By NHI Mgmt Group Editorial TeamBased on StrongDM: “How to Replace Your VPN with strongDM” (June 25, 2025)

TL;DR: Replacing VPN and LDAP access with gateway-based PAM changes how engineers reach servers and databases, reducing exposure to private keys on laptops and improving session auditability, according to StrongDM. The governance shift matters because access is being re-assembled around roles, least privilege, and traceable sessions rather than broad network reach.


At a glance

What this is: This is a practical guide to replacing VPN-based infrastructure access with gateway-mediated PAM for servers and databases, with the main benefit being narrower exposure and better session auditability.

Why it matters: It matters because IAM teams have to govern infrastructure access as a privileged access problem, not just a network routing problem, especially where server and database sessions need role scoping and traceability.


Context

VPN-based infrastructure access creates a broad trust path: once a user is on the network, the control boundary is often wider than the actual task requires. In IAM terms, that means the access model is anchored in connectivity rather than in explicit entitlements, session visibility, and privilege scope.

For server and database access, that approach tends to leave private keys, broad network reach, and ad hoc user management in place longer than necessary. A gateway-mediated PAM model shifts the control point closer to the target resource, where access can be assigned by role and recorded per session.

The article frames this as an operational replacement for VPN and LDAP in infrastructure environments, not as a redesign of application authentication. That is a common transition pattern for teams trying to tighten access without rebuilding every workflow at once.


Key questions

Q: What breaks when infrastructure access still depends on a VPN and direct private keys?

A: The control boundary becomes too wide. Users can reach the network before access is scoped to a specific server or database, which makes entitlement review, session audit, and least privilege harder to enforce. The result is broad connectivity with weak task scoping, which is exactly where infrastructure access becomes difficult to govern.

Q: Why do VPN-style access models increase privileged access risk for servers and databases?

A: They separate network reach from resource-level authorisation. Once a user is on the network, the organisation must rely on downstream controls to limit what they can touch, and those controls are often weaker than the VPN boundary itself. That is why session brokering and role scoping matter more than simple connectivity.

Q: How should teams design server and database access so it stays auditable?

A: Use enrolled resources, role-based assignment, and session logging as the core access pattern. That keeps the access model tied to specific targets and specific users or roles, rather than to a shared network trust zone that is hard to explain after the fact.

Q: When does replacing LDAP or VPN with PAM controls make the most sense?

A: It makes the most sense when the main problem is privileged infrastructure access rather than application login. If engineers need access to servers or databases and the current model relies on network reach, portable keys, or account sprawl, a PAM-style gateway can tighten governance without redesigning the underlying workloads.


Technical breakdown

Why VPN access creates a wider trust boundary for infrastructure

A VPN extends network reach before it evaluates the specific server or database the user intends to access. That model is convenient, but it collapses the boundary between being on the network and being authorised for a privileged session. For infrastructure teams, the result is that the access control plane sits too far from the asset being protected. PAM gateways change that by brokering the session toward the target resource instead of exposing the whole private environment to the client.

Practical implication: Map infrastructure access to the target resource and session, not to blanket network connectivity.

How gateway-mediated PAM changes server and database access

The architecture described here is simple: clients connect to a gateway, and the gateway connects to the server or database. That indirection allows the gateway to become the policy enforcement and audit point, while the client no longer needs direct reach into the internal network. For SSH and database sessions, this means access can be granted through inventory objects, roles, and per-session logging rather than through static network paths or shared credentials.

Practical implication: Use a gateway layer to centralise policy enforcement and session audit for infrastructure access.

Why role assignment and inventory modelling matter more than username sprawl

The article emphasises assigning servers and datasources to users or roles, then using those roles to control visibility and access. That matters because infrastructure access breaks down when entitlement logic lives in scattered accounts, bespoke keypairs, or one-off user provisioning. A role-based inventory lets teams separate admin and restricted access, align read versus write privileges, and keep the access model manageable as environments scale.

Practical implication: Model server and database access through roles and inventory objects before expanding to more users and environments.


Threat narrative

Attacker objective: Obtain broad infrastructure access that can be reused across servers and databases with minimal session visibility and weak task scoping.

  1. Entry begins when users rely on VPN reach or direct key-based access to reach internal servers and databases, which gives them broad network proximity before the task-specific control is applied.
  2. Privilege exposure persists because private keys can live on developer laptops and access is often tied to static usernames, shared network trust, or overly broad reach into the private environment.
  3. Impact is reduced when access is forced through a gateway that logs sessions and limits visibility to enrolled servers and databases rather than the whole network.
  • BeyondTrust breach 2024: A stolen BeyondTrust Remote Support API key let a China state-sponsored actor reset accounts and reach US Treasury workstations in 2024.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

VPN replacement is really a privilege-boundary redesign: The important shift here is not simply removing a tunnel, but moving infrastructure access from network presence to explicit session governance. That is a PAM problem first and a networking problem second. When access is modelled around servers and databases rather than around broad connectivity, least privilege becomes enforceable at the point of use.

