Skip to content

Evolution of Secure Service Edge and the chronicles of browser isolation

In the ever-expanding landscape of cybersecurity, organizations are continually challenged to adapt and innovate in the face of evolving threats. As digital transformation accelerates and remote work becomes the norm, the traditional security perimeter is becoming increasingly porous, leaving sensitive data and critical systems vulnerable to advanced attacks.

Secure Service Edge (SSE) emerges as a proactive approach to safeguard digital assets while enabling seamless connectivity and productivity. 

SASE Gartner

A recent study posted on Gartner’s Peer Community showed the top three challenges for the future of cybersecurity attack sophistication (56%), greater resources for cyber-attacks (44%), and hybrid work models (43%). In addition, the same group of more than 300 IT/engineering/infosec leaders reported the three emerging cloud security tools they’re most excited about are cloud-native application protection platforms (CNAPP) (39%), SSE (38%), and SaaS management platforms (SMP) (37%).

Another Gartner study calls out the business priorities for Zero Trust, with protecting customer data (63%) topping the list.

SASE Gartner 2

Evolution of Secure Service Edge

The traditional network perimeter, once a stalwart defense against cyber threats, has become obsolete in the face of modern challenges such as cloud computing, mobility, and the proliferation of internet-connected devices.

As organizations embrace digital transformation and adopt cloud-based services, the concept of a secure perimeter shifts from a static boundary to a dynamic, distributed model that extends to wherever users and data reside.

This shift in perspective gives rise to the Secure Access Service Edge (SASE) framework, which converges networking and security capabilities into a unified architecture.

SASE combines the scalability and flexibility of cloud-native architectures with the security and performance required to protect modern digital environments.

SASE, in its simplest form, is a combination of software-defined WAN (SD-WAN) and SSE, as shown in the figure below.

Central to the SASE model is the concept of SSE, which is based on Zero Trust network access (ZTNA), secure web gateways (SWG), cloud access security brokers (CASB), firewall as a service (FWaaS), and remote browser isolation (RBI).

At the heart of the SSE paradigm lies RBI, a ground-breaking technology that promises to revolutionize how organizations defend against web-based threats.

But to appreciate the significance of RBI within the broader context of SSE, it’s essential to understand the journey that led to its emergence and the transformative impact it holds for cybersecurity professionals and businesses alike.

Built ground up on Zero Trust architecture, which means, it assumes that no entity, whether inside or outside the network, should be trusted by default, emphasizing continuous verification and least privilege access.

SASE = SSE + SD-WAN

SASE = SSE + SD-WAN

Remote browser isolation: Foundation of Secure Service Edge

At the core of the SSE architecture is remote browser isolation (RBI), a revolutionary technology that decouples web browsing activity from endpoint devices, effectively isolating potential threats in a secure, remote, and sandboxed environment.

Unlike traditional web security approaches that rely on detecting and blocking malicious content at the endpoint or network perimeter, RBI ensures that web content is executed and rendered in a disposable container outside the corporate network, preventing malware from ever reaching the endpoint.

Key principles of RBI include:

Isolation: RBI creates a secure air-gap barrier between users’ web browsers and potentially malicious content, preventing direct access to corporate resources and sensitive data.

Zero Trust: By treating all web content as untrusted and isolating it in a remote environment, RBI aligns with the Zero Trust model, minimizing the attack surface and mitigating the risk of web-based threats.

Scalability: RBI offers virtually unlimited scalability, allowing organizations to support growing user populations and fluctuating demand without sacrificing performance or security.

Seamless user experience: Despite the robust security measures in place, RBI ensures a seamless and responsive browsing experience for end users, eliminating the need for cumbersome security controls that impede productivity.

The impact of RBI on cybersecurity:

The adoption of RBI as a foundational component of the Secure Service Edge has profound implications for cybersecurity practitioners and organizations seeking to fortify their defenses against web-based threats. It shifts the focus from reactive threat detection to proactive threat prevention.

RBI empowers organizations to:

  • Enhance security posture: RBI reduces the risk of web-based attacks such as phishing, ransomware, and drive-by downloads by isolating potentially malicious content away from endpoints and critical assets.
  • Improve compliance: With RBI’s ability to enforce granular access controls and prevent unauthorized data exfiltration, organizations can achieve and maintain compliance with regulatory requirements such as GDPR, HIPAA etc.
  • Enable secure remote work: As remote work becomes increasingly prevalent, RBI enables organizations to extend robust web security protections to distributed workforces, ensuring consistent protection regardless of users’ locations or devices.
  • Optimize resource utilization: By offloading resource-intensive web browsing activities to remote isolation environments, organizations can optimize endpoint performance and reduce the strain on network infrastructure.

