Skip to content

5 Key Strategies for Zero Trust integration in Cloud Architecture

5 Key Strategies for Zero Trust integration in Cloud Architecture

Cloud technologies dominate today’s digital landscape, so it is no surprise that cyber threats have evolved in response.

Accordingly, the Zero Trust model — built on the principle of “never trust, always verify” — has become a crucial element of cybersecurity, particularly for organizations leveraging cloud architecture. Zero Trust offers better visibility, consistent and comprehensive security, and the speed and agility necessary to combat rapidly evolving cyber threats.

I’ll explore five key strategies for integrating Zero Trust into the fabric of your cloud infrastructure, ensuring your data remains secure and your operations resilient. I’ll also delve into the criteria for assessing the impact of Zero Trust strategies on your organization.

If you’re ready to start your Zero Trust journey, get a free trial of Parallels Secure Workspace and Parallels Browser Isolation.

Key criteria for evaluating the effectiveness of Zero Trust strategies

Let’s kick off our discussion on integrating Zero Trust into cloud architecture by establishing some evaluation criteria. Consider the following three criteria to determine if an approach is effective.

1. Security

The foremost priority is to assess how well the strategy enhances the cloud environments’ security. A solid strategy prevents unauthorized access, detects threats in real time, and responds to security incidents effectively.

2. End-user experience

It’s essential to ensure that security measures do not make the user experience overly complex. Strategies should allow seamless access to necessary resources with minimal disruption to daily activities, thus maintaining or improving productivity.

3. IT admin management efficiency

Evaluate security strategies based on how they impact IT admin efficiency. The evaluation criteria include ease of deployment, ongoing management, and the ability of IT staff to maintain oversight without excessive overhead. By examining each strategy against these criteria, we can ensure that your Zero Trust approach secures the cloud environment and supports positive user experiences and efficient IT management.

1. Identity and access management (IAM)

Comprehensive IAM Solutions

The cornerstone of Zero Trust is robust identity verification. Implementing multifactor authentication (MFA), role-based access control (RBAC), and least privilege security policies ensure that only verified users have access to your network and only to the resources they need.

Identity Providers (IdPs) such as Microsoft Entra ID, Okta, and PingFederate play a crucial role in smoothly linking different apps and boosting security with OpenID Connect (OIDC). OIDC enhances authentication, allowing only authorized users access.

Effectiveness

  • Security. IAM enhances security by controlling access with MFA, RBAC, and least privilege policies, using IdPs like Okta for smooth app integration. For legacy systems, use tools like Parallels Secure Workspace for secure single sign-on integration. This setup enhances security by seamlessly integrating modern and legacy systems.
  • End-user experience. IAM can complicate access with additional security steps but streamlines it via single sign-on capabilities across applications.
  • IT admin management efficiency. IAM reduces IT workload by automating access control and user verification, improving administrative efficiency and system control.

healthcare professional sitting at desk working on computer

Use case: Consider a healthcare provider managing access to sensitive patient records. By integrating MFA and RBAC, the provider ensures that only authorized personnel can access specific data based on their roles, significantly mitigating the risk of data breaches.

2. Network Segmentation

Microsegmentation

This strategy involves segmenting your cloud network into smaller, highly secure zones.

Employing a secure intra-network gateway enhances control over resource access within these zones, mitigating unauthorized movements across the network. If one segment is compromised, the breach’s impact remains confined to that segment alone, thus preserving the integrity of the rest of your network and safeguarding critical resources.

Effectiveness

  • Security. Microsegmentation confines security breaches to small areas, reducing overall risk and protecting critical network resources efficiently.
  • End-user experience. Minimal impact on user experience; maintains regular access to necessary resources without interruption.
  • IT admin management efficiency. Enhances control and simplifies network traffic monitoring, improving response to threats and maintenance efficiency.

it professional working on desktop computer

Use case: A manufacturing firm operates two networks—a locally managed administrative network and a headquarters-controlled production network. Historically, accessing applications and data across these networks was a lot of work for local staff.

By implementing a secure intra-network gateway, the company now enables seamless and secure access to the production network, enhancing efficiency and reducing overhead. Parallels Secure Workspace serves as a secure gateway, facilitating streamlined access to data and applications on the production network. It also allows for secure, audited sharing of documents with external contacts, eliminating the need for local installations. Users can access this gateway through any browser on any device.

3. Continuous monitoring and analytics

Audit tools are essential for real-time anomaly detection and response, which is critical for maintaining transparency and enforcing dynamic security measures. These tools provide in-depth insights into user activities and potential threats.

