# What is Virtual Desktop Infrastructure (VDI) Security?

> Virtual desktop infrastructure (VDI) security protects centrally hosted desktop operating-system instances and the services that deliver their display and input to user endpoints.

- Canonical URL: https://yellowcube.eu/glossary/virtual-desktop-infrastructure-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

A typical deployment includes virtual desktops, hypervisors or cloud compute, images, storage, connection brokers, gateways, identity services, management planes, remote-display protocols, networks, and client software or browsers.

VDI can centralize desktop administration and keep some application data away from endpoint storage, but it also concentrates access and creates high-value control planes. Persistent and non-persistent desktops require different approaches to change, evidence, user data, and recovery.

### Key points

- **Protect access and brokering:** Strongly authenticate users and administrators, authorize resource requests, secure gateways and certificates, limit exposure, monitor sessions, and isolate privileged management.
- **Secure the hosted platform:** Harden hypervisors, brokers, images, agents, and virtual networks; control image provenance and updates; separate tenants and roles; protect storage; and detect unauthorized persistence.
- **Govern session channels:** Control clipboard, file, drive, printer, audio, camera, and USB redirection; manage downloads and caches; protect tokens and reconnect behavior; and retain proportionate evidence.
- **Important limitation:** VDI does not inherently secure the endpoint or session. A compromised client can capture credentials, input, screens, tokens, or authorized data, while a compromised control plane can affect many desktops.

### Related terms

[Remote Desktop Protocol (RDP) security](<https://yellowcube.eu/glossary/remote-desktop-protocol-security/>) · [Virtualization security](<https://yellowcube.eu/glossary/virtualization-security/>) · [Endpoint security](<https://yellowcube.eu/glossary/endpoint-security/>) · [Identity and access management (IAM)](<https://yellowcube.eu/glossary/identity-and-access-management/>) · [Zero trust architecture (ZTA)](<https://yellowcube.eu/glossary/zero-trust-architecture/>)

### Sources

[NIST SP 800-46 Rev. 2, Guide to Enterprise Telework, Remote Access, and BYOD Security](https://csrc.nist.gov/pubs/sp/800/46/r2/final) · [NIST SP 800-125, Guide to Security for Full Virtualization Technologies](https://csrc.nist.gov/pubs/sp/800/125/final) · [NIST SP 800-207, Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

