Earlier quoted context omitted.
> lets them use their personal hardware without much compromised in the way of security How do they protect against an attacker compromising this client, waiting until the employee is asleep or away for a few minutes, then using the employee's session to compromise the remote machine? Even if session establishment requires 2FA, the attacker could keep the session alive after the user attempts to close it.
For a targeted attack with a hacker remotely or physically controlling the client, I agree. However I think an automated attack would be difficult, especially if the VD sent its data to the client as a video stream, and only recieved keyboard and mouse inputs. Now maybe there's some fancy computer vision that could handle this (and all without the employee noticing)...
It's definitely going to keep a lot of the commodity malware out, but it's only going to stay secure until attackers start targeting it. And the risks from "inside" the machine (user downloads and runs something bad) don't go away, although the company gets a bit more control over the network (could also be done with an always-on VPN).