Skip to content
JBRichardson.comIT Cloud Solutions

Zero Trust remote access for staff, without a flat VPN

Security & Resilience 6 min readUpdated October 7, 2026

Why giving everyone network-wide VPN access is risky, and how identity-aware, per-application access works instead.

All guides

A traditional VPN puts a remote laptop on your internal network. If that laptop or account is compromised, so is everything it can reach. Zero Trust flips the model: nothing is trusted because of where it connects from, and every request is checked for who is asking, on what device, for which application.

What changes in practice

Flat VPNZero Trust access
Access granted toThe whole networkOne application at a time
Identity checkOnce, at connectOn every request
Device checksRareRequired: patched, encrypted, managed
If an account is stolenWide exposureLimited to what that user may reach

A practical rollout

  1. Put every user behind single sign-on with MFA, preferably phishing-resistant passkeys or security keys.
  2. List your internal applications and who needs each one.
  3. Publish them through an identity-aware access service such as Cloudflare Access, with policies per application and group.
  4. Add device posture checks so only managed, up-to-date devices can reach sensitive systems.
  5. Keep a narrow VPN only for the few systems that cannot be published, and review it regularly.
  6. Log access centrally and alert on unusual sign-ins.

Pair it with the basics

  • Firewalls and segmentation inside the office so a single compromised device cannot roam.
  • Sandboxed analysis of suspicious files before they reach staff, as covered in our cyber threat assessment work.
  • Fast offboarding: removing a person from the directory should remove every access at once.