TL;DR: VPNs still leave modern teams with all-or-nothing network access, weak auditability, and poor least-privilege enforcement across cloud and legacy systems, according to StrongDM’s analysis. The operational problem is not remote access itself but the identity governance model underneath it, which must cover humans, service accounts, and privileged workflows together.
At a glance
What this is: This is a StrongDM analysis arguing that VPNs no longer fit modern access governance because they expose too much once a user connects and do not provide enough identity-level control or auditability.
Why it matters: It matters because IAM, PAM, and NHI programmes now have to govern access by identity, privilege, and session rather than by network location alone.
Context
A VPN gives a device network reach, but it does not decide which identity should reach which database, server, cluster, or command. That gap becomes visible when access must cover humans, contractors, vendors, and service accounts across mixed cloud and legacy environments.
The problem is not remote access itself. The problem is that network-based control treats connectivity as permission, while modern identity governance needs resource-level entitlement, auditability, and offboarding across privileged and non-human access.
Key questions
Q: What breaks when a VPN is used as the main remote access control in hybrid environments?
A: The main failure is that a VPN authenticates the user and then grants broad network reach, which makes lateral movement much easier than application-scoped access would. In hybrid environments, that means the control protects the entry point but not the post-login attack surface. Security teams should judge remote access by how little it exposes after login, not by whether the tunnel works.
Q: Why does all-or-nothing VPN access increase security risk in hybrid environments?
A: All-or-nothing VPN access increases risk because one authenticated connection can expose legacy systems, cloud services, and administrative paths that should not share the same trust level. The broader the internal reach, the easier it is for a valid user or compromised account to move beyond its intended scope and access more than the business meant to allow.
Q: What are the signs that network based access controls are failing in dynamic environments?
A: Common signs include frequent firewall updates, expanding allowlists, growing use of VPNs and bastion hosts, and teams creating exceptions to keep development moving. Those are indicators that policy is lagging behind infrastructure change. When access rules need constant manual maintenance, the control model is no longer matching the pace or shape of the environment.
Q: How should teams govern VPN alternatives across humans, vendors, and service accounts?
A: Teams should govern them as a lifecycle problem across identity types, not as a single connectivity problem. That means assigning access by role and system, provisioning only what each actor needs, and ensuring offboarding removes the same access paths that onboarding created. The network is transport, not entitlement.
Technical breakdown
Why network-based access control breaks in modern environments
VPNs were built around the assumption that network membership could stand in for trust. In modern estates, that assumption fails because one connection can expose many systems, many identities, and many privilege levels. Once cloud services, legacy databases, Kubernetes, and third-party access all sit behind the same tunnel, the network layer no longer expresses who should reach what. Identity becomes the control plane, not the subnet. The important shift is from perimeter enforcement to entitlement enforcement, where access is scoped to the resource and the session instead of the network location.
Practical implication: move privileged access decisions out of the VPN layer and into identity- and resource-aware control points.
How audit trails change when access is mediated by identity
A connection log only proves that a session existed. It does not show what the user queried, which command ran, or what data was retrieved. That is the central auditability weakness in network-based access control. Stronger access mediation records the identity event, the authenticated session, and the privileged action, which creates a usable chain of accountability for compliance and incident review. For NHI governance, the same principle applies to service accounts and automated workflows: if the access event is not tied to the action, the control cannot support forensics or recertification.
Practical implication: require command-level and session-level logging for privileged access, not just connection timestamps.
Why least privilege must be enforced at the resource layer
Least privilege cannot be reliably enforced when the first control is broad network admission. A VPN can place a user inside the environment, but it cannot naturally limit that user to read-only access on one database while denying lateral reach to everything else. The article’s examples point to a resource-centric model where authorization happens at the target service, not at the tunnel entrance. That matters for PAM because privileged workflows need narrow, auditable access paths, and for NHI because service identities often need deterministic scope that a network boundary cannot express.
Practical implication: define access at the target system and session layer, then use the VPN only as transport if it still exists.
Threat narrative
Attacker objective: The objective is to turn one valid connection into broad internal access that bypasses least privilege and obscures what the actor actually did.
- Entry occurs when a user, contractor, or vendor authenticates through a VPN and receives broad network reach rather than scoped access to a specific resource.
- Escalation occurs when that network position allows movement from the intended application or database to other internal systems with no additional identity check.
- Impact occurs when the actor uses that reach to access more data and more systems than the business intended, with limited forensic visibility into what happened.
Breaches seen in the wild
- Azure Key Vault Contributor escalation 2024: Datadog found Azure Key Vault Contributor could add itself to access policies and read every secret, key and certificate in a vault.
