Secure Remote Access Pack
Replace legacy VPN with Microsoft Entra Global Secure Access - per-application Zero Trust access, with every connection checked against identity and device health.
The problem
A legacy Virtual Private Network (VPN) - or an Azure Point-to-Site (P2S) tunnel - puts remote users onto your network and trusts them once they are in, leaving a broad, always-open path an attacker can ride to anything inside. It is slow for users, costly to license and appliance, and blind to whether the device connecting is healthy. The fix is not a bigger tunnel. It is Zero Trust Network Access (ZTNA): each internal application published individually, each connection checked against identity and device health, and nothing on the network reachable by default.
What's Included
- Microsoft Entra Private Access to publish internal applications - web and non-web, any TCP/UDP port - without exposing them to the internet
- Replacement of legacy VPN and Azure Point-to-Site (P2S) connectivity with per-application access
- Microsoft Entra Internet Access to secure outbound traffic and whitelisted external resources, including Microsoft 365 traffic
- Access to external Software-as-a-Service (SaaS) through Microsoft Entra Enterprise Applications with single sign-on
- Conditional Access, device compliance, and continuous access evaluation applied per application (Microsoft Entra and Microsoft Intune)
- Global Secure Access client rollout across Windows, macOS, iOS, and Android via Microsoft Intune
- Microsoft-native Security Service Edge (SSE) design - an alternative to Zscaler and Cloudflare, built on the Microsoft Entra Suite
- A staged decommission plan for legacy VPN concentrators and always-on tunnels
What This Assumes
- Microsoft Entra Suite, or the equivalent Global Secure Access licensing for Microsoft Entra Private Access and Internet Access, plus Microsoft Entra ID P1 and Microsoft Intune
- An agreed list of internal applications and a pilot user group, with change windows for the cutover
- Applications reachable in a way Microsoft Entra Private Access can publish; anything it cannot is agreed as out of scope or handled separately
Not Included
- The Microsoft licensing subscription cost itself - ongoing, and borne by you
- Client-side firewall and network changes, and third-party (non-Microsoft) Security Service Edge products
- End-user support during and after the rollout
Outcomes
- Internal applications reachable per user, per device, per app - never the whole network at once
- Legacy VPN retired, removing an always-open attack path along with its appliance and licensing cost
- One consistent Zero Trust posture across remote and in-office users
- Access decisions that follow identity and device health, not network location
- Simpler sign-in for users - no separate VPN client, authenticated once through Microsoft Entra
Who It's For
- Organisations replacing legacy or Point-to-Site (P2S) VPN on Microsoft 365 and Microsoft Azure
- Security teams moving to Zero Trust who want a Microsoft-native alternative to Zscaler or Cloudflare
- Managed Service Providers (MSPs) and Cloud Solution Providers (CSPs) rolling out Zero Trust access as a repeatable template across many tenants
How to Start
Most engagements begin with the free audit and go no further until you have seen where you stand.
Design & Pilot
from £8,500 / $10,900
A fixed-scope design of your Microsoft-native Zero Trust access, with the first internal applications published and proven end to end.
- A Security Service Edge (SSE) design on the Microsoft Entra Suite - an alternative to Zscaler and Cloudflare
- Microsoft Entra Private Access publishing your first internal applications, with Conditional Access and device compliance per app
- A staged decommission plan for the legacy VPN concentrators and always-on tunnels
VPN Retirement Rollout
from £20,000 / $25,600
Phased onboarding of the remaining applications and users, ending with the legacy VPN switched off on an agreed date.
- Remaining internal applications onboarded in waves, web and non-web, any TCP/UDP port
- Global Secure Access client rolled out across Windows, macOS, iOS, and Android via Microsoft Intune
- Legacy VPN and Point-to-Site tunnels decommissioned, removing the always-open attack path and its appliance and licensing cost
Guarantee: your legacy VPN is fully retired on the agreed date, or the final milestone payment is waived.
Managed Rollout Retainer
from £3,500 / $4,500
An optional retainer that keeps publishing applications and tuning access policy as your estate changes.
- Ongoing application onboarding and per-app access policy tuning
- Conditional Access and device-compliance changes as your posture evolves
- A forward plan reprioritised every month
Engagement Model
Fixed-scope design and pilot → phased application onboarding → optional managed rollout retainer. Productised and outcome-based - never day rates. And it is guaranteed: your legacy VPN is fully retired on the agreed date, or the final milestone payment is waived. And it graduates into Continuous Evidence, so your Zero Trust posture and access evidence stay current inside the retainer, never reopened as a fresh project.
Pricing: from £8,500 / $10,900 - larger engagements are tailored to scope.
We govern the AI we deliver with
This work is delivered AI-accelerated, so AI tooling reads configuration and log data from your estate along the way. It is fair to ask how that is governed - and the answer is published: which providers we use and on what commercial terms, what client data never reaches a model, that a named architect signs off every output, and that AI tooling holds no standing write access to client systems.
Read our AI policyRelated
The Cyber-Insurance Renewal Pack
Legacy VPN is a control insurers now press on. Retiring it is often the finding on next year's questionnaire.
Microsoft Azure Security & Hardening
The platform hardening - identity, network, and workload controls - that Zero Trust access sits on top of.
Fractional CISO & Cloud Security Lead
Ongoing senior direction if you want the Zero Trust rollout governed and extended beyond the initial retirement.
VPN Retirement Readiness Checklist
Prefer to scope it yourself first? The free checklist of what still depends on the tunnel, what replaces it, and the cutover sequence that lands on a date.
Get started
Find out where you stand, free
Most engagements start with a no-cost posture audit against the baselines that matter to you. If a fixed-fee roadmap is the right next step, we'll say so - and if it isn't, we'll say that too.