The future is brightly secured

As organizations navigate the complex cybersecurity landscape and embrace the principles of Secure Service Edge, remote browser isolation emerges as a cornerstone technology that empowers them to adapt and thrive in an ever-changing threat landscape. By embracing RBI as a proactive defense against web-based threats, organizations can strengthen their security posture, enhance user productivity, and maintain compliance in an increasingly interconnected and dynamic digital world. RBI serves as a one-stop solution for any organization that has an appetite for, and the attack surface, encompassing access, network, and end-point security.

We at Parallels, are constantly striving to collaborate and enable our partners and customers on their journey to a secure future. As a commitment to this vision, we are excited to introduce our own in-house offering, Parallels Browser Isolation (PBI)!

Parallels Browser Isolation: See it in action

Parallels Browser Isolation provides a secure way to access web applications, including Software as a Service (SaaS) and other cloud-based applications, right from your favorite web browser on your laptop or desktop.

Parallels Browser Isolation stands as a beacon of innovation and resilience, guiding organizations towards a future where security and productivity are not mutually exclusive, but rather complementary pillars of success.

This bolsters the Parallels pedigree as a leader in cross-platform solutions spanning, desktop-server-cloud capabilities, all seamlessly integrated. Our solutions provide a seamless plug-and-play experience, combining different Parallels suite of products into one holistic platform, enabling access to on-premises or cloud-based apps and desktops via any device, any browser, or any operating system.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

When Windows 10 support ends, here’s what you need to do

When Windows 10 support ends, here’s what you need to do

Microsoft recently announced the end of support for Windows 10, and users are encouraged to make the transition to Windows 11 sooner rather than later.

From the official statement on the Windows 10 product page, “Windows 10 will reach the end of support on October 14, 2025. The current version, 22H2, will be the final version of Windows 10, and all editions will remain in support with monthly security update releases through that date.”

After October 2025, however, computers running Windows 10 will become increasingly vulnerable to security threats and may encounter compatibility issues with new software and hardware releases.

Naturally, if you’re an IT admin or just a long-time Windows user, developing a plan of action prior to Windows 10’s official end of life is a priority. That plan could include upgrading your device(s), finding a virtualization solution that makes things relatively painless, or some combination of the above.

Read on to learn more — and if you’re ready to get started, get your free trial of Parallels® RAS or Parallels DaaS now.

Transitioning from Windows 10 to Windows 11 successfully

Windows 11 is the most secure version of Windows ever created, leveraging hardware security to complement software defenses against modern cybersecurity threats. It is also faster, enhancing productivity with an improved user interface, tighter integration of Microsoft Teams across apps, and snap layouts.

However, this push towards Windows 11 comes with challenges.

It could result in millions of perfectly functional PCs being discarded because Windows 11 mandates the presence of a Trusted Platform Module (TPM) chip, potentially rendering many devices obsolete.

This is a relatively new component in modern PCs and laptops, and as a result, there are millions of devices that will be left unused or thrown out as they do not have the TPM and, therefore, the Windows 11 OS cannot be installed.

Newer enterprise and consumer devices will meet the criteria. Starting in 2016, Microsoft mandated that OEMs integrate TPM 2.0 into devices for Windows 10 and Windows Server 2016 to obtain Microsoft’s endorsement.

Older devices lacking TPM 2.0 or equipped solely with TPM 1.2 (which cannot always be upgraded), will fall short of Windows 11’s minimum system requirements.

This could force users to replace their devices prior to Windows EoL, potentially resulting in a substantial increase in electronic waste and necessitating businesses to reinvest or repurchase hardware. And with Windows 10 at nearly 70% usage, that’s potentially a lot of devices!

Before taking on the significant expense of replacing your fleet of laptops and PCs, why not explore the option of virtualizing your IT systems?

Virtualization offers the opportunity to extend the lifespan of these devices while unlocking a range of benefits and ultimately increasing security —one of the main improvements on Windows 11.

Extending the life of your Windows 10 devices post-EOL with virtualization

Virtualization technology has proven invaluable for many enterprise companies that manage extensive fleets of workforce devices. It streamlines and automates device management at scale.

A virtual migration to Windows 11 can also be a cost-effective choice since costs for virtual PCs start at $110 USD per user annually and go up to $1,600 USD for high-end virtual PCs. On the contrary, new hardware that’s Windows 11-compatible is rarely less than $1,000 USD per user.

Instead of upgrading to new Windows 11 devices, organizations can maximize their existing hardware by virtualizing their IT environment. This allows users to run Windows 11 on a virtual machine on an older device.

How to upgrade your virtual machines from Windows 10 to Windows 11

You may already use virtual machines for Windows applications or desktops. If that’s the case, you can migrate those to Windows by following these steps.

