Both technologies answer the same question — connecting your sites — with opposite philosophies.
SD-WAN: an appliance (often an NGFW) per site builds encrypted tunnels over any Internet access, with a central console. Strengths: fast rollout, local breakout to cloud and SaaS (Microsoft 365 exits directly, without hairpinning through HQ), multi-transport (fiber + 4G/5G backup), low access cost. It is the natural choice from 3 sites up, or as soon as cloud dominates the flows.
IP/MPLS: a carrier-operated private network with end-to-end QoS guaranteed by contract — something no tunnel over the Internet can promise. It remains the right choice for critical voice, real-time ERP, or a stable perimeter of a few sites with no cloud dependency.
In practice, hybrid is common: MPLS on critical sites, SD-WAN everywhere else — with a progressive migration as contracts expire.