The case for moving off VDI
Virtual desktop infrastructure (VDI) was once a standard answer for securing remote work, especially when employees depended on desktop applications. That calculus has shifted as web-based services have become the primary way most people do their jobs. The administrative overhead, cost profile, and user experience of VDI increasingly look like liabilities rather than features. For organizations whose teams mainly reach internal resources through a browser, remote browser isolation (RBI) offers a path to offload those VDI-backed workloads while keeping data and endpoints protected.
VDI delivers a full desktop environment from virtual machines hosted in a data center, streaming video to endpoint devices. It is typically run on-premise, either managed internally or by third-party Desktop-as-a-Service (DaaS) providers. The model promises centralized control and data that never touches user devices, and DaaS spending is projected to double by 2024. But the security benefit comes with heavy trade-offs.
Where VDI falls short
The most frequent objection to VDI is cost. On-premise deployments demand significant upfront capital expenditure on servers. DaaS shifts that to operational spending, but forces organizations to make difficult guesses about VM numbers, regions, service levels, and whether desktops should be persistent or pooled. Getting capacity wrong leads to overruns and wasted compute. Gartner projects that more than 90% of desktop virtualization projects deployed primarily to save cost will fail to meet their objectives by 2024.
User experience is another weak point. Even well-tuned VDI environments feel different from native apps — sessions can be latent or unresponsive when the infrastructure is not rightsized. That friction has real consequences beyond satisfaction: frustrated users seek workarounds outside the secured environment, and retention suffers.
Operationally, VDI is complex. Standing it up requires server investment, license planning, VM capacity modeling, app virtualization, network setup, and thin client rollout. It demands specialized virtual desktop administrators who are hard to hire and keep, and security policy is too often an afterthought rather than part of the initial design. Administrators frequently have to layer on separate logging, auditing, inspection, and identity tools — plus secure web gateway services — to make the environment usable and auditable.
Browser isolation as a VDI replacement
Most applications a workforce relies on today are browser-accessible, hosted in the public cloud, SaaS, or legacy data centers. That opens the door to remote browser isolation, which provides comparable security with fewer moving parts. Like VDI, RBI runs application code away from the endpoint. With Cloudflare’s implementation, all web code executes on Cloudflare’s global network, keeping untrusted devices and users away from data in use and insulating endpoints from ransomware, phishing, and zero-day threats. Administrators can enforce policies on any web-based or SaaS app — restricting file transfers, copy/paste, keyboard input, and printing — just as they would in a VDI session.
RBI differs from VDI in the economics and the day-to-day experience:
- End users get a transparent, faster experience. Cloudflare’s isolation runs across 270+ locations, so sessions are served close to the user without backhauling to centralized data centers. Its Network Vector Rendering approach avoids bandwidth-heavy pixel pushing, making the experience feel like a local browser.
- Administrators avoid upfront planning and scaling pains. Isolation policies are turned on from a single dashboard, and Cloudflare handles scaling across users and devices. Native integrations with ZTNA, SWG, CASB, and other security services ease the migration from VDI-adjacent setups.
- Costs are smoother and more predictable. There are no capital expenditures on VM capacity. Pricing is seat-based with no add-on fees for configuration, and no cloud consumption charges — a common source of VDI budget surprises. As Gartner notes, RBI is cheaper than VDI for isolation when the browser is the only application being isolated.

Note: Above diagram includes this table below

PensionBee moves from DaaS to RBI
PensionBee, a UK online pension provider, offers a concrete example. In response to the pandemic, the company rolled out Amazon WorkSpaces as a DaaS to let employees access internal resources remotely. The priority was securing Salesforce, which held customers’ sensitive pension data.
The DaaS gave PensionBee comparable access controls to what employees had in the office, but the experience quickly became a problem. CTO Jonathan Lister Parsons estimated that users were about 10% less productive on the DaaS, and IT staff had to build an automated tool just to reboot unresponsive employee sessions.
Because staff reached most applications — including Salesforce — through a browser, Cloudflare Browser Isolation was a natural fit. It gave PensionBee control over copy/paste and file downloads, protecting customer pension details from reaching local devices without the overhead of a virtual desktop.
"We started using Cloudflare Zero Trust with Browser Isolation to help provide the best security for our customers' data and protect employees from malware," Parsons said. "It worked so well I forgot it was on."
Planning a VDI transition
Moving off VDI requires more forethought than simply swapping one service for another. Cross-functional teams spanning IT, security, and infrastructure & operations should agree on how VDI is actually used, which use cases to offload first, and how changes will affect end users and administrators.
Cloudflare’s consultations start with end users, because adoption depends on their experience. From there, teams map and prioritize the applications and data that need protection. Finally, the discussion turns to the administrators and expertise needed — not just for initial configuration, but for ongoing improvements. The following questions guide that assessment:

