Three ways to put a VDI endpoint on a desk. The differences that matter are lifecycle and protocol flexibility — not, despite the sales decks, security.

What each one actually is

Thin client. A small device running a real but minimal operating system, usually Linux-based. It has enough local capability to run a client for several connection protocols, and it is centrally managed.

Zero client. Firmware rather than an operating system, purpose-built for one protocol. Nothing to patch, nothing to configure locally, and effectively nothing to attack.

Repurposed PC. An x86 machine you already own, converted by replacing its operating system with a hardened endpoint OS — ZeeTim’s ZeeOS being the example we deploy most. The hardware stays; the management model and security posture change completely.

The comparison

Thin client Zero client Repurposed PC
Capital cost Moderate Moderate Lowest — hardware already owned
Protocol flexibility High — multiple brokers Low — usually one High
Local data None None None after conversion
Patching burden Low, centrally managed Near zero Low, centrally managed
Lifecycle Long Longest Bounded by existing hardware age
Best for Mixed estates Single-protocol, high-security Large estates, constrained capital

The security point people get wrong

Zero clients are frequently sold on security, and the argument is real but narrower than it sounds. All three options store no local data and are centrally managed, which removes the main endpoint risk. The zero client’s advantage is a smaller attack surface — no OS to exploit — which matters in genuinely high-assurance environments and much less elsewhere.

For most estates, the security difference between a managed thin client and a zero client is not what should drive the decision. Protocol flexibility and refresh economics should.

The protocol trap

Zero clients are typically bound to one protocol. That is fine until the broker changes — and brokers do change. Organisations that standardised on zero clients for one platform have found themselves replacing hardware to follow a migration, which erases the lifecycle advantage that justified the purchase.

If there is any chance of moving between AVD, Citrix, Horizon or Windows 365 in the device’s lifetime, a thin client or converted PC keeps that option open.

Where repurposing wins

If you have a large estate of functional machines running an ageing OS, conversion is usually the strongest commercial case. You get central management and a clean security posture without a capital cycle. One GCC deployment covered 3,600 endpoints this way and cut refresh cost by 61% — see the case study.

The limit is hardware age. Conversion extends life; it does not reset it. Machines already near end of life should be replaced, which is why most real estates end up mixed — converted units alongside new 10ZiG or ZeeTim devices, managed from one console.

How to decide

Three questions settle it in most cases: How old is the existing hardware? Could the connection broker change within five years? Is there a genuine high-assurance requirement, or does it just sound reassuring?

For an estate-level view, start with a free EUC assessment.

Related: Lease, buy, or repurpose? · Thin clients and endpoint OS