Effectiveness

  • Security: Audit tools enable real-time anomaly detection and response, significantly enhancing network security and threat mitigation.
  • End-user experience: Minimal impact on users, maintaining system transparency while safeguarding data integrity.
  • IT Admin management efficiency: Improves IT productivity by automating threat detection and security responses and streamlining administrative tasks.

Use case: A financial institution uses remote browser isolation to boost security when accessing cloud-based financial tools. This approach protects against cyber threats by isolating each browsing session and monitoring usage in real time.

4. Embracing the hybrid cloud

A hybrid approach is essential for balancing security and functionality. It allows organizations to keep sensitive data and confidential operations securely on-premises, minimizing exposure to external threats while leveraging cloud solutions for less critical business operations.

This setup enhances operational flexibility, scales resources efficiently, and ensures compliance with data protection regulations, providing a strategic mix of security and accessibility to meet diverse business needs.

Effectiveness

  • Security. Keeps sensitive data on-premises, reducing exposure to external threats while using cloud resources for less critical tasks.
  • End-user experience. Enhances flexibility and accessibility, seamlessly integrating on-premises and cloud resources for a smoother user experience. Utilizing Parallels Secure Workspace further elevates this by offering a unified workspace where users can access both on-premises and cloud applications through a single platform, simplifying navigation and improving productivity.
  • IT admin management efficiency. Improves resource scalability and compliance management, streamlining operations and ensuring data protection efficiently.

government worker using psw

Use case: An e-commerce company employs a secure workspace solution to integrate its on-premises inventory management with cloud-based customer service applications. This strategy ensures seamless and secure access, enabling the company to manage sensitive data internally while leveraging the cloud for less critical operations.

5. Enhancing the user experience with a browser-based unified secure workspace

With the rise of remote work and the proliferation of SaaS and web applications, users need a reliable, simple way to access their work tools.

The Zero Trust model can extend through an entire virtual workspace, resulting in a unified access gateway that facilitates secure, browser-based access to business applications, SaaS platforms, web apps, and even entire desktops, all without the need to install any new software. This solution ensures that users experience frictionless access to their applications while maintaining high-security standards.

Effectiveness

  • Security. Extends Zero Trust to virtual workspaces, ensuring high security across all accessed applications without additional installations.
  • End-user experience. Offers smooth, browser-based access to work tools from any browser, on any device, and from anywhere, boosting convenience and productivity for remote work.
  • IT admin management efficiency or productivity. Reduces IT workload related to software installations and updates, streamlining application access management.

msp using psw on desktop computer

Use case: Consider the needs of a multinational corporation with employees spread across various regions, including remote and on-site workers. By implementing a unified secure workspace solution, the company allows its employees to securely access essential financial, HR, and operational cloud applications via any web browser.

This capability is particularly advantageous during travel or when employees log in via insecure public networks. This seamless integration ensures that all employees, regardless of location or device, have consistent and secure access to their work environments.

Why Zero Trust is essential for cloud architecture

Integrating Zero Trust into your cloud architecture is a necessity, not just a nice-to-have upgrade. By applying these five strategies, organizations can thoroughly protect their data and infrastructure, transforming their cloud environments into secure digital strongholds.

Tools like Parallels Secure Workspace and Parallels Browser Isolation empower your organization to address immediate security challenges while building a more secure and resilient digital future.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Enhancing Parallels RAS: Explore what’s new in version 19.4

The latest Parallels® RAS release, version 19.4, introduces remarkable new features that refine and enhance the capabilities of Parallels RAS 19 and 19.3. 

Among these enhancements are expanded go-to-market opportunities for our partners to promote Parallels RAS and extended support for Nutanix AHV for the latest image management features.

Additionally, there are improved security measures, newly introduced customizable administrative options, and improved end-user functionality. Now, let’s take a closer look at the exciting additions in Parallels RAS 19.4.

New go-to-market (GTM) opportunity for partners

Extended GTM route for partners with Azure Marketplace listing (coming soon)

Parallels RAS is now listed as a transactional offering in the Microsoft Azure Marketplace in addition to the current bring your own license (BYOL) listing. This enables Parallels RAS to be more accessible and efficient through deployment automation.

Parallels partners can benefit through private offerings and simplified selling through personalized offerings, allowing for easier access and connecting Parallels solutions with businesses and organizations across the globe.

Provisioning and Automation

Extended image management for Nutanix AHV (AOS)

We’re thrilled to announce a significant expansion of our image management capabilities, initially introduced in the 19.3 release. It is now available for Microsoft Azure, Azure Virtual Desktop, Hyper-V and VMware vCenter, and ESXi and includes support for Nutanix AHV (AOS).

