Why Zero Trust Migrations Stall

For network engineers, the cutover weekend remains the most perilous moment of any infrastructure overhaul. Flipping a 30,000-user organization from fragmented VPNs to a new architecture in one window—often involving 1,000+ legacy applications—carries enormous risk. One misconfigured firewall rule or a dropped session can halt essential services and create operational gridlock.

This "big bang" migration risk is the single greatest obstacle to Zero Trust adoption. Organizations find themselves caught between aging, vulnerable infrastructure and a migration process that appears too dangerous to attempt.

Cloudflare and CDW approach this problem differently. Their collaboration combines Cloudflare’s global Zero Trust platform with CDW’s experience navigating complex deployment failures, providing a strategic roadmap that avoids the downtime typically associated with large-scale transitions. The goal is to transform legacy debt into a modern security posture—not simply relocate existing plumbing.

Avoiding the Lift-and-Shift Trap

Traditional migrations often fail because they treat the network as simple plumbing rather than a complex ecosystem of interdependent applications. Without a granular strategy, organizations fall into the "lift and shift" trap, attempting to move hundreds of applications simultaneously without understanding their backend dependencies.

CDW counters this with a risk-aware, tiered methodology. Every application is categorized by technical complexity. Simple, modern apps move first to generate momentum, while complex, legacy systems are scheduled for a more controlled, later stage. A recent public sector project illustrates the consequences of skipping this structure: a team tried to migrate 500 applications at once, lacking a tiered approach to prioritize among 4,000+ applications. The result was systemic service disruption.

CDW’s strategists—many former security practitioners—analyze these industry-wide failure points to identify recurring anti-patterns and build a more resilient migration blueprint. By framing the work as application modernization rather than a connectivity swap, security requirements get built into the foundation of the move instead of bolted on afterward.

Wrapping Legacy Apps with Modern Access Controls

The starting point is Cloudflare Access, which replaces the broad perimeter of a traditional VPN with a Zero Trust model. Instead of granting access to an entire network segment, Access evaluates every request based on identity, device posture, and other contextual signals. This reduces the attack surface and prevents the lateral movement that causes systemic outages. Once this layer is established, legacy applications can be "wrapped" in Access, modernizing their security posture without rewriting code.

The wrapping logic addresses a common scenario:

  • Problem: A legacy application without built-in Multi-Factor Authentication (MFA) is exposed via a standard VPN, creating a high-risk entry point.
  • Mitigation: Cloudflare Tunnel creates an outbound-only connection with both Single Sign-On (SSO) and MFA built in. The application no longer has a public IP address, hiding it from Internet scans and attacks.
  • Policy: A Cloudflare Access policy at the edge requires an endpoint hardware-based MFA check and a device health scan before any packet reaches the server.

This technique lets organizations migrate at their own pace, gaining immediate security benefits from a modern cloud environment while legacy apps continue to run safely in the background.

Pre-Migration Audit Essentials

Before launching a pilot, IT leaders must audit their environment for architectural readiness. "For large deployments, we focus on application modernization," says Eric Marchewitz, a security solutions executive at CDW. "Many legacy applications could break if least privilege access was applied without proper preparation."

Architecture and Identity Assessment

  • Determine identity providers: Identify which applications rely on federated identity providers (such as Okta) versus legacy local directories.
  • Map dependencies: Document backend database and API dependencies for each application to prevent service interruptions. This revealed data identifies hidden API calls that typically break during cutover when service token-based Tunnel connectivity is not maintained.

Establish a Firebreak

Separate the project into a Strategy Group (focused on security standards) and an Implementation Group (focused on efficiency). This ensures that high-level security requirements—like those preventing lateral movement—are not bypassed for the sake of deployment speed.

Persistent Session Stress Testing

Legacy architectures often maintain session persistence poorly, causing connection drops during cellular tower switching. Cloudflare’s architecture, supported by Dynamic Path MTU Discovery (PMTUD), maintains a persistent session at the edge even as the client IP changes. Identifying affected users during the audit allows displacement of expensive, rigid legacy hardware with a modern, single-pass architecture.

Categorization and Timeline Setting

Once complete, the remaining stack is tiered to set realistic implementation timelines:

Application Tier

Description

Estimated Migration Effort

Tier 0 (Modern SaaS Apps)

Native SAML/OIDC support so Cloudflare acts as a clientless identity provider proxy during authentication

1–3 hours per app

Tier 1 (Internal Web Apps)

Standard identity headers and modern web protocols support a clientless reverse proxy deployment with Cloudflare Tunnel 

3–6 hours per app

Tier 2 (Non-Web Client-Server Apps)

Specific port/protocol support or thick-client configurations required so both Cloudflare One Client and Cloudflare Tunnel deployments are used

4–8 hours per app

Tier 3 (Legacy Enterprise Apps)

Complex server-side connectivity (e.g. peer-to-peer, bidirectional) or back-end dependency requirements so Cloudflare Mesh or WAN deployments may complement Cloudflare Tunnel to support.

1–3 days per app; may require code revisions

A Phased Roadmap

Achieving "escape velocity" from legacy hardware requires a phased rollout that prioritizes coexistence over replacement.

  1. Phase 1: Strategy & Infrastructure: Build strategy and implementation teams, identifying CDW strategists—former CISOs and architects—to serve as peer sounding boards.
  2. Phase 2: Pilot Rollout: Deploy the Cloudflare One Client to a pilot group, addressing friction points like the "latency tax" to ensure performance doesn't compromise security.
  3. Phase 3: Production Scaling: Scale across the organization, maintaining a dual-client period where users run both legacy VPN and Cloudflare Access in tandem. This preserves a safe rollback path and eases the end-user transition.

Cloudflare’s single-pass architecture runs every security check simultaneously. "When we talk to customers about the connectivity cloud, the most impactful change isn't just the modern security posture. It's the operational velocity," notes Annika Garbers, Head of Cloudflare One GTM. "Moving to a single control plane allows a security team to stop being a bottleneck." A post-quantum encrypted foundation future-proofs the bridge against the next generation of threats.

Building the Bridge, Not the Big Bang

Modernization is a bridge-building exercise, refined through a Partner Technical Advisory Board where partner feedback directly informs the product roadmap. By focusing on application modernization and phased rollout, organizations regain architectural control and eliminate the fragmentation penalty. The combination of Cloudflare’s SASE platform and CDW’s migration expertise provides a safety net—immediate security benefits of identity-based access and phish-resistant MFA without the operational gridlock of an unmapped cutover.

The objective is not just moving applications to the cloud. It's ensuring that upon arrival, the environment is more resilient, more visible, and significantly harder to breach.