VPN vs ZTNA: choosing the right remote access model
Device security for remote workers
Home network risks and mitigations
Key Takeaways
TL;DR
ZTNA is more secure than traditional VPN — it grants application-level access, not network-level access.
Enroll all remote devices in MDM and enforce compliance policies: encryption, patching, and EDR.
Use conditional access to block non-compliant devices from accessing corporate resources.
Home networks are untrusted — mitigate with always-on ZTNA, DNS filtering, and device compliance.
Provide remote workers with a home network security checklist: router password, firmware updates, WPA3, and network segmentation.
FAQ
Frequently asked questions
Should we use VPN or ZTNA for remote workers?
ZTNA is recommended over traditional VPN for new deployments. ZTNA provides application-level access (not broad network access), verifies device health before granting access, and eliminates the risk of lateral movement. For SMBs, Cloudflare Access (free for up to 50 users), Tailscale, or Microsoft Entra Private Access are practical options. If you have an existing VPN, plan a gradual migration to ZTNA.
How do we secure BYOD (bring your own device) for remote workers?
For BYOD, enroll personal devices in MDM with a work profile (separate container for corporate data). Use Microsoft Intune MAM (Mobile Application Management) policies that protect corporate data within managed apps without controlling the entire personal device. Require MFA, device encryption, and minimum OS version. Use conditional access to limit BYOD access to less sensitive resources.
Are home networks a security risk for remote workers?
Yes. Home networks typically have default router credentials, outdated firmware, no segmentation, and shared access with personal and IoT devices. Mitigate these risks with always-on ZTNA (so work traffic never traverses the local network unprotected), DNS filtering on work devices, device compliance enforcement, and employee guidance on home network hardening.
Get your Cyber Defense Score™ in 60 seconds.
100 tools. No installation. No credit card. Real evidence.