Home / Case Studies / Multi-Site Branch Operations SASE
Case Study · Multi-Site Branch Operations · SASE · Secure Access Modernisation

A multi-site branch operations group modernised secure access across sites, users and cloud applications

A multi-site branch operations group needed to modernise the way users accessed business applications, Microsoft 365, cloud services and internal systems across a distributed operating environment. The existing access model had grown around fixed sites, traditional network controls, remote access pathways and practical operational requirements. It had supported the business, but the environment had become more distributed, more cloud-dependent and more identity-driven.

Inlight IT helped design and deploy a SASE-aligned secure access model, improving policy consistency, remote access, traffic visibility, identity-aware access control and operational support across the organisation.

SITES + USERSSECURE ACCESSCLOUD APPS IDENTITY-AWARE SECURE FABRIC POLICY + IDENTITY POLICY-DRIVEN ACCESS RETAIL & BRANCH OPERATIONS / MULTI-SITE / SASE IDENTITY-LED / ONE SECURE FABRIC
Engagement at a glance

Multi-site branch operations — SASE deployment and secure access modernisation

Identity-aware secure access across branches, remote users and cloud applications for a distributed organisation.

Client
Multi-site branch operations group
Industry
Retail, distribution and branch operations
Environment
Multiple sites, distributed users, Microsoft 365, cloud applications, internal systems, identity, endpoint access and network security
Starting point
An access model grown around fixed sites, traditional network controls, remote access pathways and practical operational requirements
Engagement type
SASE deployment and secure access modernisation — identity-aware secure access across branches, remote users and cloud applications
Outcome
A more secure, scalable and supportable access model with identity-led policy and consistent controls across the environment
Key project stats

Secure access delivered as architecture, not platform

ID-led
access decisions

Access decisions follow identity, device context, application requirements and traffic behaviour, not just IP address or network segment.

Multi-site
one access model

Branches, offices, remote users and cloud applications supported through one consistent secure pathway.

Cloud
direct secure pathways

Microsoft 365 and cloud applications reached through direct, secure access pathways with appropriate inspection and policy.

Day 2
supportable operation

The deployment left an operating model support teams could monitor, operate and improve over time.

Operating context

SASE is not a product category to be switched on — it is secure access architecture designed around the way the organisation works

The organisation operated across multiple locations with users relying on a mix of site-based systems, cloud applications, Microsoft 365, remote access and internal resources. Like many distributed branch operations businesses, the network and security environment had evolved over time — branch connectivity, firewall rules, VPN access, cloud adoption, identity controls, application access and user support had all developed around real business needs.

That model had worked, but it was becoming harder to scale and manage. Users needed reliable access from different locations. Security policies needed to be more consistent. Remote access needed to be easier to control. Network visibility needed to improve. Microsoft 365 and cloud applications needed a secure access model that did not rely only on traditional perimeter controls.

The objective was to move toward a more modern access architecture: identity-aware, policy-driven, cloud-ready and easier to operate across a multi-site environment.

Why this work mattered

The organisation needed to modernise secure access without creating disruption across sites, users and operational workflows

This was not simply a firewall replacement or a new remote access tool. SASE affects how users connect, how traffic is inspected, how cloud applications are accessed, how policies are applied and how support teams troubleshoot access issues. For a multi-site organisation, access problems quickly become operational problems.

01

Secure access needed to work across all user locations

Users worked from offices, branches, remote locations and mobile contexts. The access model needed to support all of them through a more consistent secure pathway, not a patchwork of VPN, site-bound controls and cloud-specific exceptions.

02

Security policy needed consistency across the environment

Different sites had developed different access patterns over time. Policy drift creates risk. The deployment needed a model where security controls could be applied consistently across users, locations, cloud applications and traffic types.

03

Identity needed to drive access decisions

A traditional perimeter model assumes users and applications sit behind predictable locations. That assumption no longer reflects how the organisation operated. Access decisions needed to follow identity, device context, application requirements and traffic behaviour, not just IP address or network segment.

04

Microsoft 365 and cloud applications needed secure access pathways

Cloud-bound traffic patterns are not well served by routing everything back through a central firewall. Microsoft 365, SaaS applications and cloud services needed direct, secure access pathways with appropriate inspection and policy.

05

The model had to remain supportable after deployment

If users cannot reach applications, branches lose productivity. If remote access is difficult to manage, support overhead grows. If visibility is poor, troubleshooting and incident response become harder. The deployment needed to leave an environment support teams could operate.

What Inlight IT delivered

Five operational layers connecting SASE architecture, identity, connectivity, security policy and operational handover

Inlight IT helped the organisation design and deploy a SASE-aligned secure access model across the operating environment. The work connected network architecture, identity, cloud access, branch connectivity, endpoint access, security policy and managed support into a more scalable model.

01

SASE architecture and deployment planning

The work began by mapping how the organisation actually operated, not by selecting a platform. Existing network, access pathways, users, sites, applications and security dependencies were mapped so the deployment reflected the real operating environment, not a generic reference architecture.

Included
Site connectivity and access pattern reviewBranch, remote user and cloud usage mappingIdentity, user group and authentication reviewFirewall, VPN and security control assessmentApplication dependency and transition sequencing
02

Identity-aware secure access

SASE is strongest when access policy is connected to identity. Inlight IT helped align secure access controls with user identity, role, location, device posture and application requirements for a more granular access model than traditional network-based controls.

