# Zero Trust remote access for staff, without a flat VPN

*Security & Resilience · 6 min read · Updated 2026-10-07 · https://www.jbrichardson.com/resources/zero-trust-remote-access*

**Short answer:** Replace flat VPN access with identity-aware, per-application access: require MFA or passkeys, publish each internal app behind an access service such as Cloudflare Access, check device health, log access centrally, and keep a narrow VPN only for systems that cannot be published. Start with your riskiest application.

A traditional VPN puts a remote laptop on your internal network. If that laptop or account is compromised, so is everything it can reach. Zero Trust flips the model: nothing is trusted because of where it connects from, and every request is checked for who is asking, on what device, for which application.

## What changes in practice

|  | Flat VPN | Zero Trust access |
| --- | --- | --- |
| Access granted to | The whole network | One application at a time |
| Identity check | Once, at connect | On every request |
| Device checks | Rare | Required: patched, encrypted, managed |
| If an account is stolen | Wide exposure | Limited to what that user may reach |

## A practical rollout

1. Put every user behind single sign-on with MFA, preferably phishing-resistant passkeys or security keys.
2. List your internal applications and who needs each one.
3. Publish them through an identity-aware access service such as Cloudflare Access, with policies per application and group.
4. Add device posture checks so only managed, up-to-date devices can reach sensitive systems.
5. Keep a narrow VPN only for the few systems that cannot be published, and review it regularly.
6. Log access centrally and alert on unusual sign-ins.

## Pair it with the basics

- Firewalls and segmentation inside the office so a single compromised device cannot roam.
- Sandboxed analysis of suspicious files before they reach staff, as covered in our cyber threat assessment work.
- Fast offboarding: removing a person from the directory should remove every access at once.

> **Start with the riskiest app** Move your most sensitive application behind identity-aware access first. You get the biggest risk reduction and a working pattern to copy for the rest.

---
Published by JBRichardson LLC, 1603 North Olden Ave, Ewing, NJ 08638. Phone (609)-564-3016. https://www.jbrichardson.com/contact
