ZTNA is more secure than a traditional VPN, but it is not without trade-offs. The most common downsides are performance, compatibility with legacy applications, the effort of designing access policies, and the cost and complexity of multi-product platforms. Most of these depend on the product you choose rather than on ZTNA itself.
1. Performance can suffer
Most ZTNA services route traffic through the vendor’s cloud. If the nearest point of presence is far away, or the service does not cope well with packet loss, users on home Wi-Fi, hotel networks and mobile connections notice slow file transfers, choppy calls and dropped sessions. Users usually blame IT, and support tickets go up.
2. Legacy applications can be hard to support
Many ZTNA products were designed for web applications. Thick-client applications, voice, server-initiated connections and some industrial protocols may not work, which leads organizations to keep a VPN running alongside ZTNA.
3. Policy design takes work
Least-privilege access means deciding who should reach which application, under what conditions. Mapping that for hundreds of applications takes time, and overly strict policies can block legitimate work.
4. Licensing and vendor sprawl
Some vendors sell ZTNA, internet security and monitoring as separate products. Costs add up, and each product brings its own console and policies.
5. Rollout effort
Agents need to be deployed to devices, connectors installed near applications, and identity and endpoint tools integrated. Platforms that need hardware or complex network changes take longer to roll out.
How to reduce these downsides
- Test performance with real users on poor networks before you commit.
- Choose a platform that supports both application and network-level access so legacy apps are covered.
- Start with broad groups and tighten policies over time using access data.
- Prefer single-license, software-only platforms that integrate with your existing identity and endpoint tools.
How Cloudbrink addresses them
Cloudbrink was designed around these problems. Its FAST Edges are never more than 20ms from users, with a median under 5.2ms, and the Brink Protocol adapts in real time to deliver LAN-like performance even at 20% packet loss. It provides full IP fidelity, including server-initiated connections, so legacy applications are covered. It integrates with Microsoft Entra and CrowdStrike, and is delivered as 100% software under a single license. A national insurance company deployed it to 850 users in a week. Learn more about High-Performance ZTNA.