Note that a virtual TPM chip is required for upgrading to Windows 11, and you need to ensure that your virtual machines meet the system requirements for Windows 11.

Once you are sure that your virtual machines meet the requirements, you can follow the instructions in this Knowledge Base article to upgrade.

The Parallels ecosystem of virtualization solutions

Here at Parallels, we have a host of application and desktop delivery solutions that can be tailored to your needs and requirements, whether you are upgrading to Windows 11, extending the life of legacy Windows 10 devices, or solving a different challenge.

Parallels® RAS

Parallels RAS is a flexible virtual application and desktop delivery solution that empowers organizations of all sizes to work securely from anywhere, on any device.

The platform offers an agile, cloud-ready foundation and end-to-end security, controlled by a centralized management console. Leverage on-premises, hybrid, or public cloud deployments and integrate with existing technologies like Azure Virtual Desktop and Amazon EC2.

With Parallels RAS, you gain the flexibility, scalability, and IT agility to quickly adapt to changing business needs. Best of all, Parallels RAS offers a single, full-featured licensing model that includes 24/7 support and access to free training.

Parallels DaaS

Parallels DaaS is a cloud-based app and desktop delivery solution that offers flexible and secure access to critical data and apps from any internet-connected device.

This Desktop-as-a-Service offering uses a unique, cloud-native architecture that isolates the management infrastructure (which is managed by Parallels) and leaves critical business data where it belongs, in the business environment. This dramatically improves security and offers incredible scalability.

For IT admins, Parallels DaaS simplifies the onboarding and management process with intuitive administration controls and real-time dashboards, allowing all types of businesses to deliver and use enterprise-grade IT solutions.

Desktop as a Service (DaaS) exemplifies the cloud option, where infrastructure is handled by the cloud provider, allowing IT managers to focus on aspects like VM provisioning, applications, and data management.

While on-premises virtualization emphasizes control and security, cloud solutions prioritize scalability, cost-effectiveness, and convenience through redundant infrastructure and flexible pricing models.

It is time to virtualize Windows 11?

Upgrading to Windows 11 via a virtualization solution means that organizations do not need to buy new PCs and laptops before the Windows 10 end-of-life.

Rather, businesses can recycle or extend their existing fleet of devices.

For example, if a company has decided to move to Windows 11 and refresh its fleet of endpoint devices, that company could face compatibility issues or other growing pains as its IT department adjusts existing apps and needs to adapt to the new OS. Virtualization can also help with this!

By decoupling the applications from the device — or virtualizing them — users can migrate to the latest OS (Windows 11, in this case) and enjoy their new devices without worrying about whether their essential applications will still work.

End users can access their applications via the Parallels Client while on their new device. This can accelerate the adoption of Windows 11 or other new operating systems among the workforce, as IT managers can upgrade their teams’ devices at their own pace, without being hindered by application compatibility concerns.

With virtualization, users can enjoy the same great security and user experience expected with a Windows 11 device, but instead of the operating system being installed “on-device,” it is virtualized and does not require the latest TPM chip.

Ready to get started with a virtualization solution? Get your full-featured trial of Parallels RAS and/or Parallels DaaS.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Keep control of your cloud journey

Over the past decade, there has been an undoubted shift towards companies adopting and efficiently managing their applications and data in the cloud. However, this rush towards the cloud has left many companies with more complexity within their IT environments and unexpected costs. In reality, most customers today are operating in a hybrid environment for a variety of reasons. We’ll take a look at a number of those reasons below.

Even those companies that rushed their customers to the cloud are now offering those same customers more options to take a step back from the cloud; including hybrid and on-premises options for their IT environments. However, these options come at a higher price to the customer.

At Parallels, we have always believed in offering choice and flexibility for customers, as they should be able to take their cloud journey at a pace that best suits their needs. Customers vary in their requirements for public cloud services. For some, it is a fundamental requirement to realize the benefits that public cloud services bring, such as agility and ever-green architecture. For others, it’s not a core part of their IT strategy at all, at least not today. There are many in between, as surveys continue to show.

Why hybrid cloud deployments?

The options for deploying your IT environment are diverse, ranging from on-premises, single-cloud and multi-cloud configurations and various combinations of these. In July 2023, the Parallels team conducted a survey aimed at gaining deeper insights into businesses’ choices of IT environments, the infrastructure types they employ, and the motivations driving these decisions.

Of the 805 IT professionals we surveyed, 64% were actively using a hybrid cloud approach within 2023. Of the respondents spanning North America and Europe, 38% intended to increase their hybrid approach throughout 2024. This suggests there is a clear understanding of the benefits of making use of both on-premises and cloud deployments. Within the same survey, 89% believed that the public cloud offers significant value for their business.