This is a pivotal step forward, enabling businesses considering migration to Nutanix to do so seamlessly with Parallels RAS. This comprehensive support encompasses a suite of powerful features, including template versioning, enhanced image lifecycle management facilitated by tags, and convenient template scheduling functionalities.

By extending our support to Nutanix AHV, we’re providing organizations with unparalleled flexibility to select their preferred infrastructure. This empowerment enables businesses to tailor their virtual environments precisely to their unique needs and preferences.

Find out more about the latest image management features with our Tech Bytes videos.

Support for scale computing SC//HyperCore 9.2

With Parallels RAS 19.4, integration with SC//HyperCore 9.2 is now available as a provider option. This enables organizations to use the latest supported SC//HyperCore versions 9.1 and 9.2 with Parallels RAS to automate provisioning, scaling, and power management of session host workloads.

Streamlined admin experience with Agent Auto-Upgrade

Managing upgrades across numerous backend session hosts can be daunting for IT administrators. To alleviate this challenge, Parallels RAS 19.4 introduces Agent Auto-upgrade, a feature that automates the upgrading of RDSH, VDI, AVD, and Remote PC (within a host pool) guest agents according to a maintenance schedule set by the IT administrator.

Whether operating on-premises, in the cloud, or in hybrid environments, this functionality simplifies upgrades, enabling administrators to focus on more strategic initiatives while ensuring all endpoints remain up to date.

Continuous improvement of template versioning

Building upon our commitment to improvement and optimization, the latest release of Parallels RAS includes several updates aimed at enhancing template versioning capabilities.

These improvements are designed to optimize the IT administrator experience, ensuring more seamless management and better version control for virtualization templates.

Security

Self-service registration for email-based one-time passwords (OTPs)

Security remains a top priority in today’s digital landscape. Accordingly, Parallels RAS 19.4 introduces a new, robust multi-factor authentication option with email OTP.

This feature provides organizations with an additional layer of security by delivering one-time passwords directly to user email addresses. Even external email addresses not stored in the company’s Active Directory are supported, ensuring comprehensive protection against unauthorized access. This capability provides a simple yet efficient use of email-based OTPs without relying on complex, third-party dependencies services.

Validate host headers

We have introduced HTTP host header validation at the gateway. This validation process serves to mitigate vulnerabilities associated with HTTP host header injection, enhancing the overall security posture of our platform.

With this feature implementation, administrators gain comprehensive control over custom HTTP host headers with the high availability load balancers and secure gateways being automatically included in the approved list.

Activation of this feature ensures that any request lacking a recognized host header from the specified list will result in a 404 error, thereby fortifying our defenses against potential security breaches originating from unauthorized host headers.

Configuring certificate authority templates

Administrators of Parallels RAS for organizations using SAML for their enrollment servers can now leverage a larger key size for security purposes.

This new feature enables the configuration of the PrlsEnrollmentAgent and the PrlsSmartcardLogon certificate templates used by the Enrollment Server at a minimum key size of 4096 bits. Previously, the minimum key size was 2048 bits.

User experience

Enhanced user experience with multi-monitor support

End-users leveraging the Parallels Client for Web will benefit from enhanced productivity with the introduction of multi-monitor support.

This feature empowers users to fully utilize all available displays during published sessions, whether they’re working within an application or in a desktop environment. By maximizing screen real estate, multi-monitor support enhances the overall user experience, facilitating seamless multitasking and workflow efficiency.

New built-in reports

The Parallels RAS 19.4 release introduces new host pool reporting options for IT administrators, further improving its reporting capabilities. These new reports track areas in user sessions and include:

  • Sessions disconnect for host pool

New reports are dedicated to monitoring session disconnects within host pools, akin to session activity reports for individual sessions.

  • Transport protocol for host pool

New reports tailored to track the transport protocol usage within host pools, mirroring the functionality of session activity reports for host pools.

  • Bandwidth availability for host pool

New reports focused on assessing bandwidth availability within host pools, providing insights like session activity reports but at the pool level.

  • Latency for host pool

New reports aimed at measuring latency within host pools, offering analysis akin to session activity reports while focusing on pool-wide latency metrics.

  • Connection quality for host pool

New reports designed to evaluate connection quality within host pools, providing insights like session activity reports but focusing on the overall connection quality across the pool.

  • UX evaluator for host pool

New reports dedicated to assessing the user experience (UX) within host pools, offering insights like session activity reports but focusing on UX metrics at the pool level.

  • Log-on duration for host pool

New reports aimed at analyzing logon duration within host pools, providing insights like session activity reports while focusing on pool-wide logon duration metrics.

