Tools
Zero Trust network access for teams that outgrew the VPN
When the old concentrator becomes the bottleneck, what to replace it with, and why most Zero Trust projects stall at the identity layer rather than the network one.
The problem is rarely the VPN
Most organisations reach for Zero Trust network access because the VPN is slow, or because it went down, or because someone read that VPNs are obsolete. Those are symptoms. The underlying problem is almost always that network location is still being used as a proxy for trust, and the concentrator is simply where that assumption became visible.
Replacing the concentrator without fixing the assumption produces a faster version of the same architecture. The traffic now takes a better path, and a compromised laptop still reaches everything it could reach before.
What actually has to change
Identity becomes the control point
Access decisions move to Entra ID with Conditional Access, evaluating user, device state and risk at the moment of the request rather than at the moment of connection.
Device posture is enforced, not requested
Compliance state from Intune becomes a condition of access. An unmanaged or non-compliant device does not get a reduced experience, it gets refused.
Applications are published individually
The unit of access becomes an application, not a subnet. This is the part that breaks the flat network, and it is the part organisations postpone.
The old path is switched off
Running both indefinitely is the most common outcome and the worst one. You now operate two access paths and an attacker only needs the weaker.
Where Zero Trust projects actually stall
Based on the ordering of work in the projects these guides draw on, not a survey.
- Application inventory40
- Device compliance25
- Decommissioning the VPN25
- The access product itself10
The tool is the last ten percent. Most of the cost is inventory and enrolment.
Where a dedicated product earns its place
Entra Private Access covers a large share of this natively if you are already licensed for it, and for Microsoft-centric estates that is usually the right starting point rather than a third product.
A dedicated vendor earns its licence in three situations: heavy non-Microsoft infrastructure, a need for site-to-site connectivity that identity-based access does not address, or a mixed estate where a meaningful number of devices will never be Intune managed. If none of those apply, buying one is an expensive way to avoid reading your Conditional Access policies.
Where a dedicated product is worth pricing
Only relevant if one of the three exceptions above applies to you. If none do, spend nothing here.
Zero Trust network access for mixed estates
- Best for
- Estates with meaningful non-Microsoft infrastructure, or devices that will never be Intune managed
- Watch out for
- If everything you own is Microsoft managed, Entra Private Access likely covers this and you already pay for it
Links above go to the vendor. Where a link is marked as an affiliate link, a purchase may earn this site a commission at no cost to you, and it played no part in the ranking.
Scores are not published yet
The criteria above are final. Per-product scoring is in progress against a live hybrid estate, and will name a pick, a runner-up and the case where each is the wrong choice.
Who should not buy one
If your estate is Microsoft-centric, your devices are Intune managed and you already hold Entra ID P2, you very likely do not need a separate product. Spend the money on the application inventory instead. That is the work that actually blocks the project, and no vendor can sell it to you.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.