Gateway-mediated access reduces the lifetime of trust: Static reach into a private network encourages long-lived assumptions about who can get where. A gateway forces access to be brokered through an inventory and role model, which shortens the trust path and makes the session observable. For infrastructure teams, that is the practical difference between access that is merely reachable and access that is actually governed.

Private keys on laptops are a governance smell, not just a hygiene issue: The article’s concern about keys on developer devices is really about uncontrolled credential portability. Once a key can travel with the user, the organisation loses clean attachment between person, role, device, and target resource. The implication is that infrastructure access should be anchored in governed issuance and session control, not in portable credentials.

Role-based infrastructure access scales better than account-by-account exceptions: The article’s model of users, roles, servers, and datasources is a familiar IAM pattern, but its value is in limiting exception growth. Separate admin and restricted accounts, assign resources by role, and keep the entitlement graph readable. Practitioner takeaway: if your infrastructure access model cannot be explained cleanly in roles and inventory objects, it will not stay auditable for long.

Least privilege only works when the access surface is the right size: The article implicitly shows that VPN-era access is often too coarse for modern infrastructure governance. Least privilege is easier to defend when the access surface is reduced to enrolled resources and logged sessions rather than the entire internal network. Practitioners should treat that as a control design issue, not a user convenience trade-off.

From our research library:

What this signals

Gateway-mediated infrastructure access is a governance control, not just an architecture choice: Once access is brokered through a gateway, teams can separate who may reach which server or database from who merely sits on the network. That is a stronger operating model for least privilege, especially where auditability matters as much as connectivity.

Session visibility becomes the decisive control signal: When infrastructure access moves through a controlled relay, the quality of the audit trail improves in a way that VPNs rarely deliver on their own. Teams should watch for whether access is actually attributable to a role, a target, and a session, not just to a successful connection event.


For practitioners

  • Define infrastructure access around enrolled resources Model servers and databases as governed inventory objects, then grant access through those objects instead of through broad network membership.
  • Remove direct reliance on private keys on laptops Move privileged access into a brokered session flow so engineers do not need persistent keys sitting on developer devices for routine work.
  • Separate admin and restricted targets Create distinct server and database entries for administrative and non-administrative access so roles map cleanly to privilege level.
  • Use roles as the default access unit Assign servers and datasources to roles rather than to individual users wherever possible, then keep role membership narrow and reviewable.
  • Limit network reach to what the gateway requires Place the gateway where it can reach only the target resources that are intentionally enrolled, rather than exposing the broader private environment.

Key takeaways

  • VPN-based infrastructure access tends to overextend trust because network reach and privilege scope are not the same thing.
  • A gateway-mediated PAM model changes the governance unit from the network to the session, which improves auditability and role enforcement.
  • Teams that still depend on portable keys and broad connectivity should treat infrastructure access as a privileged access design problem, not a connectivity convenience problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIVPN-era infrastructure access broadens privilege scope beyond the target resource.
NHI-10 — Human Use of NHIEngineers use brokered infrastructure credentials and sessions to reach non-human resources.
Recommendation — Reduce broad infrastructure reach by scoping NHI access to enrolled servers and databases only. Separate human intent from machine-mediated access paths and log the resulting sessions.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article centres on replacing portable credentials and ad hoc access with governed session control.
Recommendation — Apply authenticator management to reduce long-lived credential dependence for infrastructure access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsRole-based access to servers and databases is the article's core governance pattern.
Recommendation — Align infrastructure entitlements to role-based authorisation and review them against actual targets.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementBroad VPN reach and portable keys create conditions for credential reuse and pivoting.
Recommendation — Track infrastructure access paths for credential exposure and lateral movement opportunities.

Key terms

  • Gateway-mediated access: A privileged access model where a relay or gateway brokers the connection between a user and an internal resource. It reduces broad network exposure by constraining access to specific systems, while shifting governance onto session controls, resource inventory, and authorization policy.
  • Role-based infrastructure access: An entitlement model that assigns servers, databases, or other infrastructure resources to roles rather than to ad hoc users. It helps keep access reviewable at scale and reduces the drift that happens when every engineer receives one-off permissions.
  • Privileged Session Monitoring: Privileged Session Monitoring is the recording and review of high-risk access sessions after elevation is granted. It gives security teams visibility into commands, queries, and configuration changes, helping them detect misuse, support investigations, and prove that administrative actions were authorised.
  • Inventory-based access governance: A governance model that manages infrastructure access through explicit resource inventory objects, such as servers and datasources, instead of implicit network reach. It keeps privilege decisions attached to named targets and makes role assignment easier to review.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org