SAML SSO capability

SAML SSO capability is now available when using Parallels RAS + Azure Virtual Desktop under the standard feature set.

Administration experience

Custom administration for tailored control

This feature introduces a custom menu under ‘Help’ within the RAS Console and allows customization of a URL in the management portal Support section.

This URL can redirect power or custom administrators to local or internal support or any other designated URL. It’s particularly beneficial for organizations that utilize Security Event and Incident Management frameworks, using local support to address IT tickets and enhance the efficiency of the support process.

Active Directory-based (AD) permissions for session management

Administrators can now define session management permissions tailored to Parallels custom administrators based on their AD group membership. This feature enhances the granularity of session management administration, ensuring that only designated administrators can oversee specific end-user sessions. This capability is particularly advantageous for service providers or larger enterprises with multiple designated help desk administrators.

View “license” permission options

This feature introduces a dedicated license view permission for administrators, available in both the RAS console and Web Management portal, tailored for both power and customer administrators. It provides the flexibility to restrict the visibility of certain license information from other administrators who have access to all license data.

Ready for Parallels RAS 19.4?

Parallels RAS continues to raise the bar with its feature offerings while ensuring the best possible admin and user experience.

From Nutanix AHV image management support to multi-factor authentication options and streamlined administrative controls, Parallels RAS empowers organizations to achieve greater efficiency, security, and flexibility in their virtual environments.

For a full list of features, refer to the Parallels RAS 19.4 release notes.

Frequently asked questions (FAQs)

1. What is the release date for 19.4?

The general availability date for Parallels RAS 19.4 is April 30, 2024.

2. What do I need to do to install the latest version of Parallels RAS?

IT managers can access the latest version of Parallels RAS through the management console two weeks after GA by going to Parallels RAS Console > Administration > Settings > Check now > Update and following the instructions from there. To access the new version immediately, managers can go to public downloads or through My Parallels Account.

3. Is there any supporting information to help me learn more about these features?

Yes, the best place for more information is in our 19.4 release notes.

Ready to explore what’s new in Parallels RAS 19.4? Get started here!

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

How DaaS is helping improve hybrid work models

Over the past few years, our work life has transformed.

Organizations are evolving their workforce’s needs. That’s why 80% of companies are planning to adopt a hybrid work model.

For example, Alludo is remote-first, where employees can choose their primary workplace.

When my fellow Alludians need to, we can use alternative workspaces. For example, we can work in a regional Alludo office or a flexible ‘hotel-style’ workspace.

This hybrid work approach allows employees to choose their best working environment.

84% of Alludo employees reported that this flexible working arrangement improved work-life balance.

98% said remote work was more productive than when there was an office-based culture.

The number of remote workers will rise over the next five years, so hybrid work models will also grow.

Let’s explore hybrid work models and how Desktop as a Service (DaaS) solutions can play a critical role.

Enable hybrid work models by adapting DaaS. Talk to us about securing your remote employees with Parallels DaaS. 

Understanding hybrid work models

Hybrid work models are different from the traditional 9-to-5 office-based work.

Rather than be glued to their desks, employees can work from various locations, such as their homes, a coffee shop, or the office itself.

The hybrid work approach enables companies to support diverse work styles. Hybrid work improves employee satisfaction and productivity. It represents a fundamental change in how work is conceptualized and executed.   Hybrid work breaks down the barriers of time and space that once confined productivity.

Hybrid work models also provide a powerful tool for attracting and retaining top talent.   Candidates choose flexibility and work-life balance when evaluating job opportunities.

They are looking for companies that show they understand and value their need for flexibility, making them more attractive employers.  Nearly 70% of companies agree that adopting a hybrid model improves recruitment and retention of employees.

DaaS hybrid work

Source: Survey of Business Uncertainty conducted by the Federal Reserve Bank of Atlanta, Stanford University, and the University of Chicago Booth School of Business. 

By adopting hybrid work models, organizations can better serve the needs of their employees.   The need for autonomy and flexibility to perform their best work allows companies to remain competitive and successful in today’s marketplace.

Challenges of hybrid work

Hybrid work models are becoming popular due to their many benefits.  Still, this model also presents several challenges, especially in technology and collaboration.

One of the most significant challenges is ensuring that remote and in-office employees have equal access to the tools, resources, and applications required to perform their jobs efficiently.

Access is usually standardized across all employees in a traditional office setting.

However, it can be challenging to maintain equality in a hybrid work environment, leading to inefficiencies and frustration.

To overcome this challenge, companies should invest in technological solutions that enable easy access to essential tools and resources, regardless of location.

By adopting cloud-based platforms and collaboration tools, employees can easily access these resources from any device with an internet connection.

