Three ways to put a VDI endpoint on a desk. The differences that matter are lifecycle and protocol flexibility — not, despite the sales decks, security.
What each one actually is
Thin client. A small device running a real but minimal operating system, usually Linux-based. It has enough local capability to run a client for several connection protocols, and it is centrally managed.
Zero client. Firmware rather than an operating system, purpose-built for one protocol. Nothing to patch, nothing to configure locally, and effectively nothing to attack.
Repurposed PC. An x86 machine you already own, converted by replacing its operating system with a hardened endpoint OS — ZeeTim’s ZeeOS being the example we deploy most. The hardware stays; the management model and security posture change completely.
The comparison
| Thin client | Zero client | Repurposed PC | |
|---|---|---|---|
| Capital cost | Moderate | Moderate | Lowest — hardware already owned |
| Protocol flexibility | High — multiple brokers | Low — usually one | High |
| Local data | None | None | None after conversion |
| Patching burden | Low, centrally managed | Near zero | Low, centrally managed |
| Lifecycle | Long | Longest | Bounded by existing hardware age |
| Best for | Mixed estates | Single-protocol, high-security | Large estates, constrained capital |
The security point people get wrong
Zero clients are frequently sold on security, and the argument is real but narrower than it sounds. All three options store no local data and are centrally managed, which removes the main endpoint risk. The zero client’s advantage is a smaller attack surface — no OS to exploit — which matters in genuinely high-assurance environments and much less elsewhere.
For most estates, the security difference between a managed thin client and a zero client is not what should drive the decision. Protocol flexibility and refresh economics should.
The protocol trap
Zero clients are typically bound to one protocol. That is fine until the broker changes — and brokers do change. Organisations that standardised on zero clients for one platform have found themselves replacing hardware to follow a migration, which erases the lifecycle advantage that justified the purchase.
If there is any chance of moving between AVD, Citrix, Horizon or Windows 365 in the device’s lifetime, a thin client or converted PC keeps that option open.
Where repurposing wins
If you have a large estate of functional machines running an ageing OS, conversion is usually the strongest commercial case. You get central management and a clean security posture without a capital cycle. One GCC deployment covered 3,600 endpoints this way and cut refresh cost by 61% — see the case study.
The limit is hardware age. Conversion extends life; it does not reset it. Machines already near end of life should be replaced, which is why most real estates end up mixed — converted units alongside new 10ZiG or ZeeTim devices, managed from one console.
How to decide
Three questions settle it in most cases: How old is the existing hardware? Could the connection broker change within five years? Is there a genuine high-assurance requirement, or does it just sound reassuring?
For an estate-level view, start with a free EUC assessment.
Related: Lease, buy, or repurpose? · Thin clients and endpoint OS