SSE / ZTNA / Zscaler

Zscaler Internet & SaaS and Private Access

Zscaler separates Internet & SaaS traffic protection, commonly known as ZIA, from Private Access, or ZPA. Client Connector can steer both while private applications are reached through configured App Connectors and access policy.

Combined public and private application accessResearch reviewed

What you are evaluating

The scored configuration selects ZIA web policy plus ZPA private application access and Client Connector. ZDX, advanced data protection, browser isolation and privileged access add-ons are excluded unless specifically purchased and assessed.

A useful evaluation context

Consider for a workforce access program prepared to manage separate public and private access configurations as one operating process.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • ZPA defines applications, user attributes, identity-provider integration and access policies.
  • App Connectors provide the private application path; log streaming supports external investigation.
  • Documented ZIA/ZPA integration includes explicit requirements for particular inspection and source-IP use cases.

Where it fits in the work

  1. Define a test private application, App Connector and SAML identity provider.
  2. Configure access and timeout rules for a small group and deploy the supported client.
  3. Verify public versus private traffic steering and inspect the corresponding service logs.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

A test contractor may reach one private web application while ordinary browsing uses the web security service.

Evidence to look for

Prove the two traffic paths and show that a neighboring application remains unavailable; then remove the user’s entitlement and measure the effect.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which ZIA and ZPA subscriptions are actually selected?
  2. Which session controls require client or application changes?
  3. How are connector health, inspection exceptions and exported logs operated?

Names you may encounter: ZIA · ZPA · Zero Trust Exchange. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.