Furthermore, many of our respondents cited flexibility, security, and cost savings as their primary reasons for choosing the hybrid cloud over 100% public and 100% private clouds. Of this group, 49% chose the hybrid cloud because of increased flexibility, 46% for improved security, 45% for cost savings, 44% for increased reliability, and 40% for more scalability.

For businesses using a hybrid approach, flexibility is important because it offers them the time needed to navigate their cloud journey at their own pace.

The emphasis on security in choosing hybrid cloud solutions is understandable. With cyberattacks on the rise, security concerns weigh heavily on IT leaders, causing significant worry. Sensitive data or information subject to regulations is best-kept on-premises rather than in the cloud, reflecting a cautious approach.

Cost considerations also drive organizations toward hybrid cloud solutions. While cloud adoption promises lower initial costs by eliminating the need for physical infrastructure like data centers, long-term operating expenses (OpEx) must be carefully evaluated.

The study also explored the primary cost benefits expected from a hybrid approach. Among participants, 31% noted that a hybrid strategy helps manage expenses associated with transitioning to the cloud by implementing the shift gradually.

Based on the findings from this survey, it’s clear that the value of the cloud is almost unanimous, offering near-instant access to key resources and the ability to scale up or down depending on the business needs. However, it’s clear that many IT organizations also intend to retain an on-premises environment to combat concerns with data security and cost predictability. Furthermore, the hybrid model offers many businesses flexibility in when and how they transition to the cloud.

A gold rush…to the cloud

Several years back, a plethora of companies advocated for a significant shift among businesses, urging them to abandon their VDI and on-premises setups in favor of embracing a cloud-first strategy. The rationale behind this push was that these advocating companies stood to gain the most from such a transition. By leveraging the vast array of cloud resources and enjoying the flexibility of accessing cutting-edge technologies, businesses were promised a multitude of benefits. However, for many, this migration came at a hefty cost.

Citrix was a keen advocate of this move as well as Microsoft and Amazon Web Services. These companies made significant investments in products and solutions to support businesses moving to the cloud and had reason to encourage them to completely move to a public cloud model.

Many businesses that eagerly embraced the call for a cloud-first approach found themselves grappling with unexpected challenges. The transition unfolded at a pace that often outpaced their accustomed rate of change, causing significant struggles. Some of the hurdles these businesses faced in the transition to a cloud-first approach included effectively managing IT costs, skills, and the organizational culture changes that came with it.

Additionally, some businesses hesitated to fully commit to a single delivery model, recognizing the potential drawbacks of locking themselves into one approach. Nevertheless, they still felt pressured to follow the prevailing trend towards cloud adoption.

The cost of moving at a pace different from your own

Moving towards a public cloud approach at a speed that is not befitting to your competencies can have a significant impact on the performance of your business. Here are some concerns to be aware of:

Costs

Embracing the public cloud is often seen as the most financially savvy approach to establishing an IT infrastructure, as it eliminates the need for substantial upfront capital expenditures on hardware such as servers. Instead, it necessitates only lightweight client and endpoint devices to access applications and data from the cloud.

However, over time, the costs associated with configuring, deploying, and managing public cloud instances can escalate compared to the predictable costs of owning and managing servers over a 5–10-year lifecycle. These costs are contingent upon usage, and any usage spikes result in additional expenses. Furthermore, price increases contribute to additional costs. Without meticulous management, automation, and analytics, businesses may find themselves paying for resources that remain underutilized.

Skill shortage

Skill shortage emerges as a critical, albeit potentially short-term, concern for numerous businesses transitioning entirely to the public cloud. This shortage often stems from hasty migrations undertaken without adequate preparation. Shifting applications and data across platforms essentially entails a full reset, introducing new processes, software, and systems that demand a heightened level of understanding. This understanding can only be cultivated through extensive training of existing staff.

In instances where businesses rush their migration to the cloud, the existing team may not have sufficient time to undergo training and formulate a comprehensive migration plan. Consequently, companies may resort to recruiting individuals with the requisite skills to expedite the migration process, albeit at inflated costs.

While this skill shortage may self-correct over the next five years, it remains a critical consideration in the present landscape. Organizations must carefully assess their readiness for cloud migration, ensuring adequate preparation and resource allocation to mitigate the impact of skill shortages on their transition to the public cloud.

Limited control

The public cloud serves to relieve businesses from the burden of configuring and maintaining the infrastructure needed for a virtualized IT environment. However, this transfer of responsibility can lead to a loss of control. Public cloud services often provide standardized configurations and services, which may not fully align with your specific needs. This limitation can hamper your ability to customize the environment to suit your exact requirements and may result in reduced visibility into the underlying infrastructure supporting your applications and data. Consequently, troubleshooting issues, optimizing performance and ensuring compliance with internal policies or regulatory requirements may become more challenging.

