Cloud Security Stack
Tools and buyer guides

Tools

Zero Trust network access for teams that outgrew the VPN

When the old concentrator becomes the bottleneck, what to replace it with, and why most Zero Trust projects stall at the identity layer rather than the network one.

12 min read · Reviewed 22 August 2026 · Criteria and weights published. Product scoring in progress.

The problem is rarely the VPN

Most organisations reach for Zero Trust network access because the VPN is slow, or because it went down, or because someone read that VPNs are obsolete. Those are symptoms. The underlying problem is almost always that network location is still being used as a proxy for trust, and the concentrator is simply where that assumption became visible.

Replacing the concentrator without fixing the assumption produces a faster version of the same architecture. The traffic now takes a better path, and a compromised laptop still reaches everything it could reach before.

What actually has to change

01

Identity becomes the control point

Access decisions move to Entra ID with Conditional Access, evaluating user, device state and risk at the moment of the request rather than at the moment of connection.

02

Device posture is enforced, not requested

Compliance state from Intune becomes a condition of access. An unmanaged or non-compliant device does not get a reduced experience, it gets refused.

03

Applications are published individually

The unit of access becomes an application, not a subnet. This is the part that breaks the flat network, and it is the part organisations postpone.

04

The old path is switched off

Running both indefinitely is the most common outcome and the worst one. You now operate two access paths and an attacker only needs the weaker.

Where Zero Trust projects actually stall

Based on the ordering of work in the projects these guides draw on, not a survey.

  • Application inventory40
  • Device compliance25
  • Decommissioning the VPN25
  • The access product itself10

The tool is the last ten percent. Most of the cost is inventory and enrolment.

Where a dedicated product earns its place

Entra Private Access covers a large share of this natively if you are already licensed for it, and for Microsoft-centric estates that is usually the right starting point rather than a third product.

A dedicated vendor earns its licence in three situations: heavy non-Microsoft infrastructure, a need for site-to-site connectivity that identity-based access does not address, or a mixed estate where a meaningful number of devices will never be Intune managed. If none of those apply, buying one is an expensive way to avoid reading your Conditional Access policies.

Where a dedicated product is worth pricing

Only relevant if one of the three exceptions above applies to you. If none do, spend nothing here.

NordLayer

Zero Trust network access for mixed estates

Best for
Estates with meaningful non-Microsoft infrastructure, or devices that will never be Intune managed
Watch out for
If everything you own is Microsoft managed, Entra Private Access likely covers this and you already pay for it
See NordLayer (opens in a new tab)

Links above go to the vendor. Where a link is marked as an affiliate link, a purchase may earn this site a commission at no cost to you, and it played no part in the ranking.

Scores are not published yet

The criteria above are final. Per-product scoring is in progress against a live hybrid estate, and will name a pick, a runner-up and the case where each is the wrong choice.

Who should not buy one

If your estate is Microsoft-centric, your devices are Intune managed and you already hold Entra ID P2, you very likely do not need a separate product. Spend the money on the application inventory instead. That is the work that actually blocks the project, and no vendor can sell it to you.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.