Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations replace VPNs and bastions with identity-based…
Governance, Ownership & Risk

Should organisations replace VPNs and bastions with identity-based access controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Yes, when the goal is stronger governance over infrastructure access. VPNs and bastions can reduce exposure, but they do not solve credential reuse, lateral movement, or poor visibility. Identity-based access controls are the better fit when organisations need per-session enforcement and auditable protocol-level access.

Why identity-based controls are a better replacement than perimeter entry points

VPNs and bastions were designed to create a narrower path into infrastructure, but they still tend to act as coarse access brokers. Identity-based access controls shift the decision point from network location to verified identity, policy, and session context. That matters when the real problem is not reachability, but who can do what, from where, and under which conditions.

That difference changes how organisations govern privileged access. Instead of granting broad network presence and assuming the bastion or VPN will contain the blast radius, identity-based models can enforce per-user, per-device, per-session, and sometimes per-action decisions. Remote Access Identity Guide is useful here because it frames VPN replacement as a broader remote-access governance decision, not just a connectivity swap.

It also aligns better with modern infrastructure patterns. Infrastructure access is increasingly distributed across cloud consoles, admin APIs, remote shells, and third-party support paths, so a single network choke point often misses the actual trust decision. Zero Trust Identity Guide helps explain why identity-centric policy and continuous verification fit this shift better than a static entry layer.

What organisations still need to solve after removing VPN and bastion dependency

Replacing VPNs and bastions does not remove the need for strong authentication, device trust, session control, or entitlement governance. If those controls are weak, the new access layer simply inherits the same weakness with a different front door. The practical improvement comes from combining identity proof, least privilege, and session-level enforcement.

That is why access governance remains central even when network access is no longer the main control. Organisations still need to know which identities exist, what they are entitled to, and whether those entitlements are still justified. IAM and IGA Basics is a strong companion for the governance side of this decision because it covers authentication versus authorization, access reviews, and entitlement management across people and machines.

For infrastructure administration specifically, identity-based access works best when it is paired with just-in-time privilege, short session windows, and auditability. That avoids turning “no VPN” into “always-on admin access.” Privileged Access Management Guide supports the operational side of this shift by focusing on vaulting, just-in-time access, zero standing privilege, and session recording.

When replacement improves security, and when it only changes the shape of the problem

Identity-based controls are most valuable when the organisation needs granular access decisions, stronger accountability, and reduced lateral movement. They are especially effective where bastions have become shared jump hosts, where VPNs expose large internal network ranges, or where remote access has accumulated exceptions over time. In those cases, the old model tends to preserve broad trust even when the business only needs narrow administrative action.

The same logic applies to modern attack paths. Valid credentials, credential replay, and overprivileged access can defeat perimeter-style controls quickly once an attacker is inside. Identity-centric access does not eliminate compromise, but it can reduce how far a stolen session or reused secret can travel. Identity Threat Detection and Response (ITDR) Guide is relevant because it ties access design to the attack techniques and detections that matter after initial compromise.

For infrastructure teams, the real question is not whether VPNs and bastions are obsolete, but whether they are still the best control for the use case. If the access pattern is high-trust, persistent, and poorly attributed, identity-based access is usually the better governance model. If the environment still relies on broad administrative movement without strong policy enforcement, the replacement will be cosmetic rather than protective.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST Zero Trust (SP 800-207)N/A — Zero Trust ArchitectureIdentity-based access replaces broad network trust with verified, session-level access decisions.
Recommendation — Use identity-centric policy and continuous verification instead of perimeter trust for infrastructure access.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementVPN replacement still depends on secure credential lifecycle and authenticator control.
IA-2 — Identification and Authentication (Organizational Users)Interactive infrastructure access still requires strong user authentication before authorization decisions.
AC-6 — Least PrivilegeReplacing VPNs and bastions is justified when access can be reduced to minimum necessary privilege.
Recommendation — Manage authenticators tightly and rotate or revoke them when remote access paths change. Require strong user authentication before granting infrastructure access. Enforce least privilege so admitted users can only perform approved infrastructure actions.
ISO/IEC 27001:2022A.5.15 — Access controlIdentity-based access is an access-control design choice for governing infrastructure entry and use.
Recommendation — Apply documented access-control rules to infrastructure access paths.

Practitioner Guidance

What to prioritise: Treat this as an access-governance redesign, not a tooling migration. The first decision is which infrastructure actions truly require human interactive access, and which can be shifted to policy-controlled, time-bound, and fully logged access paths.

What to verify: Before retiring VPN or bastion dependency, verify that the replacement can enforce strong authentication, conditional access, per-session approval or scoping, and complete audit trails for every privileged path. If the replacement cannot explain who accessed what and why, it is not an equivalent control.

Common mistake: Replacing a perimeter mechanism with another broad gateway and calling it identity-based. If users still receive wide internal reach once admitted, the organisation has changed the entry mechanism but not the trust model.

Practitioner takeaway: The strongest replacements are narrow, attributable, and reversible, they reduce standing reach rather than just hiding it behind a different login screen.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org