Additionally, despite public cloud providers typically offering high availability and reliability, service disruptions can still occur due to factors beyond your control, such as outages or maintenance activities. These disruptions may limit your ability to mitigate their impact on your IT operations.

Vendor lock-in

Transitioning to the public cloud can lead to vendor lock-in, where your applications and data become closely tied to specific cloud provider services or technologies. This entanglement can complicate and raise the cost of switching providers later on, exacerbating the limitations on your control over your IT environment.

Moreover, migrating to the public cloud means relying on the cloud provider for many facets of your IT infrastructure, such as hardware provisioning, network configuration, and software updates. This dependency diminishes your direct control over these crucial components.

Back peddling from cloud to on-premises

Even companies that initially encouraged the move to the wholesale cloud have started to recognize this was not the best course of action for many customers or that these customers want more flexibility in their own cloud journey.

Hyper-Converged Infrastructure (HCI)

Hyper-Converged Infrastructure (HCI) is a software-defined IT infrastructure framework that integrates compute, storage, networking, and virtualization resources into a single, unified system. In traditional data center architectures, these components are often managed separately, leading to complexity and inefficiency.

Leading companies like Nutanix and Scale Computing have been offering this type of framework to customers for many years, which in essence, offers the advantages of a cloud model but within your own data center. This integrated approach not only simplifies infrastructure management but also provides scalability and agility, helping organizations meet their evolving IT needs with ease.

Microsoft is now following this type of framework with its own HCI offering, which hosts Windows and Linux VMs or containerized workloads and their storage. It’s a hybrid product that connects the on-premises system to Azure for cloud-based services, monitoring, and management. Microsoft Azure Stack HCI offers the security of an on-premises server located within your company’s office walls but is managed through the Azure subscription and based on virtualization principles.

The key difference here is that the business is not purchasing the initial hardware. Microsoft is providing it as part of the service at a monthly cost, which includes the flexibility of both cloud and on-premises, loaning of hardware and cloud resources, and the management and analytics of the environment.

Universal licensing

Another example is Citrix and its Universal Licensing model. Before the introduction of Universal Licensing, Citrix offered two main pathways for delivering its digital workspace solutions. Firstly, customers could opt for Citrix Virtual Apps and Desktops (CVAD) to run on virtual resources in a location of their choice, traditionally purchased as a perpetual license with annual maintenance, but now available solely through a subscription model for new customers.

Furthermore, customers seeking the flexibility to operate across both public cloud and on-premises environments require Universal Licenses. This newfound flexibility, however, comes at a higher cost for customers and depends on the size of the organization. Therefore, limiting this option to organizations with more than 250 user licenses and to those customers wanting to stay away from the more costly Universal Licensing model and remain on their existing afraid cannot. Learn more in our blog post that asks: “Does Citrix Universal Licensing provide simplicity — or not?”

Many leading cloud-centric companies are acknowledging the importance of allowing customers to transition to the cloud at their own speed, with hybrid solutions emerging as a valuable option for many on this migration journey. However, these companies have also effectively leveraged this gradual transition and customer preference for hybrid environments to develop more profitable business models for themselves. So, what is the solution? Find out how Parallels® RAS can help.

Parallels RAS: A simplified hybrid deployment for app and desktop delivery

Parallels RAS has always offered a universally licensed approach, with a simple subscription model eliminating complexity for businesses. Parallels RAS grants access to all features, including secure gateway access, across various deployment options such as on-premises, public cloud, or hybrid environments.

This flexibility extends to optimized Azure Virtual Desktop (AVD), VDI desktops in the public cloud or data center, and remote access to physical workstations. Parallels RAS emphasizes avoiding vendor lock-in, prioritizing customer choice, and maintaining simplicity in its offerings.

With a focus on meeting customer needs, Parallels RAS continues to deliver on its promise of simplicity, empowering users to consume resources where they are most effective. Consider evaluating your current or potential virtual apps and desktops vendor to ensure alignment with your requirements and preferences.

Making your move to the cloud

A scenario for many customers could involve retaining the current on-premises infrastructure while transitioning away from Citrix to Parallels RAS or adopting a hybrid model. Many organizations have said it is easier to migrate to Parallels RAS rather than moving to the next version of Citrix. With this approach, organizations can utilize Parallels RAS to manage Azure Virtual Desktop (AVD) deployments alongside their existing on-premises systems. This strategy offers the flexibility to carefully plan and execute change management strategies at a pace that suits the organization’s needs.

It allows for thorough testing and gradual migration of specific workloads or departments to the cloud while maintaining stability and continuity with the on-premises infrastructure. This method enables organizations to leverage the benefits of cloud technology while mitigating risks and ensuring a smooth transition for users and IT operations.

