IIJ scales secure remote access to approximately 10,000 devices with Absolute Secure Access


Internet Initiative Japan Inc. (IIJ) is an internet pioneer that launched Japan's first commercial internet connectivity service in 1993. Since then, IIJ has delivered total network solutions — including internet connectivity, WAN, cloud, security, and mobile services — to enterprise and individual customers. Built on highly reliable, high-value-added network infrastructure, IIJ continues to power digital transformation for businesses across Japan.
An aging VPN under pressure as telework surged
IIJ's remote access ran on a legacy VPN paired with a third-party endpoint compliance tool — both nearing end of life. As telework demand climbed, the team added 11 servers as a stopgap. Users had to pick a server themselves, traffic piled onto single nodes, and engineers restarted servers every few days. Worse, retiring the compliance tool threatened to drop IIJ's security level. The company needed a successor built to scale, not another appliance.
With our previous remote access service, we had put 11 servers in place as a stopgap measure. However, users had to select which server to connect to themselves, which was extremely inconvenient. In addition, users sometimes concentrated on a single server, and high traffic volumes depleted the resources of individual servers. This made the servers themselves unstable, so we had to deal with the issue by restarting them every few days.
How They Did It
Deploying its own ZTNA service, powered by Absolute Secure Access
Rather than buy more appliances, IIJ deployed its own IIJ Flex Mobility Service/ZTNA, using Absolute Secure Access as the core engine. The goals were clear: let large numbers of users connect reliably and run endpoint compliance checks without fail. "The issue could have been resolved by adding more VPN appliances, but that would have increased both costs and operational workload," says Hirofumi Miura. "We thought that if we had a good service of our own, there was no reason not to use it." Users now connect with a single operation — no server selection required.
Scaling from 200 to roughly 10,000 devices
The rollout began with around 200 devices and expanded fast. IIJ now runs 12,000 licenses and approximately 10,000 active devices, with concurrent connections peaking between 7,000 and just under 8,000. Absolute Secure Access's clustered architecture absorbed that growth without performance impact. More than 3,000 iPhones joined the environment too, provisioned automatically through Microsoft Intune integration — when a smartphone registers, the Absolute app downloads on its own.
Instant troubleshooting with Insights
When a connectivity issue arises, the Insights visibility dashboard shows at a glance who is communicating, over which connection, and at what quality level. Administrators can immediately determine whether a delay is caused by the user’s home wireless environment or the load on their PC — without collecting or analyzing log files. Troubleshooting that previously required back-and-forth with end users now resolves directly from the management console.
Maintenance-free Local Breakout for web conferencing
For services like Teams and Zoom, IIJ uses Local Breakout (LBO) to route traffic directly to the internet rather than through the VPN tunnel. With conventional VPN, administrators face the constant burden of updating exclusion lists every time SaaS providers change their IP addresses. Per-App VPN eliminates that entirely: by specifying an application name or domain, the service tracks changes automatically. The result is maintenance-free operation and stable web conferencing quality at scale.
With our previous remote access service, we had put 11 servers in place as a stopgap measure. However, users had to select which server to connect to themselves, which was extremely inconvenient. In addition, users sometimes concentrated on a single server, and high traffic volumes depleted the resources of individual servers. This made the servers themselves unstable, so we had to deal with the issue by restarting them every few days.
If recommending it to other companies, I would highlight the fact that it can scale significantly while flexibly supporting everything from simple operation to advanced configuration. Even when we receive an inquiry that a user can't connect, isolating the cause is extremely smooth. Previously, we had to ask users to send us logs for analysis, but now we can identify the issue immediately from the management console.
Resilience at scale, run by a small team
IIJ Flex Mobility Service/ZTNA is now a business infrastructure for every IIJ employee. A team of just three to four people manages approximately 10,000 devices, replacing a fragile 11-server setup with a single console. Security checks run inside the service, and Absolute's Virtual IP/Network Resilience technology keeps sessions alive as users move between floors or switch from Wi-Fi to LTE. Connection drops — once a daily frustration — are gone. As networking professionals, IIJ holds its own infrastructure to an exacting standard, and the service meets it.

For IIJ, Absolute Secure Access:
- Manages approximately 10,000 active devices with just three to four people
- Supports 12,000 licenses and 7,000–8,000 peak concurrent connections with no performance degradation
- Replaced 11 physical servers with a single management console
- Completes endpoint compliance checks — patch, antivirus, and domain participation — natively within the service
- Maintains uninterrupted sessions during network transitions through Virtual IP/Network Resilience technology
- Added more than 3,000 iPhones, automated via Microsoft Intune integration
- Accelerates troubleshooting with the Insights dashboard — no log file collection required
- Enables maintenance-free Local Breakout for stable web conferencing through Per-App VPN



