We are planning a remote-access migration for roughly 500 employees and contractors. The environment includes SaaS, internal web apps, Windows and Linux admin access, a few legacy applications, and workloads split between on-prem infrastructure and public cloud. Identity is centralized, but endpoint management and device posture are inconsistent for contractors.
We do not want a big-bang cutover. The initial thought is to inventory applications and users, classify access by protocol and sensitivity, migrate a low-risk web app first, and then move groups in waves. The hard part is avoiding years of permanent exceptions and overlapping access paths.
For anyone who has done this at similar scale, what did you get wrong in the first phase? Did app discovery, identity-group cleanup, private DNS, endpoint support, legacy protocol support, or user communications create the most work?
How did you handle emergency administration and outage scenarios when the normal access path was unavailable?
Source: r/sysadmin · by /u/Puzleheadoed-Ice3232