Another significant challenge of hybrid work is maintaining security, compliance, and data integrity across different work environments.

With employees accessing sensitive information from various locations and devices, organizations face increased cybersecurity risks, including data breaches, malware attacks, and insider threats.

To mitigate these risks, organizations must implement comprehensive security measures that protect remote and in-office environments.

Some measures may include deploying endpoint security solutions, implementing multi-factor authentication, and conducting regular security training and awareness programs for employees.

Additionally, organizations must ensure compliance with relevant regulations and standards, such as GDPR, HIPAA, and PCI DSS, to protect sensitive data and avoid regulatory penalties.

The final challenge that a hybrid work model can bring is fostering collaboration across distances.

Collaboration is essential for the success of any organization.

Still, it can be challenging to maintain in a hybrid work environment where employees are physically dispersed, and spontaneous interactions and face-to-face communication are not directly available to remote employees.

Companies must leverage technological solutions to overcome this and facilitate seamless communication and collaboration among distributed teams.

These solutions may include video conferencing platforms, instant messaging tools, and project management software that enable real-time communication and collaboration regardless of location.

Fostering a collaborative culture through regular team meetings, virtual social events, and collaborative projects can help strengthen bonds and drive collective success.

Leveraging DaaS for seamless integration

Desktop as a Service solutions offer a compelling solution to the challenges posed by hybrid work models.

By delivering virtual desktops and applications over the Internet, DaaS ensures that employees can access their work environment from anywhere, using any device.

Companies can benefit from the flexibility to seamlessly integrate remote and in-office work environments, enabling employees to work efficiently and collaboratively regardless of location.

1. Flexibility

DaaS provides high flexibility for employees, enabling them to work from anywhere with an internet connection.

Using DaaS removes the need for employees to worry about whether the technological infrastructure is in place wherever they may be working.

2. Consistency

DaaS ensures employees have the consistency essential to productivity and continuity when working in hybrid environments. It enables employees to access their desktops and applications the same way, regardless of whether they are in the office or working remotely.

3. Collaboration

DaaS facilitates seamless collaboration among remote and in-office teams by providing a centralized platform for accessing shared files, applications, and resources.

A centralized platform ensures employees can access the files they need quickly and easily, wherever they may be working from.

4. Security

One of the most significant benefits of DaaS is its robust security features. DaaS solutions offer a range of security features, including data encryption, multi-factor authentication, and centralized access controls, to protect sensitive information across hybrid work environments.

With DaaS, businesses can be confident that their data is secure, even when employees work remotely.

5. Scalability

DaaS solutions are highly scalable, allowing organizations to quickly adapt to changing workforce needs.

Scalability is essential in hybrid work environments, where businesses must scale their infrastructure up or down quickly and efficiently to meet demand.

With DaaS, businesses can quickly add or remove users as needed without worrying about the technical infrastructure required to support them.

Hybrid work models are becoming increasingly common as companies adapt to changing workforce needs.

DaaS solutions are proving to be essential in enabling the seamless integration between remote and in-office work environments, allowing companies to offer their employees the flexibility to work remotely and collaborate effectively, leading to success in a dynamic work environment.

The future of work is still evolving, and DaaS is expected to play a crucial role in driving innovation and productivity in hybrid work environments.

Parallels DaaS is your secure platform that supports hybrid work

Whether your employees are working from the office or remotely, Parallels® DaaS offers seamless access to virtual applications and desktop environments.

Its cloud-hosted control plane enables secure remote access to your business applications, desktops, and data from any internet-connected device.

The solution’s quick and easy onboarding process allows for immediate access to applications and desktops from any device, eliminating the complexity surrounding user onboarding and managing users and applications.   This makes it easier for even small businesses to deliver and use enterprise-grade IT solutions.

Thanks to its unique architecture, with access points closer to where data and users reside, Parallels DaaS promises the best performance for end-users, with transparent operations for administrators.

So, if you’re looking for a solution that can help you embrace hybrid work and enable your employees to work productively from anywhere, check out Parallels DaaS.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Remote virtual machine access using port forwarding and SSH private/public keys

Virtualization technology allows us to create multiple virtual machines (VMs) on the same physical machine.

A virtual machine operates like a software program running on a computer, simulating the behavior of an independent machine.

In essence, it establishes a computer within another computer.

When operating within a window on the host computer, a virtual machine offers users an experience that’s nearly identical to using a separate computer.

For many software developers, using a virtual machine is preferable for easy cross-platform compatibility purposes; they also offer greater security, flexibility, and scalability.

When setting up your virtual machine, you can access its graphic user interface (GUI) to interact with the virtual machine separately from the other machine(s) or operating systems on your physical computer.

