Citrix buys company that containerizes Windows desktop apps independently of the OS
Citrix on Tuesday announced that it has completed the acquisition of longtime partner Numecent, producer of technology that containerizes and manages Windows applications. The acquisition builds on joint efforts to integrate Numecent’s management tool, Cloudpager, with Citrix Desktop-as-a-Service (DaaS) after an integration announced in April let administrators natively publish and manage the application containers through familiar Citrix workflows. Numecent’s other product, Cloudpaging, packages Windows applications into isolated application containers independent of the underlying operating system, streaming them to Windows endpoints on demand rather than requiring them to be included in a desktop image. Citrix plans to further integrate the technology into its platform, while also continuing Cloudpaging and Cloudpager support for physical Windows devices. “Enterprise customers have told us for years that application management is one of the most painful parts of running a Windows environment,” said Shawn Bass, SVP and GM of Citrix DaaS, in the announcement of the acquisition. “Numecent has solved this in a genuinely elegant way. By bringing Cloudpaging and Cloudpager into Citrix, we can make this capability native to every DaaS and physical desktop deployment so IT teams get back the time they spend wrestling with images and app conflicts.” Analysts and consultants said the move will help enterprise IT to some extent, but will also increase vendor lock-in with Citrix while potentially exposing enterprises to data security risks. Good for Citrix customers Gartner VP Analyst Stuart Downes said, “overall, this is a positive for Citrix customers,” but he stressed that the promised conversions “are not 100% compatible.” He said, “low-level integrations into the kernel are generally not successful” because code that needs the lowest level of OS integration usually needs direct links to the hardware. Still, he estimated that applications at the low level probably account for only 2% of enterprise applications. For the more typical apps, Downes said that there will likely be “north of 90% compatibility. It varies. There are quite a lot of complex factors in app virtualization.” But he emphasized that Numecent offers two components: Cloudpager and Cloudpaging, and “we have yet to see how Citrix will integrate both.” Justin Greis, CEO of consulting firm Acceligence, also sees a lot of potential savings for the enterprise. “Large companies can have thousands of Windows applications, including legacy, custom, industry-specific, and highly specialized applications,” he said. “Many have dependencies on particular versions of Windows, libraries, configurations, or desktop images. Every major desktop refresh, Windows migration, VDI program, cloud move, acquisition, or infrastructure modernization effort can therefore create another application testing and repackaging cycle. The ability to abstract more of the application layer from the environment underneath it can remove a meaningful amount of that friction.” Noah Kenney, principal consultant at Digital 520, added that the theoretical advantage that Citrix can now offer has great enterprise potential. But, he argued, this likely amounts to an enterprise IT pay less now, pay more later situation. “There are operational savings here, which is why customers will adopt it, but the bill comes due when they try to leave,” Kenney said. “This is a good acquisition for Citrix and probably bad for enterprise leverage over time. Citrix can now lose the desktop and still keep the customer. Every application moved into Cloudpager raises the cost of the next migration. Customers get the simplification now and Citrix gets the switching cost later.” Half right Sanchit Vir Gogia, chief analyst at Greyhound Research, said that he reads the containerization pitch as half right. “The packaging premise is valid. The cross-operating-system execution premise is not,” he said. Gogia pointed out that Numecent Cloudpaging packages a Windows application with its dependencies and streams it to a Cloudpaging Player on a physical or virtual Windows endpoint, where it executes locally. “A Mac or Linux user reaches that application through Citrix’s remote delivery, where it still executes on Windows. That is cross-platform access, not cross-platform execution,” he said. “A Windows application does not become a Mac application merely because its pixels arrive on a Mac. The container is a packaging promise and the boundary of that promise is Windows.” That said, he noted that there is still a lot of value in the Citrix arrangement, because Cloudpaging separates an application from a particular Windows image and carries that package across physical and virtual Windows environments, including Arm-based devices. “The real advance is not escaping Windows,” Gogia explained. “It is making application change less dependent on desktop change. Microsoft’s own App Assure data puts enterprise application compatibility above 99.7%, and Cloudpaging’s commercial logic lives almost entirely inside the fraction that remains. At enterprise scale, the final 1% of applications can carry far more than 1% of the business risk.” But, he added, “Existing Numecent customers need binding answers on entitlements, migration and exit. Citrix has bought control of a useful Windows application lifecycle. Control now has to prove itself, and the proof it owes customers is less complexity, not merely more control for Citrix.” Possible risk However, consultant Brian Levine, executive director of FormerGov, pointed out that the nature of these new Citrix capabilities could expose users to serious security issues, including the risk of data exfiltration. He sees Cloudpager as “essentially a privileged switch that can push software to every Windows endpoint at once, which is precisely the kind of mass-distribution channel that produced SolarWinds and Kaseya. Bolting it onto Citrix, whose NetScaler gear has been a favorite ransomware target through repeated ‘CitrixBleed’ flaws, may leave CIOs and organizations wondering who will focus on security for the combined entity, and how will it prevent the type of attacks we’ve seen against Citrix.” Citrix was asked to comment on these security questions, but did not do so by publication time.
Computerworld
Polygon
Bored Giant
CNET
A Sharp Eye
Rewind Blog