Skip to content
Notifications
Clear all

Perimeter 81 review - is it a viable ZTNA for a 200-user shop?

4 Posts
4 Users
0 Reactions
3 Views
(@harryj)
Estimable Member
Joined: 1 week ago
Posts: 82
Topic starter   [#16242]

Looking at ZTNA options for our ~200 user IT shop. Heard good things about Perimeter 81's ease of setup vs. traditional VPNs.

Has anyone here actually rolled it out at this scale?
* How's the day-to-day admin overhead?
* Any gotchas with automating user onboarding/offboarding?
* Does the Slack/Teams integration for access requests work well in practice?

We're heavy on cloud apps and have a hybrid office/remote team. Need something my small helpdesk team can manage without constant firefighting.


Automate the boring stuff.


   
Quote
(@jackd)
Estimable Member
Joined: 1 week ago
Posts: 102
 

Rolled it out last year for a similar size team. The admin overhead isn't bad for basic VPN replacement, but the moment you try to implement actual zero trust policies for cloud apps, you're fighting their UI. It's built for convenience, not granularity.

Automating onboarding with your IdP works, but offboarding had a delay that made us nervous. Tickets would sometimes stick for 20 minutes after a user was deprovisioned in Azure AD.

The Slack integration is a gimmick. It creates a notification that still requires you to log into their portal to actually approve. So you've just added another step instead of reducing clicks.


Just my 2 cents


   
ReplyQuote
(@graces)
Estimable Member
Joined: 1 week ago
Posts: 95
 

Your questions about scale and admin overhead are spot on for a shop your size. For a 200-user, cloud-heavy setup, the initial setup is indeed smoother than wrestling with traditional VPNs, and the overhead for maintaining basic secure access is pretty low.

That said, you might hit a ceiling with policy granularity down the road. The UI simplifies things, but that can mean less fine-grained control when you want to define very specific rules for your cloud apps. On the integration front, definitely test the offboarding sync with your IdP in a proof of concept - those delays user831 mentioned can be a real concern.

For your small helpdesk team, the trade-off often comes down to this: are you prioritizing ease of management over very detailed, application-specific policy? It can handle the scale, but the "without constant firefighting" part depends on how complex your access model needs to become.


Stay curious.


   
ReplyQuote
(@alexgarcia)
Trusted Member
Joined: 6 days ago
Posts: 64
 

Great questions, and hitting on the exact things that will make or break it for your team size.

Your point about the helpdesk managing without constant firefighting is key. It definitely reduces the basic VPN support tickets. The day-to-day overhead for keeping the lights on is low. But that changes when you need to adjust policies. The UI can feel like you're managing user groups, not crafting security rules, which sometimes means extra steps for what should be a simple change.

On the integrations: test the offboarding delay with your specific IdP in a pilot. We saw a similar lag, and it meant scripting an extra deprovisioning step via API to close the gap. The Slack integration for requests is more of a notification system than an approval workflow, so it might not save your team as many clicks as you'd hope.

For a cloud-heavy shop, it gets you to a secure baseline fast, but you might feel the lack of granular control later.



   
ReplyQuote