Back to Field Notes
Zero Trust Architecture/Field Note

ZTNA Replacing VPN — A Migration Plan That Doesn't Stall

ZTNA migrations stall in the long tail of legacy applications. Sequence the migration around app discovery, not user populations.

Author

Sofia Reyes

Distinguished Architect, Zero Trust Practice

Published

January 24, 2026

Read

10 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Sequence the migration around application discovery, not user populations. Mature programs find 60–80% of apps suit ZTNA, 15–25% need a connector or proxy adaptation, and 5–10% require legacy network access for the foreseeable future.
  • 02Start with contractor and partner access — that is where ZTNA shines and where VPN deployments are weakest. Capture early-win UX testimonials before moving into employee migration.
  • 03Keep VPN for: UDP-only / broadcast / multicast admin tools, lab and OT environments where ZTNA connectors are not certified, and disaster-recovery break-glass paths. Plan a small, hardened VPN footprint as part of the end state.
  • 04The 5–10% legacy tail needs a deliberate strategy: ZTNA jump-host into an enclave, or a hardened residual VPN. Pretending it does not exist is what stalls programs at the 90% mark.

Zero Trust Network Access promises fewer attack surfaces, finer-grained access, and a better user experience than VPN. The procurement decision is straightforward; the migration is not. Most stalls occur in the long tail of legacy and contractor-facing applications.

Discovery first, then user migration

Before migrating users, build a complete inventory of applications they reach via VPN. Mature programs find that 60–80% of applications are well-suited to ZTNA, 15–25% need a connector or proxy adaptation, and 5–10% will require legacy network access for the foreseeable future. That last bucket needs a deliberate strategy — typically a small, hardened VPN footprint or an enclave reachable via ZTNA jump-host.

Contractor and partner access

Contractor and partner access is where ZTNA shines and where most VPN deployments are weakest. Use it as the early-win pattern: replace contractor VPN first, instrument the user experience, capture testimonial-quality data, then move into employee migration with momentum.

What to keep VPN for

  • 01Network-level admin tools (UDP-only protocols, broadcast/multicast)
  • 02Lab and OT environments where ZTNA connectors are not certified
  • 03Disaster recovery break-glass paths
#ZTNA#VPN#Remote Access

/WRITTEN_BY

Sofia Reyes

Distinguished Architect, Zero Trust Practice · Alexa Cybersecurity