However, relying solely on the GUI may not always be practical if you’re a software developer, especially if you need to access a VM remotely.

In such cases, you should use the Secure Shell protocol (SSH) to execute remote logins or commands securely over an unsecured network.

Parallels Desktop enables remote access to virtual machines with SSH and port forwarding.

By default, Parallels Desktop operates in shared network mode, which works “out of the box” and does not require any specific configuration.

Parallels Desktop will work as a virtual router for your virtual machines when you use this networking mode. However, it also means that the VMs cannot be accessed from external computers.

The port forwarding (also known as port mapping) functionality allows computers on your local network and the Internet to connect to any virtual machines that use the shared networking mode.

According to the port-forwarding rule, the connection to a specific port on your Mac will be redirected to a specific port of your virtual machine.

To gain remote access to a VM via port forwarding, you must first configure Parallels Desktop to accept the connection using a port forwarding rule.

This is achieved by following the process outlined below.

Establishing port forwarding rules

Note: Port forwarding is only available in Parallels Desktop for Mac Pro and Parallels Desktop Business Edition.

1. Open the Parallels Desktop Command Center

2. Select the VM you want to access remotely 

Then, click the Configure button.

3. Once the Configuration window opens, select the Hardware tab

Then the Network option on the left side, then click “Advanced.”

4. Click on the “Open Networking Preferences” button

5. Click the Add (+) button below the Port forwarding rules list

6. In the displayed window, perform the following actions

  • In the Protocol field, specify the port type you want to establish network connections. You can choose between the TCP or UDP port types.
  • In the Source Port field, type the incoming port number on your Mac.
  • In the Forward to section, indicate the name or IP address of the virtual machine you want to connect to.
  • In the Destination Port field, type the port on the virtual machine to which the data will be transferred.

  7. Click OK to add the rule

Checking port forwarding

To check that the rule works properly, enable, e.g., SSH on your virtual machine (some Linux distributions have it enabled by default).

As an example for SSH, use the following rule:

Protocol TCP
Source PortChoose a different port number between 1024 to 49151 for each VM
Forward toChoose your virtual machine
Destination Port22

To make sure that port forwarding is enabled from your Mac inside a virtual machine, use one of the following scenarios (in these examples, port 8081 is redirected to a Linux VM, and port 8888 is to a Windows VM) :

Scenario 1: connect from the same Mac

In Terminal, type in the following command and press Enter:

ssh -l <your_VM_username> -p <source_port> 127.0.0.1

Enter the password for the user in the virtual machine and press Enter:

Scenario 2: connect from another Mac or PC in the same network

In Terminal (on Mac) or PowerShell (on Windows), type in the following command and press Enter:

ssh -l <your_VM_username> -p <source_port> <host_machine_IP_address>

Enter the password for the user in the virtual machine and press Enter.

To check that you logged into the virtual machine, execute the following command in Terminal:

uname -a

If you successfully log into the virtual machine, you will see a Linux kernel version.

The same method can also be used to set up an SSH port forward for a Windows machine by adding that to the port forwarding list:

You can run a “systeminfo” command to verify the system you are on.

Using SSH key pairs

Now we have the systems tested and working using password authentication, we can make them more secure.

SSH public/private keypairs offer a more secure, convenient, and scalable authentication mechanism than traditional password-based methods.

By leveraging SSH keypairs, organizations can strengthen their security posture and ensure secure remote access to their systems, eliminating the need to transmit passwords over the network.

With keypairs, the private key remains securely stored on the user’s computer.

In contrast, the public key is stored on the server, significantly reducing the risk of interception by malicious actors.

Because the keypairs are generated using cryptographic solid algorithms, they are much longer than passwords, making them highly resistant to brute force attacks.

Once SSH keypairs are set up, users can seamlessly log in to SSH-enabled systems without entering a password, adding convenience for automated processes and scripts.

Generating SSH public/private keys

The SSH key pair consists of two cryptographic keys: public and private keys.

These keys are mathematically related but are designed so that it is computationally infeasible to derive the private key from the public key.

The public key is shared securely with the server or system you want to access.

It can be freely distributed and stored on several servers or systems and is provided when you attempt to connect to a server.

The private key is kept securely on your local computer or device. It should never be shared with anyone else.

This key is used to decrypt encrypted messages with the corresponding public key, and when you attempt to connect to a server, your local SSH client uses your private key to prove your identity.

When you attempt to connect to a server using SSH, the server sends a message encrypted with your public key.

Your SSH client decrypts this message using your private key and sends back a response.

