Zero Trust Without the Chaos: A Practical VPN Replacement Path
The Zero Trust principle of "never trust, always verify" is widely accepted. The harder question is where to begin when legacy VPN infrastructure is deeply embedded. Cloudflare's guidance for customers who are stuck in that spot: pick one or two high-value applications and offload them to a Zero Trust Network Access (ZTNA) service like Cloudflare Access. It's a concrete first step that delivers security and usability gains without demanding an overnight overhaul of your entire network.
The VPN Problem Isn't Just Security
The familiar VPN model grants network-level access by default after authentication. That trust invites lateral movement: an attacker who compromises one less-sensitive entry point can traverse the network toward critical data. Beyond that exposure, VPNs impose a poor user experience at today's scale of remote work, and they create avoidable manual work for IT teams already stretched thin.
Gartner has projected that by 2025 at least 70% of new remote access deployments will be served predominantly by ZTNA rather than VPN services, up from less than 10% at the end of 2021. The trade-off between security and employee experience is no longer a given.
How ZTNA Changes the Access Model
Instead of authenticating a user once and opening the corporate network, ZTNA evaluates each access attempt against rules based on identity, device posture, geolocation, and other context. Users are continuously re-evaluated as context changes, and all events are logged for visibility. This per-resource authorization eliminates the lateral movement vector that VPNs leave open.
The user-facing result is also different. As Udaan co-founder Amod Malviya put it, conventional VPNs "can lull people into a false sense of security." With Cloudflare Access, he said, the per-user, per-access model feels like "Authentication 2.0 — even 3.0." OneTrust reported similarly that employees connect to the tools they need so simply that they don't know Cloudflare is powering the backend.
Building a ZTNA Pilot Plan
Full VPN replacement can take considerable time, but incremental migration delivers value. ZTNA and VPN can co-exist while you move at your own pace.
For a pilot, choose one or two applications behind your VPN that would deliver the most visible win. Good candidates include:
- Applications with frequent complaints or heavy IT support ticket volume
- Internal tools used heavily or accessed by high-risk user groups
- Apps behind hardware or license renewals you already have planned
Your pilot's core team should include an identity admin or someone who manages internal employee apps, plus a network admin who understands traffic flow related to your VPN. Those perspectives will keep the rollout realistic, especially as scope shifts.
Executing the Pilot Transition
Step 1: Connect your app to Cloudflare's network
Cloudflare's Zero Trust dashboard guides you through setting up an app connector with no virtual machines required. You can create a tunnel for application traffic in minutes, route it by public hostnames or private network routes, and Cloudflare manages the configuration from there. The workflow supports web apps, SSH, VNC, RDP, and internal IPs. Once the tunnel is live, the application is invisible to the public Internet, which significantly reduces your attack surface.
Step 2: Link identity and endpoint protection
Cloudflare Access aggregates your existing security stack. It supports over a dozen identity providers (IdPs) including Okta, Microsoft Azure AD, Ping Identity, and OneLogin, and you can link multiple IdPs or separate tenants from a single provider — useful during mergers, acquisitions, or compliance updates like incorporating a FedRAMP tenant.
The IdP handles user stores and authentication; Cloudflare Access applies the Zero Trust rules deciding who reaches which resources. You can also integrate endpoint protection providers such as Crowdstrike, SentinelOne, Tanium, or VMware Carbon Black to factor device posture into access decisions.
If you start with simpler methods — one-time pins or social identity providers for external partners — you can expand later without altering your fundamental setup. Each integration just adds another contextual signal for your rules.
Step 3: Configure Zero Trust rules
Policies are customizable per app. A low-risk application might only require a @company.com email address plus SMS or email multifactor authentication. Higher-risk apps can demand hard token MFA, device posture checks, or validation via external APIs.
MFA is notably hard to deploy natively on many legacy on-prem apps. Using Cloudflare Access as a reverse proxy creates an aggregation layer that simplifies adding MFA across all resources.
Step 4: Test clientless access
Once an app is connected and rules are set, end users can typically test web, SSH, or VNC access with no device client or mobile device management rollout. This accelerates adoption and eases third-party access for partners and contractors.
A device client remains useful for protecting SMB or thick client apps, verifying device posture, or private routing. Cloudflare Access handles arbitrary L4-7 TCP and UDP traffic; with bridges to WAN-as-a-service it can also offload VPN use cases like ICMP or server-to-client initiated VoIP.
Pacing Toward Full VPN Replacement
Seeing the full scope of thousands of internal IPs and domains can make full replacement feel daunting. Two capabilities in Cloudflare Access can help you close the gap:
- Local domain fallback entries: Point selected internal hostnames to your internal DNS resolver so access to Intranet resources is disseminated more efficiently.
- Private network discovery: This report passively monitors network traffic over time. For discovered apps, Access workflows let you tighten Zero Trust rules as needed.
These tools reduce the anxiety around retiring a VPN entirely, letting you build toward Zero Trust at a sustainable pace.
Measuring the Business Impact
Customers who offload apps from VPNs report shorter onboarding times and fewer access-related tickets. eTeacher Group, for example, cut employee onboarding time by 60% after implementing Cloudflare Access.
If you maintain a co-existence strategy with your VPN, track ticket volumes and resolution times for the apps you've transitioned to ZTNA. Partner with HR to gather qualitative feedback on employee satisfaction and productivity. While connecting security improvements to specific cost savings involves many variables, reducing VPN reliance is a direct step toward shrinking your attack surface and improving your macro return on investment.
You can start with Cloudflare Access for free and follow the pilot steps outlined above. For broader planning, a Zero Trust roadmap can help you decide which project to tackle next.



