Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / How Windows 11 Is Making Enterprise VPNs Obsolete
Transcript
- Lucas: You know, I've been looking at Microsoft's Ignite announcements from last fall, and one thing that's quietly happening is that Windows 11 is essentially making the traditional corporate VPN obsolete. Luna: Obsolete? That's a strong word. I mean, VPNs have been the backbone of remote access for like twenty years. Lucas: They have been. But Microsoft is building the replacement directly into Windows 11 — it's called Windows 365 Secure Access, combined with Always On VPN. And the data from early enterprise deployments is pretty striking. Luna: What kind of data are we talking about? Lucas: Microsoft shared a case study with a mid-size financial services firm — about 5,000 employees. They migrated from a legacy Cisco AnyConnect VPN to Windows 11's native Always On VPN with Entra ID integration. They reduced their VPN infrastructure costs by 40 percent and cut helpdesk tickets related to VPN connectivity by over 60 percent. Luna: Sixty percent fewer tickets? That's huge. Most IT teams I talk to say VPN issues are their number one support headache. Lucas: Exactly. And the reason is that the traditional VPN model is fundamentally flawed for modern work. You're routing all traffic through a corporate data center, even if someone is just checking their personal email. It's inefficient and it creates a bottleneck. Luna: So what does the Windows 11 approach do differently? Lucas: It's based on zero-trust network access, or ZTNA. Instead of granting access to the entire corporate network, Windows 11's Secure Access feature authenticates per app or per resource. The device never actually connects to the corporate LAN — it just gets a secure tunnel to the specific application it needs. Luna: Right, so it's essentially a per-app VPN, but built into the OS and managed through Intune. Lucas: Exactly. And it integrates with Microsoft's Secure Service Edge, or SSE, which is part of their SASE framework. So you get web filtering, data loss prevention, and cloud access security broker capabilities all in the same tunnel. Luna: I can see why Microsoft is pushing this. It locks enterprises into their ecosystem even more. Lucas: That's the cynical take, and there's truth to it. But practically, it also solves real problems. One of the biggest is split tunneling — or rather, the lack of it. With traditional VPNs, IT often forces all traffic through the corporate network for security, which kills performance for cloud apps like Microsoft 365. Luna: Yeah, I've heard users complain that Teams calls get choppy when they're on VPN. Lucas: Exactly. With Windows 11's Always On VPN, you can configure split tunneling intelligently. Traffic to Microsoft 365 goes directly to the internet, while traffic to internal apps goes through the VPN. And it's policy-based, so it's managed centrally. Luna: What about security? If you're sending some traffic direct, isn't that a risk? Lucas: That's where the SSE layer comes in. Even direct traffic can be filtered through Microsoft's cloud security stack. So you're not losing visibility, you're just not routing it through your own data center. It's actually more secure in many ways because you're reducing the attack surface of your on-premises network. Luna: So what does this mean for IT departments right now? Should they start planning to rip out their VPN concentrators? Lucas: I think the smart move is to start with a pilot. Pick a group of users who are already on Windows 11 Enterprise, configure Always On VPN through Intune, and see how it goes. Microsoft provides a migration guide that walks you through co-existence with your existing VPN. Luna: And if today's conversation gave you something usable for your own IT planning — something that might save you a few headaches — that's exactly the kind of practical takeaway we aim for on this show. And honestly, listener support is what keeps this thing ad-free and focused on what actually matters for people managing Windows environments. If you find value in these deep dives, you can toss a few bucks our way at buy me a coffee dot com slash fexingo. No pressure at all — just helps us keep the lights on. Lucas: Yeah, it's a small thing that makes a big difference. And speaking of practical — one gotcha I want to flag: licensing. Windows 11's Always On VPN is available in Windows 11 Pro and Enterprise, but the Secure Access feature requires a separate subscription, Microsoft Entra Internet Access. It's part of the Entra suite. Luna: So there's a per-user cost. That could be a dealbreaker for some orgs. Lucas: It depends. If you're already on Microsoft 365 E5, you might already have some of those entitlements. But for smaller businesses on Business Premium, it's an add-on. You need to do the math. Luna: What about third-party VPN vendors? Are they adapting? Lucas: They are. Cisco, Palo Alto, and others are all pushing their own ZTNA solutions. But the difference is that Microsoft's is baked into the OS and managed through Intune. You don't need to deploy a separate client. That's a huge operational savings. Luna: I can see why the financial services firm in that case study saw such a drop in tickets. No client to install, no manual configuration, no split tunneling debates. Lucas: Right. And it's not just about cost. It's about user experience. When a user logs into a new Windows 11 device, the VPN configuration is already there via Autopilot. They don't have to call IT to get set up. Luna: That's a game changer for onboarding. How does the migration actually work? Do you have to cut over all at once? Lucas: No, and that's the beauty of it. You can run both in parallel. You set up Always On VPN with a condition that it only applies to certain users or devices. Then you slowly migrate groups. The legacy VPN client can remain for fallback. Luna: So there's no big bang migration. That's reassuring. Lucas: Exactly. And Microsoft has a tool called the VPN Migration Toolkit that helps you convert your existing VPN profiles into Intune policies. It's not perfect, but it handles the basics. Luna: What about devices that aren't Windows 11? Macs, Linux, mobile? Lucas: That's the limitation. This is a Windows-first play. For non-Windows devices, you'd still need a third-party ZTNA solution. But Microsoft's pitch is that if you're a Windows shop, you can simplify your stack significantly. Luna: So the takeaway for IT leaders: start evaluating Windows 11's built-in VPN capabilities now, even if you're not ready to fully cut over. Lucas: Absolutely. And pay attention to the licensing. Talk to your Microsoft rep about Entra Internet Access pricing. The technology is solid, but the cost model might surprise you. Luna: I think the bigger question is: in three years, will anyone still be running a traditional VPN concentrator? Or will it all be cloud-delivered ZTNA? Lucas: I think the hardware will be gone. The software-defined perimeter is already here. Windows 11 is just the delivery mechanism for most enterprises. Luna: It's one of those quiet revolutions. No big announcement, just a gradual shift in how we think about network access. Lucas: And that's often how Microsoft works. They build the replacement into the platform, and one day you realize you haven't touched your VPN appliance in months.