Included
User and group access requirementsIdentity-aware policy designAuthentication and conditional access alignmentApplication and resource-level access controlsPrivileged and over-broad access reduction
03

Branch, remote user and cloud connectivity

Inlight IT supported the deployment of connectivity pathways that improved access to Microsoft 365, cloud applications and internal systems while maintaining security controls, moving the organisation away from a purely site-bound access model.

Included
Branch connectivity requirementsRemote user access designMicrosoft 365 and SaaS access pathwaysInternal application access and traffic routingPolicy consistency across locations
04

Security policy and traffic control

A SASE deployment needs clear security policy design — otherwise it becomes another access layer without consistent control. Inlight IT helped structure security policy across users, locations, applications and traffic types.

Included
Web and cloud access controlsApplication access policyTraffic inspection requirementsSite and user segmentationLogging, visibility and operational escalation
05

Operational handover and managed support

Inlight IT helped transition the SASE environment into an operating model that could be monitored, supported and improved over time, with deployment validation and policy refinement built into the handover.

Included
Deployment validationUser and site support during transitionIssue handling and remediationPolicy refinement after rolloutDocumentation and managed services alignment
Delivery approach

From access-pattern mapping to a deployment that landed in a supportable operating model

Select a stage to trace how the deployment moved from access mapping to managed operation.

Market context

A perimeter model assumes users and applications sit behind predictable locations — that no longer reflects how many organisations operate

Users work from multiple places. Applications sit in Microsoft 365, cloud platforms and internal environments. Security controls need to follow identity, device context, application access and traffic behaviour. For a multi-site branch operations group, inconsistency compounds quickly: different sites develop different access patterns, remote access becomes harder to manage, policies drift, troubleshooting becomes slower and support teams lose visibility.

5

Five operational layers connected SASE architecture, identity, connectivity, security policy and operational handover.

1

One consistent secure access model replaced a patchwork of VPN, site-bound controls and cloud-specific exceptions.

Drift

Different sites develop different access patterns over time — policy drift creates risk, and inconsistency compounds quickly across a multi-site environment.

Both

Each visibility or policy gap creates either a security risk or an operational drag — and often both.

Multi-site branch operations engagementInlight IT delivery record
What changed for the client

The organisation gained a more modern secure access architecture across users, sites, cloud applications and internal systems

The deployment improved access control, policy consistency, visibility, remote access support and operational manageability across the environment.

O·01

More consistent secure access across locations

Users across branches, offices and remote locations could be supported through a more standardised secure access model, reducing site-by-site exception handling.

O·02

Improved identity-aware access control

Access policies could be better aligned to user identity, role, application requirements and business context, rather than to network location alone.

O·03

Reduced reliance on legacy access patterns

The organisation moved toward a more flexible model for remote access, cloud access and internal application connectivity, reducing dependency on site-bound VPN patterns.

O·04

Stronger security policy consistency

Security controls could be applied more consistently across users, locations, cloud applications and traffic types, reducing policy drift across sites.

O·05

Better visibility and supportability

The operating model improved visibility into access behaviour, policy handling and troubleshooting pathways for support teams.

O·06

A more scalable network security model

The environment became better positioned to support distributed users, cloud applications and future operating changes without rebuilding the access architecture.

Net position

The value was not simply replacing legacy remote access or modernising connectivity. The value was creating a more consistent secure access model across the business.

Project outcomes

SASE delivered as access architecture, not as a platform installation

Outcome 01

SASE as architecture, not platform

Identity, branch, remote and cloud access unified into one operating model.

Outcome 02

Multi-site environment supported

Branches, offices, remote users and cloud applications consistent under one access model.

Outcome 03

Identity-aware policy design

Access decisions follow user, role, device and application context.

Outcome 04

Cloud-ready Microsoft 365 access

Direct secure pathways with appropriate inspection and policy.

Outcome 05

Visibility across access and policy

User, application and traffic behaviour brought into operational view.

Outcome 06

Operational handover complete

Environment connected to ongoing managed services and improvement.

Technology and service scope

The work connected secure access architecture, identity-led policy and managed operation

Secure access architecture

6
  • SASE deployment
  • Secure access architecture
  • Zero Trust network access
  • Deployment planning and validation
  • Application dependency and transition sequencing
  • Policy refinement after rollout

Identity and policy

6
  • Identity-aware access control
  • Authentication and conditional access alignment
  • Application-level access controls
  • Privileged and over-broad access reduction
  • User and group access requirements
  • Site and user segmentation

Connectivity

6
  • Branch and remote connectivity
  • Cloud and SaaS access
  • Microsoft 365 access security
  • Network and SD-WAN
  • Internal application access and traffic routing
  • Firewall and traffic policy

Operations and support

6
  • Managed services alignment
  • Logging and visibility
  • Operational escalation
  • User and site support during transition
  • Issue handling and remediation
  • Documentation and handover
Practical next step

Need secure access that works across users, sites and cloud applications?

We review your access model and where SASE fits before you commit to a platform.

Discuss SASE & Zero Trust