Phase 1: Clientless web isolation for browser-based apps
Cloudflare's clientless web isolation approach routes access to private web applications through an isolated browser environment. Users simply follow a hyperlink — no endpoint software is required. Administrators can then layer on data protection rules that restrict risky actions within these isolated browsing sessions. This model is especially well-suited for extending access to contractors or third parties on unmanaged devices, since enrolling users takes nothing more than sharing a link.
These isolated links can coexist with the existing VDI deployment, providing a natural migration path. Running both approaches side-by-side gives internal stakeholders a direct comparison that can help build support for the browser-based model over time. Clear communication across teams remains important, both when deciding which applications to isolate first and when explaining the resulting changes to end users.
Phase 2: Moving SSH and VNC workloads to Cloudflare
Non-web applications present a different challenge. Many VDI environments still carry workloads that rely on SSH or VNC protocols — for instance, privileged administrators using SSH for remote desktop control, or employees needing VNC's graphical interface to reach legacy systems. Cloudflare extends browser-based access to both of these environments as well, again without installing client software on endpoints.
The architecture is the same for both protocols: an administrator establishes a secure, outbound-only connection between the target machine and Cloudflare's network, after which a terminal or graphical session renders directly in the browser. Because traffic flows through Cloudflare, each connection can be gated by identity-based authentication and granular policies, with full session auditing available. Setup and rule management happen through the same ZTNA console used for browser isolation.
A sensible order of operations is to begin with SSH for privileged administrators — who can provide valuable early feedback — and then expand to VNC for the broader user base that depends on it. This browser-based delivery typically reduces latency compared to a virtualized desktop and gives users a more direct, responsive workspace.
Phase 3: Evolving toward a Zero Trust posture
Step 3A: Enforce identity policies per application
Once the first two phases have established Cloudflare as the access layer for the selected web and non-web workloads, the next step is widening that coverage. The same policy builder used for isolated apps can apply conditional access rules across every application, with Zero Trust best practices in mind. Cloudflare supports concurrent integration with multiple identity providers and can even federate several instances of the same IdP, accommodating diverse user populations.
After identity verification is in place, many organizations layer on MFA requirements. These same identity checks can be enabled within the VDI environment itself during the transition, helping build organizational confidence in Zero Trust policies before VDI is fully decommissioned.
Step 3B: Add device posture checks
The steps up to this point have deliberately avoided endpoint agents to keep deployments fast. Over the long term, however, installing Cloudflare's WARP client adds meaningful security and visibility benefits. WARP runs on all major operating systems and supports flexible rollout: scripted deployment alongside common MDM tools for managed endpoints, or self-enrollment for third-party users.
With WARP in place, access policies can additionally verify the presence of specific applications or files, confirm disk encryption, check OS versions, and evaluate other endpoint attributes. Organizations using CrowdStrike, SentinelOne, or other endpoint protection providers can also require those tools to be present and healthy before granting access.
Device posture signals add granular visibility across both managed and BYOD equipment. As with identity checks, administrators can enable posture validation for VDI users first, then progressively route managed devices directly to applications — bypassing the slower virtualized path entirely.
Step 3C: Moving security services out of the virtualized environment
The cumulative effect of these phases is a reduced dependency on VDI infrastructure. The final stage of the transition is shifting the remaining workloads to cloud-delivered ZTNA, protecting one-to-one connections between every user and every application regardless of where those applications are hosted. Wider Cloudflare adoption yields greater consistency in controls, visibility, and end-user experience across the application portfolio.
Virtualization historically served as a bridge between legacy hardware investments and a cloud-first direction. But as applications, users, and data move to the cloud, maintaining virtualized security controls places an increasing burden on administrators and detracts from end-user productivity. Future-oriented organization can also evaluate Cloudflare's natively integrated Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and email security services as part of the broader transition.
Summary table

Transition best practices
Several guiding principles help make the move away from VDI as smooth as possible:
- Track end-user experience closely. The replacement must outperform what it replaces. Listen carefully to what users like and dislike about the new services to drive adoption.
- Foster cross-functional collaboration. Sunsetting VDI touches IT, security, infrastructure, and virtual desktop administration. Establishing shared workflows and trust early prevents friction later.
- Roll out incrementally. Test each phase with a limited set of users and applications before expanding. Starting with clientless web isolation on select apps is the fastest way to build momentum and win executive buy-in.
Progress metrics

With clientless browser isolation, an organization can begin the shift away from VDI almost immediately. A Zero Trust consultation can help map the specific migration path, and the broader Zero Trust roadmap provides guidance for sequencing this work alongside other security modernization efforts.



