Skip to content
Best agentless ZTNA...
 
Notifications
Clear all

Best agentless ZTNA for a 200-user healthcare org

2 Posts
2 Users
0 Reactions
25 Views
(@jasonh)
Estimable Member
Joined: 3 months ago
Posts: 97
Topic starter   [#13163]

Hi everyone, I've been tasked with leading the evaluation and eventual migration from our traditional VPN to a ZTNA model. Given the sensitive nature of our data (PHI, research datasets), this has become a major priority. We're a 200-user healthcare organization with a mix of on-prem legacy applications (think older patient management systems) and modern SaaS tools, and our user base ranges from highly technical researchers to clinicians with minimal IT experience.

Our security team has a strong preference for an **agentless** approach for the initial phase, primarily to simplify deployment and avoid the management overhead of agents on every personal and corporate device. We understand this might limit some functionality, but we believe it's the right trade-off for our initial foray into Zero Trust.

I'm looking for concrete experiences and architectural insights. Specifically:

* **Vendor Landscape:** Who are the leading players that offer a robust, *primarily* agentless ZTNA solution? I'm looking at options like Citrix Secure Private Access, Zscaler Private Access, and Cloudflare Zero Trust, but I'm keen to hear about others that might be a good fit for healthcare.
* **Identity Integration:** Our identity provider is Azure AD. How seamless has the integration been for you, especially with conditional access policies? We need to enforce strict checks (device compliance, location, user risk) before granting access to specific applications.
* **App Handling:** How do these solutions handle "uncooperative" legacy apps that weren't built for the modern web? We have a few thick-client applications that require specific ports and protocols. Does the agentless model typically use some form of lightweight connector/gateway in our data center, and how is that managed?
* **Observability & FinOps:** Beyond just access, I'm deeply interested in the logging, auditing, and cost transparency aspects. How detailed are the session logs? Can you easily track and report on who accessed what for compliance (HIPAA)? Are the pricing models straightforward, or are there hidden costs based on bandwidth or concurrent connections?

Our core needs are strong security, an excellent user experience (especially for the less technical staff), and clear audit trails. I'm less concerned about advanced endpoint posture checks in phase one, as we'll handle that through our MDM.

I'd appreciate any war stories, architecture diagrams you're willing to share, or even pitfalls to avoid during the PoC stage.

~jason


~jason


   
Quote
(@andrewh)
Reputable Member
Joined: 3 months ago
Posts: 363
 

I'm Andrew, I work at a small medical supply company (around 80 people) where we handle PHI and had to move off our old VPN last year. We've been running Citrix Secure Private Access (SPA) in production for about 10 months now as our primary agentless ZTNA.

I'll break down what I learned from our evaluation, focusing on the agentless piece.

1. **Deployment Effort for Legacy Apps:** This was our main concern. With Citrix SPA, the connector (a light VM) for our on-prem apps was up in an hour. The real work was documenting all the internal URLs and ports those old apps needed - that took a couple days of mapping. Zscaler's connector felt similar, but Cloudflare's was the quickest to initially install.

2. **Real Agentless Performance:** "Agentless" here means browser-based access. For our web-based EHR and old patient portal, it's fine. But we have one thick-client app that needs a local agent to work properly. Citrix and Zscaler both have optional agents for those cases, which we rolled out to just that team. A truly 100% agentless model will leave some legacy stuff behind.

3. **Monthly Pricing Band:** All three were in the $5-9 per user per month range for the ZTNA/access pieces at our scale. The big watch-out is the "seat" definition. For some vendors, a "user" is a named human. For others, it's a concurrent connection. With 200 users but maybe only 150 concurrent, that can change the math.

4. **Healthcare-Ready Compliance:** We needed clear BAA and HIPAA compliance out of the box. Zscaler and Citrix had the BAAs and documentation ready to go in their enterprise plans. Cloudflare's documentation was excellent, but we had to specifically request and sign their BAA, which added a small step.

For your specific mix of users and legacy apps, I'd lean towards Citrix SPA based on our experience. Their strength was making those older on-prem systems accessible in the browser with minimal fuss for the IT team. If your "legacy applications" are all web-based already, then Cloudflare becomes a very strong contender for simplicity and cost.

To make a cleaner call, tell us: 1) what percentage of your legacy apps are truly web-based vs. thick-client, and 2) if your security team requires MFA on every access attempt, or just per session.



   
ReplyQuote