Google rolls out BeyondCorp Remote Access, a cloud-based tool that lets employees securely access their company's internal web apps without using a VPN
Google is rolling out the product now as organizations figure out how to accommodate remote workforces through the Covid-19 pandemic.
Context & Ripple Effects
BeyondCorp Remote Access is the productization of a decade-long internal project: back in 2015 Google moved its own internal apps onto the public Internet and rebuilt security around device-level rather than network-level trust, as covered in its enterprise security architecture overhaul. The commercial plumbing followed in 2018, when Google began offering the cloud identity technology behind G Suite as a standalone service to developers.
The timing is the story: with Covid-19 forcing entire workforces off corporate networks at once, the VPN — designed for a minority of dial-in users — is the bottleneck, and Google is shipping this now to meet that demand.
First-order effects
- Enterprises scrambling to support remote staff gain a cloud-hosted way to reach internal web apps without VPN capacity or client software, with Google Cloud positioned as the vendor of record for that access layer.
- The rollout gives Google a concrete enterprise-security wedge built on assets it already runs internally, rather than a net-new product line.
Second-order effects
- VPN vendors face their core use case being reframed as legacy: if access is granted per-app based on device and identity, the network tunnel stops being the security boundary customers pay for.
- Identity infrastructure becomes the competitive battleground — the same cloud identity stack Google exposed to developers in 2018 is now the enforcement point, pulling rivals toward equivalent identity-first offerings.
Third-order effects
- If adoption holds, the pattern points to zero-trust becoming the default enterprise architecture rather than a Google internal curiosity — a trajectory the corpus already shows continuing, with Workspace gaining zero-trust and data-loss-prevention controls by 2023.
- Security procurement shifts from buying network appliances to subscribing to access-as-a-service, concentrating power with hyperscalers who already operate the identity and device-management layers.
The trend: Enterprise access control is migrating from VPN-perimeter trust to identity- and device-based zero-trust delivered as cloud services, with the pandemic acting as the forcing function.