Solution
Replace Always On VPN And DirectAccess For On-Prem AD
Move off Always On VPN, DirectAccess leftovers, and site-to-site tunnels without moving your directory to Entra. One encrypted outbound-only fabric for user-to-service and site-to-site access under a single policy model.
Why this matters
DirectAccess is gone, Always On VPN is a certificate estate with a gateway attached, and every branch tunnel is a device somebody has to keep alive. The directory does not have to move to fix any of that.
- One fabric covers both motions: user-to-service access for remote staff and site-to-site connectivity between branches, governed by a single policy model instead of two stacks.
- No concentrator to size for peak concurrency, licence per tunnel, or refresh when it reaches end of support.
- Direct peer-to-peer paths with NAT traversal, so branch traffic does not hairpin through a head-office gateway that becomes the bottleneck and the outage.
- Access follows verified device and user identity rather than whichever subnet the tunnel dropped someone into.
- Migration runs per site. Prove one branch, then move the next, with the VPN still in place underneath until you choose to decommission it.
Outcomes
One appliance and one support contract off the bill
No certificate estate to renew purely to keep access working
Branch onboarding without shipping and staging hardware
Narrower access than a tunnel that lands users on a whole subnet
A staged migration you can stop at any point
Related ControlIT pages
AD readiness reviewControlIT vs VPNRDP without port forwardingControlIT overviewArchitectureProduct BrochureTalk to Computer Port
Published by Computer Port IT Solutions. This page is part of the ControlIT product knowledge base for search engines, AI crawlers, and IT teams evaluating secure endpoint operations.