If the server can successfully decrypt your response using your public key, it knows you possess the corresponding private key, allowing you to access the system.

SSH keypairs are typically generated using cryptographic algorithms such as RSA or DSA.

Your local SSH client software can generate these keys for you. The keys are often stored in files (e.g., “id_rsa” for the private key and `id_rsa.pub` for the public key) in a hidden .ssh directory in your user’s home directory.

Creating SSH keypairs

To explain how to generate and use the SSH keypairs, I have three systems: a Mac, which is my local machine; an Ubuntu VM, which will be the remote machine; and a Mac VM, which will use the port forwarding rules.

Each system has a different theme for the terminal windows to make it easier to follow.

First, I will check my local machine to ensure no local keys exist, using the command:

ls ~/.ssh/id_*

As no matches were found, no keys were present on our local machine. If they are present, you should back them up in case they are accidentally removed or lost.

Next, we can generate our SSH key on the local machine.

To do this, type in the command:

ssh-keygen

The command replies that it is generating a public/private keypair using rsa as the default encryption.

If you wish to use a different algorithm you can use the -t flag to select from the following alternatives: dsa, ecdsa, ecdsa-sk, ed25519, ed25519-sk.

I will also add a comment using the -C flag so that I can quickly identify what the key is for.

My command line would look like this:

ssh-keygen -C "Test for SSH Keys on Mac & Ubuntu"

By default, the file is saved in my user directory in the .ssh folder, so I hit enter to accept that.

I also hit enter for the passphrase question, which adds an extra layer of security but also means I would have to enter it each time I connect. I am trying to avoid that in this example.

Retrieving the public key

If we rerun the ls command, we can see two files in the .ssh directory: the private and public keys.

Move into the .ssh directory, open the contents of the public file, and copy them so that we can add them to the remote machine in a file called authorized_keys.

cd .ssh 

ls -la 

cat id_rsa.pub

Adding the public key to the remote machine

To enable SSH access to a remote machine, you must upload the public key from your SSH key pair onto the remote server. This allows the remote machine to decrypt connections initiated by your local computer, which uses its corresponding private key for encryption.

On the remote machine, go to your home directory and check if the .ssh subdirectory exists:

cd ~
ls -al ~

If it does exist cd into that directory, and if it doesn’t, create the subdirectory, and then go into it and check to see if the authorized_keys file exists:

mkdir .ssh
cd .ssh
ls -al

If the authorized_keys file does not exist, create one using the following command:

touch authorized_keys

Then edit the file using your editor of choice to add the public key copied from the local machine.

If you already have an authorized_keys file in the directory with content, add your new key on a new line and save the file.

Putting it all together

Now that our private and public keys are created, we need to check that they work.

Check the IP address of your virtual machine from the Parallels devices-> networking tab

Now ssh into that system from your local host that has the private key installed on it:

ssh <user>@<ip address>

And as you can see, we are logged in without providing a password.

As we have set up port forwarding on our local host, we should also be able to access the Ubuntu VM from a different system, but going through the host machine and using the port that was assigned at the beginning of this article, that being 8081 of the Mac system.

If I go to my Mac VM running on the same host, I can copy a key to the Ubuntu box, but this time, instead of cut/paste, I will use the ssh-copy-id command to add to my authorized_keys file on the Ubuntu system, but using port 8081 of my host system:

ssh-copy-id -p <port> <user>@<ip address>

We can check the key was correctly added by going back to the Ubuntu VM, and checking the authorized_keys file:

 

The text highlighted in red is the new key from the Mac on the VM. If we return to that VM, we can execute the ssh command displayed at the end of the ssh-copy-id command message to access the Ubuntu VM system from my Mac’s VM system via my host Mac:

And as you can see from the command prompt at the end, I am back on the Ubuntu System.

Ready to try it yourself? Sign up now for a free 14-day trial to see how easy it is to implement port forwarding and secure key pairs using Parallels Desktop Pro. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

Conquer new worlds in Age of Empires on your Mac

In a world where strategy is paramount and maintaining your dominion requires both strength and wisdom, the Age of Empires games have long captivated players with their immersive universe of historical grandeur and warfare.

This iconic series invites players to traverse time by commanding powerful civilizations through the ages, from the humble beginnings of the Stone Age to the formidable heights of the Imperial Age.

Through meticulous management of resources, strategic planning, and diplomatic finesse, players shape the destinies of empires, leading their chosen people to glory or ruin.

https://www.parallels.com/blogs/age-of-empires/(opens in a new tab)

For loyal Mac users, the dream of commanding mighty civilizations once seemed a distant fantasy, hindered by the lack of availability for Mac and Windows exclusivity.