Final words

The cloud presents tangible benefits that many companies can swiftly access. An on-premises infrastructure remains essential for providing security and cost predictability to businesses. By embracing a hybrid approach, companies can leverage the strengths of both environments. Contrary to common belief, achieving a hybrid deployment doesn’t necessitate an increase in costs; instead, it allows organizations to tailor their cloud journey according to their unique pace and requirements.

Parallels champions choice and flexibility through its universally licensed Parallels RAS, empowering organizations to seamlessly manage virtual desktop deployments across on-premises, public cloud, or hybrid environments. This approach ensures a gradual transition to the cloud while preserving stability and control over IT operations.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Preparing your business for the unpredictable: The role of DaaS in disaster recovery

In the fast-paced world of modern business, the surge in natural disasters, intensified by climate change, poses unprecedented business challenges. 

Businesses must be ready for anything, from hurricanes to floods to wildfires and cyber-attacks. While securing the safety of your company’s employees and physical locations is most important, once that’s in place then the focus shifts to maintaining connectivity and operations.

That’s where disaster recovery (DR) is a crucial process, ensuring the restoration of business operations after a disaster. While traditional DR methods often prioritize servers and networks, the significance of desktops must also be understood in today’s digital landscape. Your employees’ desktops are their hub for data storage and application access. Losing them in a disaster can be a severe setback for your business.

This is where Desktop-as-a-Service (DaaS) emerges as a game-changer. Parallels DaaS, a cloud-based service providing users with virtual desktops stored in the cloud, offers several advantages for effective disaster recovery.

Understanding the climate-induced surge

Extreme weather events

Multiple scientific studies, notably by the Intergovernmental Panel on Climate Change (IPCC), reveal a significant increase in hurricanes and extreme weather events. Elevated sea surface temperatures fuel these storms, heightening the vulnerability of physical infrastructure and leading to extended downtime.

Altered precipitation patterns and flood risks

Climate-induced changes in precipitation patterns elevate the risk of flooding, and warmer temperatures increase rainfall, posing a direct threat to businesses. Accordingly, robust disaster recovery measures, especially for desktop systems, have become imperative to mitigate downtime and data loss in the event of a flood and associated water damage.

Wildfires and ecological dynamics

Prolonged droughts and rising temperatures intensify wildfires, impacting businesses in vulnerable regions. Beyond the immediate smoke and fire damage, the possibility of compromised IT infrastructure necessitates effective disaster recovery for desktop systems.

The intersection of natural and artificial disasters

Escalation of cybersecurity threats

The evolving cyber threat landscape, marked by ransomware attacks, malware, phishing attempts, and more, demands swift recovery measures. Desktop-as-a-Service (DaaS) emerges as a solution to ensure business continuity and prompt recovery from cyber-induced disasters.

Vulnerabilities in power infrastructure

Whether stemming from natural disasters or cyber-attacks, power outages present an artificial disaster. When integrated into disaster recovery plans, DaaS ensures cloud-hosted desktop accessibility or cloud-based disaster recovery during power disruptions.

Embracing resilience with DaaS

The escalating frequency of natural and artificial disasters emphasizes the need for resilient disaster recovery strategies. Scientific research and published reports underscore the urgency of adopting solutions like DaaS to navigate the unpredictable nature of current climate conditions.

Discover DaaS for disaster resilience

Efficient data backup and restoration

Storing your desktops in the cloud makes it significantly easier to back up and restore your data. This streamlined process ensures that your critical information is safeguarded against unforeseen disasters.

Remote accessibility

In the event of office damage, DaaS allows your staff to access their desktops from anywhere with an internet connection. This remote accessibility ensures business continuity, allowing your team to continue operations even when the physical workspace is compromised.

Data privacy compliance

DaaS aids in compliance with data privacy regulations, such as GDPR and HIPAA. By storing data securely in the cloud, businesses can navigate regulatory requirements more effectively, mitigating the risks of non-compliance.

Considerations when implementing DaaS for disaster recovery

Choose a reliable DaaS provider

Selecting a trustworthy DaaS provider is crucial. Seek out a provider such as Parallels with a proven track record in disaster recovery and a robust infrastructure to support your business needs.

Network readiness

Ensure that your network can handle the traffic associated with streaming virtual desktops. A robust and scalable network is essential for the seamless functioning of DaaS during disaster recovery scenarios.

Employee training

Train your employees on how to use DaaS effectively. Familiarizing your team with the platform ensures a smooth transition during disaster recovery and helps maintain productivity.

Additional tips for disaster recovery

Develop a comprehensive DR plan

Create a thorough disaster recovery plan that encompasses all aspects of your business. Ensure it includes protocols for desktop recovery using DaaS.

