Solution design

VPN replacement with Cloudflare Access and Tunnel

Replace broad network access with per-application identity, device posture, and outbound-only private connectivity.

Use When

Use this pattern when users need access to private web apps, SSH/RDP, developer tools, dashboards, or internal portals without exposing origins or maintaining broad VPN routes.

Core Design

IdentityConnect corporate IdP, verify group claims, and enable SCIM for lifecycle control.
ConnectorPlace Cloudflare Tunnel near the private application and avoid inbound firewall exposure.
PolicyUse default-deny, reusable Access Groups, short sessions for sensitive apps, and posture where managed devices are required.
ValidationConfirm allowed users succeed, blocked users fail, logs show identity and posture context, and origin is not directly reachable.

Rollout Notes

Start with one low-risk app, migrate pilot users, compare helpdesk impact against VPN, then move app-by-app. Keep VPN available until critical workflows, logging, and rollback are proven.