Subscribe to the Non-Human & AI Identity Journal
Home FAQ Cyber Security What breaks when VPNs are used as the…
Cyber Security

What breaks when VPNs are used as the main onboarding control?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 2, 2026 Domain: Cyber Security

VPNs can make remote access easy, but they often give users broader network reach than they actually need. In merger scenarios, that creates a trust gap because access is expanded before the organisation has full visibility into devices, entitlements, and application needs. The result is convenience without enough containment.

Why This Matters for Security Teams

When VPN access becomes the main onboarding control, it is easy to mistake connectivity for readiness. A tunnel proves a user can reach the network, not that the device is trusted, the identity is verified, or the user should see every internal segment. For merger activity, that gap is risky because inherited accounts, unmanaged endpoints, and unknown application dependencies often arrive faster than security can validate them. NIST guidance on access control and zero trust, including NIST SP 800-207, is clear that network location should not be treated as proof of trust.

The practical problem is that VPNs often flatten policy. Once connected, users may inherit broad reach that is hard to scope by role, device health, geography, or business purpose. That creates hidden exposure during the exact period when security teams need the tightest containment. The stronger the acquisition urgency, the more likely temporary access becomes the default, and temporary controls tend to linger. In practice, many security teams encounter lateral movement, data exposure, or privilege confusion only after the merger access path has already been opened, rather than through intentional design.

How It Works in Practice

VPN-centric onboarding usually follows a familiar pattern: the new user or acquired employee is given network credentials, then allowed to reach internal resources while the rest of the identity and endpoint work catches up. That can be useful for continuity, but it creates a large trust boundary too early. A better approach is to treat VPN as one transport option, not the control plane. Access decisions should be driven by identity assurance, device posture, and application-specific authorization, with temporary scope that is continuously reviewed.

Current guidance suggests pairing onboarding with stronger checks at the identity and device layers. For example, organisations can use just-in-time access for sensitive systems, segment merger populations by business function, and require conditional access before granting broader network routes. If the environment includes high-value systems or privileged workflows, consider separating ordinary user connectivity from administrative access and aligning privileged workflows with CISA Zero Trust Maturity Model principles rather than network membership alone.

  • Verify the person, the device, and the business need before expanding network reach.
  • Limit initial VPN access to the minimum subnets or apps required for day-one work.
  • Use short-lived access and review logs for unusual east-west movement.
  • Map onboarding exceptions to owners, expiry dates, and compensating controls.
  • Prefer application-layer access where possible so network connectivity does not imply trust.

Where identity governance is weak, device telemetry is incomplete, or merged environments still share flat network segments, these controls tend to break down because the VPN becomes the easiest path around incomplete application-level segmentation.

Common Variations and Edge Cases

Tighter onboarding controls often increase integration overhead, requiring organisations to balance speed against containment. That tradeoff is most visible in mergers where business pressure is high and IT inventories are incomplete. In those cases, security teams sometimes allow broader VPN access as a temporary bridge. Best practice is evolving, but the key is to make the bridge narrow, time-bound, and observable rather than treating it as the default operating model.

There are also edge cases where VPN remains useful. Contractors may need restricted internal access for a short period, and some legacy applications still depend on network presence. Even then, the access model should be explicit about scope and expiry. For regulated environments, identity proofing and entitlement decisions should remain separate from transport access, especially where personal data, financial workflows, or customer onboarding are involved. That is why frameworks such as the FATF Recommendations matter when onboarding intersects with assurance and account opening processes.

The main exception is a tightly governed, fully inventoried environment with strong segmentation, mature endpoint assurance, and rapid entitlement review. Outside that kind of maturity, VPN-led onboarding tends to widen the trust boundary faster than security can validate it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1VPN onboarding is an access-control decision that needs explicit authorization rules.
NIST Zero Trust (SP 800-207)SP 800-207Zero trust replaces network location with continuous verification and least privilege.
NIST SP 800-63ALIdentity assurance matters when onboarding users before full trust is established.
OWASP Non-Human Identity Top 10NHI-1Onboarding gaps often create unmanaged non-human access alongside human access expansion.
NIST AI RMFGOVIdentity and access decisions need governance when onboarding is used as a temporary bridge.

Treat VPN as transport only and enforce identity- and device-based policy before each access grant.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org