The VPN project that ends: roll out in an afternoon, onboard people automatically, stop answering "is the VPN up?"
Connect your IdP, push the client through MDM, approve the first devices — that's the whole project plan for week one. The old VPN runs in parallel while teams migrate at their own pace; nobody's Thursday depends on a flag-day cutover.
The departing contractor's account dies in the IdP, SCIM carries it to the network, and every session on every device ends within seconds. No certificate revocation lists, no shared-credential rotation, no "did we get all the keys?" audit.
Point OpenVLAN at Okta, Entra ID, or Google Workspace. Users and groups sync; MFA piggybacks on login.
Standard installers for macOS and Windows deploy like any other managed app. Linux servers take one shell command.
Device approval is one click. Start from deny-all and grant by IdP group — least privilege by default.
Run in parallel for a week, migrate wave by wave, then decommission the concentrator and reclaim its IP block.
NAT traversal handles hostile networks; relay fallback covers the rest. Connectivity complaints drop off.
Access requests flow through the IdP groups you already manage — no per-app VPN group juggling.
MDM installs the client; SSO does the rest. First-day network access without IT touching anything.
ACLs answer that in one place, mapped to groups that HR already owns.
SCIM disables their account; sessions die in seconds, not at the next certificate expiry.
There is no appliance. The pager gets quieter.