Organizations are increasingly turning to hybrid cloud deployments to balance their need for extra capacity with the mandates to reduce costs and ensure data security. With leading public clouds providing mature offerings, they are proving to be instrumental in allowing organizations to achieve these apparently conflicting goals.
By leveraging the cloud, organizations can reduce their data center usage – both for space and power – and avoid the costs associated with acquiring hardware. In addition, tier one public clouds can provide worldwide availability that allows organizations to scale capacity out and in as demand and users’ locations change, which can ensure and optimize user productivity. However, public clouds are inherently public, which places an additional burden on IT to ensure the security of all data, applications, and desktops that are hosted there.
Thankfully, tools exist that can help IT secure resources hosted in the cloud while ensuring end users have access to the applications and data they need to get their jobs done. Connection broker technology, traditionally only considered within the context of Virtual Desktop Infrastructures (VDI) or Desktops-as-a-Service (DaaS) deployments, provides IT with unique capabilities that help ensure the secure access of all computing resources and the data they hold in the cloud, and are particularly useful in hybrid environments.
When adopting a hybrid approach for an infrastructure, IT faces challenges beyond what the previous moat-and-castle security designs can handle. Environments hosted in a public cloud can be the target for data breaches and require additional considerations to guarantee against unauthorized access. In addition, these public cloud environments are subject to the same compliance regulations as the organizations on-premises resources.
Connection brokers help IT tackle these challenges in a way that “makes sense” across the complex landscape of a hybrid environment. Without a connection broker, IT finds themselves using different management consoles to control capacity and access across their hybrid environment. Doing so makes it difficult to ensure privileged access control rules are implemented consistently across all environments and complicates the tasks of monitoring and auditing access.
Instead, by using a connection broker that integrates with all platforms in a hybrid cloud environment, IT has a centralized control plan where they can provision or terminate instances, authenticate and authorize users to hosted resources across environments, and monitor user access to ensure compliance. And, connection brokers provide a common entry point for end users, as well, allowing IT to enforce multi-factor authentication, implement role-based access control, and potentially record remote sessions, for example, all from a single platform.
To further improve security, connection brokers that are part of a broader remote access platform seamlessly integrate with security gateways to support network architectures that keep resources hosted in the public cloud off of the public internet. The connection broker intelligently controls the security gateway to authorize access and connect users only to specific resources hosted in the private network. This design eliminates the need for a VPN, which can hinder user performance and scale poorly, and instead allows IT to build an access control solution that adheres to zero-trust concepts.
If your organization has not yet embarked on a hybrid cloud adventure, how do you know now is the time and that a connection broker is right for you? To start, look for end-user and corporate initiatives that typically benefit from a hybrid cloud approach, including:
- A distributed workforce collaborating on a common corporate data set – keep data off of end-user devices by connecting users to computing resources hosted in the cloud
- Contractors and part-time employees – restrict project-based workers from accessing your corporate data center by providing them with computing resources in the cloud
- Traveling employees – avoid sending corporate resources into the field and, instead, connect mobile workers to cloud-hosted resources
These are just a few examples of very common business workflows that benefit from the additional security gained by leveraging a connection broker to manage a hybrid cloud environment. Without leveraging the public cloud, these scenarios require IT to open up the corporate firewall to remote, traveling, or non-corporate users and can easily result in corporate data leaving the corporate network. Moving these workflows into the cloud isolates these users from the corporate datacenter, while using a connection broker to manage access ensures secure connections only to the authorized resources.
When architecting a hybrid cloud managed by a connection broker, ensure that you design security and high availability into the management plane, as well as into the hybrid cloud the connection broker manages. Connection brokers should be kept off of the internet, with security gateways providing access to login portals. Set permissions in the cloud that restrict the connection brokers to manage only the hosted resources that are part of the end-user computing environment. And, design redundancy into the environment by clustering connection brokers and security gateways, as well as by spreading resources across cloud regions. When well-architected, the connection broker acts as a set-it-and-forget-it tool, regulating access so that IT can focus on other tasks.
One of those tasks is monitoring the environment to ensure ongoing security. As the single point of access for hybrid environments, a connection broker acts as a lens where IT can focus attention on who is accessing what resources, from where, and for how long. This level of detail across all hosting platforms allows IT to flag outliers in end-user behaviors to spot potential breaches, for example, as well as to plan for the future by tracking resource usage trends over time.
As cloud and on-premises technologies evolve, IT must constantly evaluate their organization’s environment to ensure it capitalizes on emerging trends. Leveraging a connection broker can help here, as well, as the connection broker provides end users with a consistent access portal and experience while IT updates, modifies, or reinvests in the underlying technologies. For example, advancements in container technology may influence the move of end-user computing resources off of virtualization hosts and into containerization services. Connection brokers isolate end users from these types of underlying infrastructure changes, whether those are on-premises or in the cloud.
And, most importantly, connection brokers ensure the security of the infrastructure and data by being the persistent gatekeeper for hybrid corporate resources, implementing multi-factor authentication, restricting access based on rich access control rules, and monitoring user connections to corporate data. When it comes to securing hybrid cloud infrastructures, connection brokers play an invaluable role that benefits end users, IT, and the organization as a whole. As you map your journey to a hybrid cloud, consider the strategic implementation of connection brokers as part of your broader cloud security strategy.
##
ABOUT THE AUTHOR
Karen Gondoly is CEO of Leostream, a vendor neutral platform providing a comprehensive and scalable solution for organizations to securely deliver and manage remote access to physical and virtual machines hosted on-premises and in cloud environments.





