TL;DR: Traditional VDI adds cost and latency for a workforce that now relies heavily on web apps, while enterprise browsers shift access controls closer to the endpoint and reduce infrastructure overhead, according to Island. The governance question is no longer whether desktop virtualization works, but where browser-based access can replace it without weakening identity, device, and application controls.
NHIMG editorial — based on content published by Island: VDI Reduction: Strategies for Enterprise IT Teams
By the numbers:
- In most organizations, 80–90% of the applications being used are web-based external or internal applications.
- An enterprise browser can reduce the need for VDI by 80-90%, saving money on licensing costs.
- Only 13% of organizations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption.
Questions worth separating out
Q: How should security teams decide which users can move out of VDI?
A: Start with the applications, not the department.
Q: Why does VDI create governance issues for identity teams?
A: VDI can hide entitlement decisions behind a uniform desktop experience, but identity governance still has to answer who can access what, from where, and under which conditions.
Q: What do organisations get wrong when replacing VDI with enterprise browsers?
A: They sometimes treat the browser as a convenience layer instead of an enforcement point.
Practitioner guidance
- Segment users by access pattern Separate full desktop users from browser-first users by mapping each role to the applications it actually needs.
- Treat the browser as a governed access layer Apply conditional access, session policy, and data controls to the enterprise browser so access decisions are enforced where work happens.
- Rightsize VDI before replacing it Review VM templates, resource allocation, and application fit before assuming every desktop requires the same stack.
What's in the full article
Island's full post covers the operational detail this post intentionally leaves for the source:
- Browser deployment considerations for replacing or complementing VDI in specific user groups
- Practical scenarios for contractor onboarding, BYOD access, and secure application delivery
- Cost and infrastructure discussion around server load, maintenance, and licensing assumptions
- Vendor-specific enterprise browser capabilities and how they map to web application access
👉 Read Island's analysis of VDI reduction strategies for enterprise IT teams →
VDI reduction and browser-based access: what should teams change?
Explore further
VDI reduction is really an access governance decision, not just an infrastructure optimisation exercise. The article frames cost and user experience as the visible problem, but the deeper issue is how organisations decide where secure access controls should live. When applications are mostly web-based, keeping every user in a remote desktop adds complexity without adding proportional governance value. Practitioners should judge VDI by control necessity, not by habit.
A question worth separating out:
Q: What is the difference between VDI reduction and application virtualization?
A: VDI reduction is the broader strategy of cutting unnecessary desktop dependency, while application virtualization is one possible implementation that delivers individual apps without a full desktop. The right choice depends on workload complexity, compliance needs, and whether the user truly needs an isolated desktop environment.
👉 Read our full editorial: VDI reduction is really an access and governance problem