Regular DR plan testing

Test your disaster recovery plan regularly to verify its effectiveness. Regular testing helps identify potential gaps and ensures your plan is reliable.

Secure data backup

Keep your data backed up in a secure location. Implement robust backup strategies to protect your critical information from potential disaster loss.

Employee training

Train your employees in disaster response protocols. Ensuring your team is well-prepared for emergencies contributes to a swift and coordinated response.

How to protect your business from the unpredictable with DaaS for disaster recovery

A data-centric approach to disaster recovery is crucial for safeguarding your business from the unexpected. Preparedness is more critical than ever in today’s ever-changing world. By incorporating these tips and embracing solutions like DaaS, your business can weather challenges and storms, emerging on the other side stronger than ever.

To learn more about how DaaS is the ideal solution for a desktop disaster recovery plan, download the full whitepaper here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

How-to: Providing secure access to Microsoft Azure with Parallels Browser Isolation

What is Parallels Browser Isolation (PBI)? 

Parallels Browser Isolation (PBI) is a comprehensive, cloud-native solution that offers highly secure access to web applications and SaaS via a preferred web browser. It is a remote browser isolation solution that offers Zero Trust protection from cybersecurity threats and aligns with industry security standards for safety, protection, and compliance.

Parallels Browser Isolation is a fully hosted remote browser isolation service, with a control plane and containerized browser instances. It’s scalable, flexible, and agentless, offering a highly adaptable and secure solution for all users within an organization.

Learn more about Parallels Browser Isolation!

Why would you like to set up secure access to Microsoft Azure with Parallels Browser Isolation (PBI)?

Like many SaaS applications, users have access to Microsoft Azure from any device and any location by default.

Conditional access in Microsoft Entra Identity (Azure AD) enables you to impose restrictions on managed devices or specific network ranges. However, it’s important to understand that these restrictions are applicable only to managed devices.

What if you want to enforce restrictions without the use of VPN agents? Or suppose you aim to apply access controls to bring-your-own-device (BYOD) policies or non-windows-based devices?

Adding to these challenges, it’s crucial to note that conditional access focuses solely on securing entry points. It does not extend to controlling actions within Microsoft Azure (or any other SaaS application) once access is granted.

What if your security needs include stopping users from downloading data while permitting uploads? Or suppose you need to disable copy/paste functions, prevent screenshot capture, and block printing capabilities? These requirements align with a Zero Trust security model, yet such specific restrictions cannot be achieved through traditional conditional access or role-based access controls alone.

Parallels Browser Isolation enables you to route all Microsoft Azure access through a remote browser. This setup allows for geo-blocking, restricting access exclusively to locations associated with PBI IP addresses.

Following this configuration, only users who adhere to the PBI policies and belong to the designated access groups will be granted the ability to connect to Azure. Furthermore, the policy engine empowers you to specify permissible actions within Azure, such as copy/paste, upload, download, print, and others, offering a tailored and secure user experience.

PBI Azure Portal Diagram

Implement conditional access on Azure

For the first step, you must set up Microsoft Azure to exclusively permit access from PBI IP addresses. You can do this by setting up conditional access within Microsoft Entra ID (formerly known as Azure AD). It’s important to highlight that activating this conditional access feature requires a Microsoft Entra Identity P1 license. The process starts with establishing a Named Location that encompasses the IP addresses associated with Parallels Browser Isolation.

As an admin, go to “Microsoft Entra ID” —> “Security,” —> “Named Locations” Click on “+ IP ranges location” and give this location a unique name. In my case, I called this location “Parallels Browser Isolation”. Add all IP addresses used by Parallels Browser Isolation. The list can be found online in this KB article: https://kb.parallels.com/en/130095.

When adding the different IP addresses, add a /32 to the end to identify that these are single IPs and not ranges.

Once this is done, go to “Microsoft Entra ID” —> “Security” —>“Conditional Access”

Click on “+ Create new policy” and give it a unique name. In my case, I called it “PBI Only Policy”.

In configuring the policy, the initial step involves selecting the ‘Users’ to whom the policy will apply. It’s advisable to begin with a small user group for testing purposes before expanding the policy to include a broader audience.

Important: Make sure you exclude at least a few users from this policy, as you might need to get back into your Microsoft Azure if there are configuration or other issues with your conditional access configuration. If you include everyone and you have an issue, you can’t log in to Microsoft Azure anymore and, therefore can’t make any changes to the conditional access settings in the “Microsoft Entra ID”.

Next, we need to select the “Target Resources” and select “Include”.

If you want to protect your Azure portal only, then choose the “Select apps” option and “Select” only “Microsoft Admin Portals”. This application covers access to Microsoft Azure and some other management portals.

