a completely different approach, allows end users to
connect to a virtual desktop hosted either at the company’s
data center or a chosen public cloud.
of their own.
06 02
The Shift to DaaS
By hosting these virtual desktops within the company's data center, there is more
control of what gets stored inside and what is allowed to leave.
In the past few years, a shift to cloud-hosted desktops has emerged called DaaS
or Desktop as a Service. This transitions the infrastructure required to host,
broker and tunnel the virtual desktop connections to the cloud vendor,
effectively reducing the management and operational functions for IT.
07
A VDI/DaaS system needs to live ideally within
For example
If you have remote workers in Brazil accessing a virtual desktop hosted in
Virginia these response times can reach over 300ms, making for an
unbearable experience.
Keystrokes will be delayed, trying to talk or see a colleague on Zoom will freeze
“Why can’t I Zoom from my virtual up and just using your mouse to click around through a web page will be
desktop?”
frustrating. There are many tools like this one available to measure your own
latency inside a given Azure region.
08 02
This table below shows what Microsoft Azure’s latency #s are
from a given region to another when taken in June of 2022
Keeping VDI Secure
to corporate data.
Sure, the desktop lives within the managed confines of IT and can be
quickly deployed and destroyed at will. In the beginning, virtual desktops
were typically accessed from a company-issued device such as a laptop.
This way the company owned the entire experience end-to-end and was
able to help support any issue that may come up. Companies quickly
realized that it was not very cost-effective to provide both a VDI desktop
and hardware for the employee so they tried to cut costs on the physical
endpoint side.
09
These unmanaged devices were then left un-
With VDI being a known entry point for remote-workers, they are
IT must stay up to date with the steady stream of updates needed for the
10
IT must stay up to date with the steady stream of updates needed
for the infrastructure, virtual desktops and the clients used to connect.
As an example
2021 wreaked havoc as VDI vendors had to repeatedly apply must be constantly patched and rebooted as well to maintain a
These updates can often be scheduled after normal 9-5 hours but will still be disruptive for the end
user when they login for the day and must relaunch all of their work.
With remote-workers in different time-zones this can be a challenge to accommodate and undergo
11
Getting VDI off the Ground
heightened period of time can be tough for end users, it can be even harder
Often there are entire IT teams dedicated to design and manage VDI/DaaS
A new freedom
12
Gartner reports that in 2020-2021, securing your remote-
workforce was the #1 project for organizations looking to
review how users are accessing company apps and data.
New dedicated teams may emerge as well, responsible for the end-to-end
delivery and user experience while on a virtual desktop.
13
VDI UX
end user. That is until they try to print, copy/paste, open that large Excel
and must traverse the various hops in between there and the printer
in the office.
This list here from Verizon, shows some common apps and
their bandwidth estimate per user.
14
As you can tell, any type of video streaming performed by a large
group can often consume the organization's entire internet link if
not sized properly.
These scans if not scoped properly can bring an entire VDI environment
to its knees and consume your Help Desk staff for the day.
This reminds us that VDI lives on shared infrastructure and can suffer from
the noisy neighbor problem. If 1 VM within the VDI cluster is inundated with
traffic for whatever reason, it can cause others to be starving for resources.
These issues and others can leave users begging for their laptop back.
15
The High Cost of VDI
a virtual desktop instead of physical machines is that they can be more efficiently
managed and require less IT staff to operate.
For traditional VDI, there is still infrastructure to build, secure and manage in
The virtual desktops require IT staff to build and manage the desktop images,
build and test applications and manage the access controls. In a medium to large
environment, these images, applications and desktops multiply quickly and
require sufficient staff to manage and support them.
the hosting of the virtual desktops, the actual compute, storage and
networking for the cloud-hosted virtual desktop is still a significant cost
to the company, whether paid up front or monthly.
16
These #s directly from Amazon, show how much an AWS
Power Pro Root Volume User Volume Monthly Pricing Hourly Pricing
Take for example this use case of 2 different virtual profiles, Power Additional headcount to manage the solution is also required.
(Marketing, Finance) & PowerPro(Developers), each using a 50 GB You can safely estimate another 2-3 IT Engineers ($100k/each)
user volume. needed to manage the Windows OS Images, assignments and
[500] Power Virtual Desktops + [100] PowerPro Virtual Desktops = applications tailored for DaaS. This brings DaaS costs to a
$49,000 per Month minimum of $888k per year for the organization.
17
Switching to SaaS Apps
One idea is to move towards a SaaS model for the more popular business
systems.
Apps like:
Google Docs
Zoom
Salesforce
18
Over half of these apps are not even managed by IT,
according to stats here from Productiv.
Since web apps are by nature, publicly accessible and the security
controls are maintained by the vendor, some companies might have slight
Your employees work freely, hesitancy on how they are used and what data is stored there.
your data stays secure
19
Separate Physical Devices
They can leverage Wifi at any location and stay connected over the company’s
VPN. While providing remote users a laptop is one of the most expensive options
for a company to endure, it can also be insecure and unpopular as well.
With companies that have already implemented a Zero-Trust model for remote
devices, the additional layers of authentication can be helpful in keeping users
and devices verified but is not a complete solution.
20
The operational overhead to manage physical
to reduce.
21
Looking for a Modern VDI Alternative
Employees dont want to log into multiple devices with multiple user
a single device that can handle both business and personal. One they can
work-related tasks while they must use a different device for anything
unrelated to work.
Or toggle back and forth between personal and business windows virtual
desktops all day long. We need a system that allows both secure access to
22
There is a different solution, re-imagined for the modern
age to overcome these preceding challenges.
A solution that is both secure and simple to manage for your existing Administrators.
Venn Software is the key to keeping company data isolated and protected in the
remote-first workforce.
23
Thanks for Your Attention!
Want to hear more about how Venn.com can help your company?