How to Retire Legacy VPNs in Favor of Zero Trust Access
Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.
Traditional VPNs give users broad network access once connected and present a constantly targeted appliance on the internet. Zero trust access replaces that model with per-application access based on identity and device health. Here is how to plan the transition.
Step 1: Inventory what the VPN is used for
List the applications users reach through the VPN: internal web apps, file shares, remote desktop, legacy client-server apps, admin tools. Most organizations find that a small number of applications account for most usage.
Step 2: Move what can go to SaaS or the cloud
File shares to SharePoint/OneDrive, email to Exchange Online, and some apps to SaaS remove VPN dependency entirely.
Step 3: Publish internal web apps through an identity-aware proxy
Options include:
- Microsoft Entra Private Access (part of Global Secure Access) for private apps.
- Microsoft Entra application proxy for internal web applications.
- AWS Verified Access for applications hosted in AWS.
Each enforces Entra ID (or your IdP) sign-in, Conditional Access and device compliance for every request.
Step 4: Secure administrative access
Use Azure Bastion, AWS Systems Manager Session Manager or privileged access solutions for server administration instead of VPN-plus-RDP.
Step 5: Shrink and harden the VPN
For what remains, require MFA, restrict access to specific subnets per user group, patch on an emergency SLA and monitor closely.
Step 6: Retire
Once usage is near zero, decommission the VPN appliances — removing one of the most attacked devices in your environment.
Measure
Track VPN users and connections monthly. The trend should be steadily down.