Important: If you choose the “All cloud apps” option, take into account that you might have configured your Parallels Browser Isolation (PBI) solution to be federated with “Microsoft Entra ID,” and therefore, you need to make sure you exclude the application that was created in “Microsoft Entra ID” for PBI from this policy. If not, you won’t be able to log in on PBI.

On the “Conditions” settings, we now have to enable the “Locations” filter. We want to have this policy enabled for all locations except for the “Parallels Browser Isolation” location created in the first step of this procedure.

To do this, under “Include”, select “Any Network,” and under “Exclude,” select “Select Locations” and select the “Named Location” you created earlier, in my case, “Parallels Browser Isolation” location.

The other conditions like “User risk”, “Sign-in risk”, “Device platforms”, “Client apps,” and “Filter for devices” can remain in the default configuration and don’t need to be modified.

The final steps are to set the “Access Controls” to “Block access”, set “Enable policy” to “On,” and save it.

Publish Microsoft Azure as a Secure Web Application in Parallels Browser Isolation (PBI)

Now that the conditional access is configured, your next step is to make sure the users can access Microsoft Azure via Parallels Browser Isolation (PBI).

To do this, log in and go to the PBI admin portal. Click on “Applications” —> “Add Application” —> “Secure Web Application”.

Start by setting the “Name“and the “Icon”. Set “https://portal.azure.com” as a start URL.

Under “Domains,” you have now to specify all URLs that are used by Azure.

For some SaaS applications, this is a single domain, but for Microsoft Azure, the list is pretty long (this is the full list of all domain names used by Microsoft Azure).

You can add the individual subdomains or only the main domains. In the example below we simplified the list of domains to include only the main domains, but not the individual subdomains. Also, we added all possible domains, not just the ones linked to the Microsoft Azure login but all the individual services.

The following domains have been added:

aadrm.com

azconfig.io

azure.com

azure.net

azureedge.net azuresynapse.net loganalytics.io

login.live.com microsoft.com

microsoftonline-p.com microsoftonline.com

msauth.net

msauthimages.net

msftauth.net

msftauthimages.net

office.com

status.microsoft

trafficmanager.net

windows.net

Under the “Access for secure web applications,” select the users or groups in PBI that must have access to Microsoft Azure. Optionally, select an extra policy you want to apply to this application. If the policy doesn’t exist yet, you must first save the application, create a new policy, and then edit the app and assign the newly created policy.

Before creating the policy, don’t forget to save the configuration. You do this by clicking on the bottom of the screen on “Add”.

Once that is done you will see the app in the list of published apps.

Azure Portal PBI

In this example, I want extra security on top of Microsoft Azure and, therefore, will create an extra policy to block “copy/paste”, “download”, and “printing” and have a watermark on the screen to make it more difficult to take screenshots.

To create a new policy in the right menu bar, click on “Policies” —>“Add”

Again, we start with setting a “Name”. My policy will be called “Microsoft Apps Policy”, and the idea is that I can apply this same policy to other published Microsoft applications I may want to publish in PBI later.

I want to apply the policy to all users, so I will set the filter for “Users and Groups” to disabled.

Same for the “Active Hours”, I keep it set to disabled.

For the “Location,” I can implement the geo-restriction. As we have restricted access to Azure to only PBIIP addresses with conditional access, we can’t set country-based geo-restrictions at that level.

In my example, I have geo-restricted Microsoft Azure access to “Belgium”, “France”, “Germany”, “Italy”, “Netherlands”, “Portugal” and “Spain”.

On the “Security controls/Policy Features,” I enabled the “Disable printing”, “Disabled downloads,” and “Disable Clipboard” features.

Under “Security controls/End-user experience,” I enabled the following features:

  • Blue border”: This will put a visual indication (blue border around the screen) that you are not accessing the website directly but via the Parallels Browser Isolation solution.
  • Watermarking”: This will add the user’s login name and date as a watermark on top of the screen so that taking screenshots becomes more difficult.

The “Restrict URLs” options don’t need to change here — they can stay on the default values.

Finish creating the policy by clicking on “Save”. Now that the policy has been created, go back to the “Azure Portal” application and add the “Microsoft Apps Policy” to the application.

Test the setup

Now that we have published the “Azure Portal” application on PBI and configured the conditional access on Microsoft Entra ID, we can test if the setup works: First, we try to open it directly from the web browser.

This should not work as the conditional access only allows connections from the Parallels Brower Isolation IP addresses.

PBI Secure Access

If we do the same thing but via Parallels Browser Isolation, it works. Also, note the watermark and the blue bar around the screen.

Now you have set up secure access to Microsoft Azure via Parallels Browser Isolation!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.