It’s no longer an epic battle to play Age of Empires games on your Mac, especially the popular Age of Empires II: Definitive Edition. This could be the pinnacle of the Age of Empires universe — at least according to fans of the beloved series.

With Parallels Desktop, players can weave together the olden times and the modern era on their hardware of choice.

Discover how you can step into epic tales of the past, equipped with your trusty Mac.

If you’re ready to embark on this legendary journey through the Age of Empires, let the gaming capabilities of Parallels Desktop Pro lead the way.

How to play Age of Empires on a Mac

It’s time to take command of your realm in the Age of Empires. Here’s how to get started conquering new realms in Age of Empires II with Parallels Desktop:

1. Install Parallels Desktop

If you don’t already have it, download and install the latest version of Parallels Desktop. The Pro or Business edition is recommended for the best gaming performance.

2. Create a Windows 11 Virtual Machine

Open Parallels Desktop and set up the Windows 11* virtual machine using prompts on the screen.

3. Adjust virtual machine settings on Pro or Business Edition

Access the Parallels Desktop Control Center and navigate to the “Hardware” section.

If you are using Parallels Desktop Professional or Business editions, you can adjust the virtual machine settings by allocating an adequate amount of RAM, CPU, and GPU resources to ensure a seamless gaming experience.

You can accomplish this by enabling the Gaming Profile.

When the Gaming Profile is enabled, Parallels Desktop provides more RAM and CPU to Windows, enters full-screen view for greater immersion, and toggles the mouse mode for better compatibility with games.

To enable the Gaming Profile:

1. Shut down Windows via the Start menu and open its configuration. 

2. Click “Change” and select “Games only”. 

*Note that you’ll need to purchase a Windows license if you don’t already have one.

Can I run Age of Empires II: Definitive Edition on Mac?

Age of Empires II: Definitive Edition is primarily designed for Windows but can be run on Mac using virtualization software like Parallels Desktop.

As a Mac user, you can experience the excitement of building empires and leading armies in this legendary game if your Mac meets the minimum requirements:

RequirementMinimal
OSWindows 10
ProcessorIntel Core 2 Duo or AMD Athlon 64×2 5600+
GraphicsNVIDIA® GeForce® GT 420 or ATI™ Radeon™ HD 6850 or Intel® HD Graphics 4000 or better with 2 GB VRAM
DirectXVersion 11
NetworkBroadband Internet Connection
Storage15 GB available space
Memory4 GB RAM

Does Age of Empires work on an M-series Mac?

Yes, you can transform your Mac into a formidable stronghold for playing Age of Empires on an M1, M2, or M3 chip Mac.

This video guide covers everything from setting up your virtual machine to improving its performance, getting you ready to play Age of Empires II: Definitive Editions as if you were playing on a Windows machine.

What versions of Age of Empires work on Mac?

The Age of Empires franchise has journeyed through time, with nine games released since 1997. Each chapter adds new lands to conquer, civilizations to develop, and challenges to overcome. As the series progresses, it brings more sophisticated gameplay, diverse cultures, and deeper historical narratives.

The Age of Empires universe encompasses:

  • Age of Empires (1997)
  • Age of Empires: The Rise of Rome (Expansion – 1998)
  • Age of Empires II: The Age of Kings (1999)
  • Age of Empires II: The Conquerors (Expansion – 2000)
  • Age of Mythology (2002)
  • Age of Mythology: The Titans (Expansion – 2003)
  • Age of Empires III (2005)
  • Age of Empires III: The WarChiefs (Expansion – 2006)
  • Age of Empires III: The Asian Dynasties (Expansion – 2007)
  • Age of Empires: Definitive Edition (2018)
  • Age of Empires II: Definitive Edition (2019)
  • Age of Empires III: Definitive Edition (2020)

With the release of Age of Empires IV in October 2021, the series achieved new heights, offering advanced graphics, refined mechanics, and an even broader historical scope.

The good news? You can play any of the Age of Empires games that are available on Windows on your Mac, provided your Mac meets the minimum game requirements.

Playing Age of Empires on Mac

The barriers that once prevented Mac users from partaking in the grand sagas of Age of Empires have been dismantled — if you use Parallels Desktop.

Embrace the challenge of strategy, conquer distant civilizations, and relive pivotal moments of history, all from sleek platform of your Mac.

Whether you’re strategizing the construction of your empire from the ground up, leading your armies into battle, or negotiating peace treaties, Parallels Desktop + Age of Empires provides an immersive gaming experience.

Ready to start your conquest and claim your place in history?

If your heart is set on this legendary odyssey, Parallels Desktop is the gateway to this epic voyage through time. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.