- Uber breach 2022: A contractor's stolen password and MFA fatigue gave a Lapsus$-linked attacker Uber's internal tools; Uber rotated keys to many services.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Network access is no longer a sufficient trust boundary: VPNs assume that once a user is on the network, the access problem is mostly solved. That assumption collapses in cloud and hybrid estates where one session can touch databases, servers, clusters, and admin workflows with very different sensitivity levels. The implication is that identity governance has to move from network admission to resource-specific authorization.
Privileged access control must be evaluated by session evidence, not connection evidence: A connection log does not tell you whether a database query was read-only or whether a command changed system state. This is where PAM becomes more than a user-access layer. Practitioners need controls that preserve accountability at the command and action level, not just the login level.
Service accounts and human users now need the same governance logic, applied differently: The article treats humans, contractors, vendors, and service accounts as part of the same access problem because they all need differentiated access to the same infrastructure. That is the right framing. Access policy should be governed as a lifecycle across actor types, with the resource, not the network, as the unit of control.
Identity blast radius is the real VPN problem: Once a tunnel is established, the practical blast radius is whatever sits behind it. That creates a governance gap where lateral reach is broader than intended and recertification tells you nothing useful about what the session could reach. Practitioners should treat excessive network reach as an identity design flaw, not a transport problem.
Zero Trust only helps when it is enforced at the right layer: The article’s strongest signal is not that Zero Trust matters, but that Zero Trust cannot be reduced to a branded VPN replacement. The control has to sit close to the resource, the credential, and the privileged action. Otherwise the organisation replaces one broad trust assumption with another one.
From our research library:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- 49% of IT professionals would prioritise improving privileged access management if the decision were theirs alone, according to Netwrix's 2023 Hybrid Security Trends Report.
- Read next: Just-in-Time Access and Zero Standing Privilege Guide
What this signals
Identity blast radius: When a VPN turns network reach into implied trust, the real governance issue is not remote access but how far a valid session can spread. That is why resource-scoped access and session logging matter more than perimeter control in hybrid estates.
The programme signal is straightforward: organisations should treat VPN replacement as an IAM and PAM redesign, not a tooling swap. If humans, vendors, and service accounts still share broad network admission, the access model remains too coarse for modern infrastructure.
For practitioners
- Define access at the resource, not the network Map databases, servers, clusters, and admin tools to explicit entitlements so a connected user cannot automatically see adjacent systems.
- Separate human, vendor, and service access paths Use different policy and provisioning logic for employees, contractors, third-party vendors, and service accounts instead of one shared network pathway.
- Require session-level audit trails for privileged actions Record commands, queries, and administrator actions so investigators can reconstruct what happened after a session ends.
- Limit default network reach for privileged workflows Replace broad VPN reach with narrow, task-scoped access to the specific systems a user or workflow needs for the job.
Key takeaways
- VPN-centric access control gives users broad internal reach, which is too coarse for modern hybrid environments with mixed privilege levels and mixed identity types.
- The article shows that auditability improves when sessions are tied to commands and resource actions, not just login timestamps.
- Practitioners should shift entitlement decisions to the resource layer and use the network only as transport, if they use it at all.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Broad VPN reach creates the same excessive-access problem for non-human and privileged workflows. |
| NHI-10 — Human Use of NHI | The article spans humans, vendors, and service accounts as one access-governance problem. | |
| Recommendation — Reduce broad tunnel-based reach and scope NHI access to the exact resource and action required. Separate human-mediated access from NHI-driven workflows and govern each with explicit lifecycle controls. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article argues for resource-level entitlements instead of broad network admission. |
| Recommendation — Apply PR.AA-05 to move access decisions from network membership to specific entitlements. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article stresses credential handling, onboarding, and offboarding around privileged access. |
| Recommendation — Use IA-5 to govern credential lifecycle and prevent broad VPN access from becoming standing trust. | ||
| MITRE ATT&CK | TA0008 — Lateral Movement | Broad VPN reach can enable movement from one system to another inside the private network. |
| Recommendation — Map network-broad access paths to TA0008 and prioritise controls that limit lateral movement after login. | ||
Key terms
- Network-Based Access Control: A control model that grants access primarily by whether a device or user is inside a trusted network boundary. In modern environments, this is too coarse because internal reach can span multiple systems, privilege levels, and identity types without expressing the actual entitlement needed.
- Least Privilege: A security principle requiring that every identity, human or non-human, is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.
- Interaction-Level Audit Trail: A record that captures the full AI session rather than only network traffic or file events. It ties the prompt, model response, identity, and policy response together so auditors can reconstruct what happened and why the control acted the way it did.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org