M
Mid-Market (51-1000 emp.)
"Twingate is great software but falls short on enterprise management and deployment."
Twingate is an excellent 'VPN' alternative with a user-friendly interface, easy setup for end users, and top-notch security for split/full tunnel access. I hate to complain, but I'm writing this in hopes that Twingate addresses some issues I have. Deploying and configuring Twingate across most MDMs like NinjaRMM, Intune, and Jamf Pro is incredibly frustrating. This isn't limited to one OS; it's the same on macOS and Windows. If you install it without any configuration, it works fine. But when you try to deploy with settings like root cert for NextDNS, machine key, silent install, or macOS launch agents, it really struggles. macOS is where the product needs the most attention. It constantly has update issues, dual instances, and orphaned system extensions. The Twingate team knows the product falls short in enterprise deployment and management. Most issues stem from the documentation; I had to extract proper Jamf deployment documentation from one of their macOS leads. They need to invest heavily in updating deployment docs for all supported MDMs and operating systems. Their recommended deployment strategies feel piecemeal and incomplete, like a half-finished puzzle you're left to solve. The Windows deployment solution is one massive PowerShell script, which I wouldn't mind if it worked and was easy to modify. I'll give them credit for a solid Windows uninstall script that's helpful for troubleshooting. On macOS, Twingate really lacks—there's no easy-to-use uninstall script, and it leaves orphaned system extensions without a restart, which Windows doesn't have. From a product standpoint, if you're considering Twingate for home or small business use, it's great. For large-scale deployment and management, it falls short. DNS management and NextDNS integration have a lot of catching up to do; the admin GUI is confusing and lacks options. It seems like many features you'd expect from a DNS filtering dashboard are missing. I could go on, but I've ranted enough. I'd avoid Twingate until it matures for larger enterprises. They need to invest in the admin dashboard, DNS integrations, and work with more MDMs to understand how admins and users use the product. Twingate didn't really 'solve' anything for us; it just made it easier for end users to switch to a more modern VPN solution than our legacy WatchGuard one. I think the security team likes that resources are easily manageable based on permissions and groups.
D
Director of Infrastructure
"Effortless Group Management and Simple Implementation"
Our team really likes being able to create groups and manage team resources through them. We also find implementation very easy. Managing temporary access for external users can sometimes be tricky. For our team, it helps with monitoring usage on our internal website and supports our SOC2 and HIPAA compliance efforts.
"Fast, Simple, and Modern"
The best aspect is the straightforward admin experience. After adding the Gateway to the infrastructure, it's easy to add resources and manage policies. This is particularly useful when dealing with a large number of resources, as we do. Additionally, onboarding internal users is effortless with the Twingate client; we've received many positive comments about the client app across all operating systems. I have no dislikes. Perhaps the pricing could be an issue if the number of seats is very high. We have multiple private cloud environments with microservices and internal tools. With Twingate, we can control access and ensure only authorized personnel can reach resources.
"A Handy Tool for Managing Private Network Access"
Switching from a bastion server with SSH keys was a pain, as keeping those keys current and organized was a hassle. Using Terraform to oversee Twingate users, groups, service accounts, tokens, connectors, and resources fits perfectly into the Infrastructure as Code model. However, policy management is click-ops; it would be great to handle that via Terraform too. Also, having MFA at the resource level would be beneficial. Depending on the workflow, the simple friction of needing to authenticate can thwart a malicious action. Currently, even if resources are in separate groups with MFA enabled, once you authenticate, all resources in groups that require auth become accessible. I understand there are plans for per-group authentication. Moving from a single bastion server with SSH to IaC was cumbersome. Twingate greatly simplifies that, and it also enables us to use external pipelines for resource access in a sensible way using service accounts, and to securely expose private endpoints to the right people.
"Speedy and Reliable Connections with Easy MFA Integration and High Security"
Connectivity is very fast and reliable, and it works well with any ISP. Implementation was simple, customer support is responsive, and integrating with our MFA systems was straightforward. Security is top-notch. The interface is user-friendly. There's not much to criticize, though after an update, it might take time to adapt to the new version; in the past, we had to uninstall and reinstall for the VPN to function correctly. It provides online security for our tools and all our software.
