TL;DR: As remote work and unmanaged endpoints persist, VDI’s complexity, latency, and cost are pushing enterprises toward browser-native secure access models, according to Seraphic. The identity implication is that session controls, device posture, and data handling now need governance at runtime rather than inside a centralized desktop stack.
NHIMG editorial — based on content published by Seraphic: Browser-native secure access and the limits of VDI
By the numbers:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
Questions worth separating out
Q: How should security teams govern access for unmanaged devices without relying on VDI?
A: Security teams should govern access at the session and data level, not assume the endpoint is trusted.
Q: Why do browser-based workflows create identity governance risk in regulated environments?
A: Because the identity decision at login does not control everything that happens afterward.
Q: What do organisations get wrong when replacing VDI with enterprise browsers?
A: They sometimes treat the browser as a convenience layer instead of an enforcement point.
Practitioner guidance
- Map remote access by workflow, not by device type Identify which applications and data flows still depend on VDI because of data sensitivity, then separate those from web-native workflows that can be governed at the browser session level.
- Define browser-session policy for sensitive actions Set explicit controls for copy, paste, download, print, upload, and local storage in the browser session.
- Treat session artefacts as governed access residue Include cookies, cached content, downloaded files, and browser storage in your identity and data handling policy.
What's in the full article
Seraphic's full article covers the operational detail this post intentionally leaves for the source:
- Browser-native enforcement examples for blocking copy, paste, print, download, and upload actions by policy
- Session hygiene specifics for clearing cookies, cache, and storage artefacts after the session ends
- Data residency and compliance handling across managed and unmanaged endpoints, including regulated workflows
- Browser-level DLP features such as watermarking, sensitivity labels, and prompt controls for AI tools
👉 Read Seraphic's analysis of browser-native secure access and VDI replacement →
Browser-native secure access: what it changes for identity teams?
Explore further
VDI is increasingly a control-plane mismatch, not just a performance problem. The article is really describing a shift in where trust lives. VDI centralised the desktop, but modern work is happening in browsers across managed and unmanaged endpoints, which means the access boundary has moved. That creates a governance gap for IAM and PAM teams because authentication may be strong while the session itself remains loosely controlled.
A question worth separating out:
Q: When is VDI still justified instead of browser-native access?
A: VDI can still make sense for highly specialised applications, tightly controlled desktops, or legacy workflows that cannot operate safely in a browser. It is harder to justify when the primary need is secure access to web applications, controlled data handling, and flexible work across managed and unmanaged endpoints.
👉 Read our full editorial: Browser-native secure access exposes VDI’s limits for enterprises