MPLS was built for a world where applications lived in the data center. Most of them don't anymore.
Email, file sharing, video calls, and CRM now run in Microsoft 365 and other SaaS platforms. Yet many branch networks still route that traffic across expensive private circuits to a central site, through a data center firewall, and only then out to the internet. The organization pays premium prices per megabit to make its most-used applications slower.
That's the real case against MPLS. Cost matters, but the architecture no longer matches where the traffic goes.
The Hairpin Problem
Picture a user in a branch office joining a Teams call. The traffic leaves the branch over MPLS, travels to headquarters, passes through the central firewall, exits to the internet, and finally reaches Microsoft's network. The return path repeats the trip in reverse.
Every extra hop adds latency and another point of congestion. Microsoft's own connectivity guidance for Microsoft 365 recommends the opposite design: let branch traffic reach Microsoft's network from the nearest possible internet exit. Microsoft groups its endpoints into categories and flags the most latency-sensitive ones, including Teams media, for direct, local routing.
A backhauled MPLS design breaks that guidance by default.
Why Cheaper Links Make Network Teams Nervous
The obvious fix is to replace MPLS with business broadband, dedicated internet access, or 5G. Those links cost far less per megabit. They also come without the guarantees that made MPLS attractive in the first place.
Broadband jitters. Packet loss spikes at peak hours. A 5G link can degrade when the cell gets busy. Voice and video suffer first because they can't retransmit lost packets the way file transfers can. A dropped packet in a Teams call becomes a frozen face or a clipped word.
Network teams know this, which is why many MPLS contracts get renewed out of caution rather than need.
Our engineers at IT Builders see the result regularly in branch network assessments: Microsoft 365 traffic backhauled across MPLS to a central data center, with users blaming "the internet" for call quality problems that the WAN design itself creates.
Reviewing Your WAN Before the Next Renewal?
The right mix of MPLS, broadband, and wireless links depends on your application profile, branch count, and the traffic that actually needs to reach the data center.
How Application Steering Handles an Unreliable Link
SD-WAN earns its place by treating every link as unreliable and measuring it continuously. Follow that Teams call through a FortiGate running Secure SD-WAN.
It identifies the application. FortiOS recognizes Teams and other Microsoft 365 traffic through application signatures and Fortinet's Internet Service Database, which tracks the IP ranges of major SaaS providers. The SD-WAN rules know a packet belongs to a Teams call, not a file download.
It measures every path. Performance SLA health checks probe each link constantly for latency, jitter, and packet loss. The FortiGate always knows which link can carry real-time media right now.
It steers the call. An SD-WAN rule sends Teams media over whichever link currently meets the quality threshold. If the primary broadband link starts dropping packets mid-call, the FortiGate moves the traffic to the healthier link.
It repairs what it can't avoid. When every available link is degraded, forward error correction and packet duplication across overlay tunnels can recover lost packets before the user notices them.
Bulk traffic like backups and software updates, meanwhile, rides the cheapest link available. Nobody pays premium-circuit prices to move a Windows update.
Security Has to Move With the Breakout
Sending traffic straight to the internet from every branch solves the hairpin, and it also removes the central firewall that used to inspect that traffic. Every branch becomes its own internet edge.
This is where "SD-WAN" and "Secure SD-WAN" part ways. A routing appliance with SD-WAN features steers traffic well but leaves the branch exposed, so the organization ends up buying a separate security stack for every site.
FortiGate runs SD-WAN natively inside FortiOS, on the same device that provides the next-generation firewall, IPS, web filtering, and SSL inspection. The branch gets local breakout and full security inspection from one box, managed centrally through FortiManager. There's no separate SD-WAN appliance and no separate SD-WAN license.
Where the Savings Come From (and Where They Don't)
The savings come from three places: replacing or downsizing MPLS circuits with lower-cost internet links, eliminating separate branch security appliances, and cutting the data center bandwidth that backhauled SaaS traffic used to consume.
How much an organization saves depends on its current contracts, its branch count, and how much traffic still needs a private path. Some workloads, such as legacy applications or regulated data flows, may justify keeping a smaller MPLS footprint. A credible migration plan models the numbers branch by branch instead of promising a flat percentage.
Migrate Hybrid-First
The lowest-risk migrations don't cut MPLS on day one. They add internet links alongside it and let SD-WAN run both as underlays.
That gives the team live performance data from every branch before any contract changes. SaaS traffic moves to local breakout first, where the gains show up fastest. Once the data shows the internet links meeting the application SLAs, MPLS circuits come down in stages, starting with the sites that need them least.
The Bottom Line
MPLS protected application quality in a data-center-centric world. SD-WAN protects it by measuring every link, steering each application to the path that can carry it, and putting security at the branch where the traffic now exits. Done carefully, the move lowers WAN costs and improves the Microsoft 365 experience in the same project.
IT Builders is an authorized Fortinet Engage Partner holding the SD-WAN specialization. Our engineers model migration costs branch by branch, design application steering around the tools users depend on, and cut over sites without interrupting business operations.
Facing an MPLS renewal or planning a branch refresh?








