Multi-CloudHow-To & HardeningRetrospectives

How to Retire Legacy VPNs in Favor of Zero Trust Access

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

Traditional VPNs give users broad network access once connected and present a constantly targeted appliance on the internet. Zero trust access replaces that model with per-application access based on identity and device health. Here is how to plan the transition.

Step 1: Inventory what the VPN is used for

List the applications users reach through the VPN: internal web apps, file shares, remote desktop, legacy client-server apps, admin tools. Most organizations find that a small number of applications account for most usage.

Step 2: Move what can go to SaaS or the cloud

File shares to SharePoint/OneDrive, email to Exchange Online, and some apps to SaaS remove VPN dependency entirely.

Step 3: Publish internal web apps through an identity-aware proxy

Options include:

  • Microsoft Entra Private Access (part of Global Secure Access) for private apps.
  • Microsoft Entra application proxy for internal web applications.
  • AWS Verified Access for applications hosted in AWS.

Each enforces Entra ID (or your IdP) sign-in, Conditional Access and device compliance for every request.

Step 4: Secure administrative access

Use Azure Bastion, AWS Systems Manager Session Manager or privileged access solutions for server administration instead of VPN-plus-RDP.

Step 5: Shrink and harden the VPN

For what remains, require MFA, restrict access to specific subnets per user group, patch on an emergency SLA and monitor closely.

Step 6: Retire

Once usage is near zero, decommission the VPN appliances — removing one of the most attacked devices in your environment.

Measure

Track VPN users and connections monthly. The trend should be steadily down.

replace vpn with zero trustTravelex2019

More on this story