Remote working setup for sales teams — cloud apps, Entra ID and Zero Trust
Use cloud-hosted CRM and Microsoft Entra ID with conditional access and per-app controls to support hybrid sales teams in 2026; combine that with a reliable VoIP provider and local internet failover to keep calls running. Focus on three priorities: access, security and uptime.
How quickly can your reps access customer data?
Speed of access is the first decision criterion because sales people need instant, reliable access to CRM records, quotes and call tools. Prioritise cloud-native CRMs (Salesforce, Microsoft Dynamics 365, HubSpot) or web-fronted legacy apps that can be wrapped with modern authentication — these remove the need for slow, brittle VPN tunnels and reduce login friction. Fast access means single sign-on with session persistence and mobile-friendly UIs so reps don’t lose selling time when they switch device or network.
Operational checks to use when comparing options:
- Can the CRM be reached directly from a mobile network without VPN?
- Does single sign-on (SSO) support MFA and conditional access?
- Is session performance acceptable over 4G and home broadband?
Measure candidate setups by running five representative tasks (open a lead, update opportunity, start a call) from several UK ISPs during a week. If any workflow adds more than 5–10 seconds per action on average, users will notice and resist the change.
How secure is remote access and audit-ready?
Security and compliance are the second criterion because sales teams handle personal data and commercial intelligence. Rather than a blanket network tunnel, use per-app conditional access so you only allow authenticated sessions to specific cloud apps and block everything else. In our experience, VPN-only remote access is now an outlier, not the default — Zero Trust patterns (Entra ID conditional access + per-app access) have replaced the blanket VPN for most of the businesses we have migrated. VPN survives specifically for legacy line-of-business apps that pre-date web-based authentication.
This approach reduces lateral movement risk and gives cleaner audit trails. For UK-focused guidance on secure remote access and identity, see the NCSC’s guidance on secure remote working. Practical checks:
- Is MFA enforced via Entra or equivalent?
- Are access policies scoped by app and device posture?
- Can you get a session log that shows user, app and IP for 90 days?
How does the setup affect productivity and call reliability?
Third, measure the impact on sales activity: call success rate, CRM update speed and tools availability during visits. VoIP and conferencing are essential — if your chosen setup routes voice over a corporate VPN hosted in a single data‑centre, expect higher latency and dropouts for reps on mobile networks. Instead, prefer VoIP that uses local Internet breakout so calls follow the shortest path to a UK PSTN gateway.
Include these checks when evaluating providers:
- Do call tests from home Wi‑Fi and 4G show acceptable MOS or call quality?
- Is there a simple offline workflow (cached notes, SMS fallback) when connectivity drops?
- How are call recordings and consent handled under the ICO rules?
Make sure the mobile experience is identical to desktop for the core tasks — fewer toggles, fewer separate credentials. Small process changes that shave 10–20 seconds per task add up across a team of 20 reps.
How quickly can you deploy and support it?
Finally, pick solutions you can roll out without months of custom engineering. Sales teams need minimal training and straightforward recovery options when a rep joins, leaves or loses a device. Look for identity-first deployments where adding a user is an admin action in Entra and provisioned to apps automatically.
Assess supplier support by timing three routine tasks: add a new user, revoke an account, and reconfigure MFA for a lost phone. If any takes more than an hour of admin work or requires multiple vendor tickets, your internal overhead will grow quickly. For rollout planning, allow a two- to four-week phased migration per 20–50 users so you can pilot, fix edge cases and document the sales-specific workflows.
When comparing commercial offerings, score each option against the four criteria above, weight access and uptime higher for teams that are customer-facing, and choose the one with clear admin workflows and auditing.
To see a shortlist of supported configurations and migration options, check our remote working options and pick two candidates to pilot. A small pilot that validates SSO, call quality and one audited app will save time and money versus a full-bore replacement.
Related reading
- our remote working guide
- Remote workforce IT support: practical guide for UK businesses
- Remote working setup for finance teams — Zero Trust, per-app access and clear audit trails
- How to fix remote working IT issues: practical steps for UK businesses
- Remote working IT support pricing: what UK businesses should actually expect
FAQ
Can sales reps work without VPN and stay secure?
Yes — using per-app access with Microsoft Entra ID conditional access and strong MFA keeps sessions secure while removing VPN overhead; VPN is only usually kept for legacy apps.
How long does a typical migration take for a small sales team?
Expect a phased migration in roughly 2–4 weeks per 20–50 users to pilot, fix issues and roll out without disrupting selling activity.
What should I test before switching everyone over?
Run tests for CRM access, VoIP call quality on home broadband and 4G, single sign-on and an admin-led account recovery; these cover the top three failure modes.
Will switching to per-app access help with audits and data requests?
Yes — per-app policies create clearer logs and shorter retention windows, which makes it easier to produce access records during an ICO or internal audit.







