# Verified Access ZTNA Migration Checklist (July 2026)

TCP / non-HTTP access is **GA** (client required). HTTP apps: browser-only.

## Prereqs

- [ ] IAM Identity Center (or OIDC) trust provider
- [ ] Device trust providers if posture required (Jamf / CrowdStrike / …)

## Waves

1. Inventory Client VPN apps → HTTPS vs TCP vs thick-client
2. Pilot 3–5 low-risk HTTPS apps + MFA group policy
3. Tighten Cedar (device, geo, path); attach WAF to endpoints
4. Developer tools → back-office
5. TCP endpoints (SSH/RDP/RDS) + Verified Access client where needed
6. Decommission broad Client VPN when ~90% moved

## Counter-case

Permissive Cedar forever + no WAF on public endpoints is worse than VPN ACLs.