"Quick Setup, Solid Network Access Control, and Excellent Google Workspace Integration"
Setting up and rolling out was a breeze. Access control at the network layer works well. It integrates smoothly with Google Workspace, and there's a Terraform provider plus a GitHub Actions step. I have no complaints. It allows a remote workforce to access private resources in AWS securely.
I
Information Technology Engineer
"Seamless, Scalable ZTNA with Fine-Grained Access Control"
Twingate delivers a smooth and secure Zero Trust Network Access solution that removes the need for traditional VPNs. Deployment is simple, and its cloud-native design scales effortlessly without heavy infrastructure changes. I particularly value the granular access controls, which let us enforce least-privilege principles effectively. From a security perspective, it improves visibility and control over user access, strengthening our overall security stance. Identity provider integration is seamless, and the user experience is excellent—end users can access resources securely without the performance bottlenecks often seen with VPNs. Additionally, Twingate simplifies access management for both internal and external users, making it a dependable option for modern distributed environments. One area that could be improved is the logging and traffic monitoring UI. Currently, advanced search and filtering are lacking, making it hard to quickly investigate specific user actions or incidents. The interface would benefit from more intuitive navigation and robust filters (e.g., by user, resource, time range, and action) to streamline log analysis. Better visibility into traffic patterns and more detailed audit logs would also greatly enhance monitoring and troubleshooting.
"Twingate Streamlines Multi-AWS Management with Seamless Entra ID SSO Permissions"
At Autbank, we leverage Twingate to manage access to our clients' multiple AWS accounts, which has significantly simplified our operations. We simply deploy a connector within each client's network to centralize all access. With permission management integrated through our Entra ID SSO, granting specific permissions to individuals for limited periods is extremely straightforward. So far, we haven't encountered any difficulties or issues with our use of Twingate; it's an excellent tool for business. The centralization of multiple networks via different connectors greatly assists us in our daily workflows.
M
Mid-Market (51-1000 emp.)
"Lightweight, dependable, and easy to integrate—a significant upgrade from legacy IPSEC VPN"
This is a lightweight solution with minimal setup effort, strong reliability, solid performance, and negligible overhead. Compared to our previous IPSEC VPN, it saved us money, improved our security posture, and boosted network performance. Integrations with IaC tools like Terraform are straightforward, and the product is user-friendly; plus, the free home tier is a great perk that lets tech enthusiasts experiment without risking production. However, automated deployments on new builds require a few extra manual steps. On the Mac side (though this is more of a macOS issue), we've had problems with Twingate detecting the security posture. Specifically, when a Mac is in clamshell mode, it reports biometrics as offline. We have a mandate to keep biometrics enabled, but we can't rely on Twingate's posture check for that. The remote access to specific resources with high visibility is excellent. In the past, with a traditional VPN, geographically distant users or those with unreliable connections often suffered high retransmission rates and long round-trip times to the concentrator. Deploying Twingate connectors at the network edge noticeably enhanced the experience for users who frequently experienced retransmissions, especially those using QUIC.
"Straightforward setup and use, but missing some enterprise conveniences"
Getting started is simple for IT, and for most users it's install-and-forget. The interface could use polish—it's not particularly intuitive for our non-technical team. IT is fond of it because it slots neatly into our current stack (Azure AD, SentinelOne) and we consider the pricing reasonable. One of our satellite offices actually runs a connector on a Raspberry Pi without any noticeable performance hit. Overall, it's a solid product with some drawbacks. It's clearly built with developers in mind, and I miss certain features that would make it more enterprise-friendly. For instance, it's surprising there's still no way to gracefully drain a connector before an upgrade. On the bright side, it's highly customizable, and we've been able to work around that by using the connector's Prometheus metrics to schedule upgrades during low-activity windows—though we shouldn't have to do that. We've also encountered some puzzling issues where users get logged out and can't log back in without restarting the Twingate service, which our end users can't do. The granular access is a big win because now we're confident that our call center staff have access only to exactly what they need.