Zscaler support without admin rights across supported domains
First-line support needs enough Zscaler context to assess tickets. Broad admin rights are not required for that task. CentaurNexus connects role-based user, device and access context for the first finding and extends it with additional supported domains for second level and administrators.
Every IT team knows the pattern: an employee reports that an internal application is unreachable or the connection keeps dropping. The ticket lands with the help desk. To understand what's going on, first-level would have to look into the Zscaler console: Is the user correctly authenticated? Is a ZIA policy blocking the target URL? Is the ZPA app segment enabled? Does ZDX show a network or device problem? Four questions, potentially three to four different portals, and each of them requires privileged access.
The convenient path would be to simply give the help desk admin rights in Zscaler. The secure path is the exact opposite. Zscaler admin rights are powerful: whoever holds them can change policies, move users, open segments. That is far more than the task requires for first-level support, and it contradicts the principle of least privilege. The consequence in many organizations: the help desk has no insight at all, escalates every other ticket to the small team with admin access, and resolution time rises.
The real problem: visibility without privileges
As a Zero Trust Exchange, Zscaler delivers excellent control and telemetry. ZIA governs internet access with firewall, IPS, sandboxing, and DLP; ZPA replaces classic VPN with application-specific segments; and ZDX measures the digital user experience down to the device and network level. So the data is there. The problem is not Zscaler, but the way a help desk gets to this data: either with too many rights or none at all.
This is exactly where CentaurNexus comes in, a sovereign single pane of glass for Zscaler, with production operation for EU customers entirely on STACKIT in the EU and documented privacy and data paths. CentaurNexus is not a replacement for Zscaler and not a second console with the same buttons. It is an operations and support layer on top that reads and writes via the official Zscaler OneAPI, releasing only as much information as each role actually needs.
User Support Center: the 360-degree user picture in a single view
The heart of support is User Support Center. The agent enters a username or email address and receives the consolidated picture across the Zscaler domains, merged from individual OneAPI queries, in a single interface:
- ZIA: authentication and policy status, applied rules, blocked or allowed destinations, relevant internet-access events.
- ZPA: assigned application segments, access and connection status to private applications, instead of guessing about VPN tunnels.
- ZDX: the user's digital experience, device and network health, indications of ISP, Wi-Fi, or device issues.
Instead of opening three portals and manually piecing together fragments, first-level reads the picture in one place. This reduces portal switches, shortens time to diagnosis, and makes the result reproducible: two agents checking the same user see the same picture.
For roles that need more depth, Unified Support Center extends the same approach with additional domains such as ZIdentity, PRA, and EASM. The view thus grows from the quick first-level picture to broader analysis, without having to switch interfaces.
Why it stays secure: OneAPI, RBAC, and audit
The decisive point is that this insight does not come at the expense of security, but strengthens it. Three mechanisms interlock.
Access only via the official OneAPI
CentaurNexus addresses Zscaler exclusively via the documented OneAPI, using a credential that the customer provides in their own tenant. There is no reverse engineering and no imitation of internal admin screens. The help desk itself never holds Zscaler admin credentials.
RBAC domain scoping
Not every help desk should see everything. Via RBAC domain scoping, a support team sees only its assigned area, such as a department, a site, or a tenant. First-level gets the diagnostic context, but no insight into other areas and no write rights it does not need. For MSPs and system integrators, this can be extended in a controlled way across multiple tenants.
Everything auditable, sensitive actions with approval steps under the tenant policy
Security-relevant access and changes are logged in a traceable manner: who, what, when, on which target. Where writes actually occur in Zscaler, the approval process defined by the tenant policy can additionally be enforced, so a second authorized person must approve. Such evidence can support documentation for NIS2- or DORA-related reviews; it does not establish compliance on its own.
How a ticket runs with CentaurNexus
- A user reports that an internal application is unreachable. The ticket lands with first-level.
- The agent opens User Support Center and searches for the user by name or email. The 360-degree picture across ZIA, ZPA, and ZDX appears in a single view.
- ZPA shows that the required app segment is not assigned to the user, while ZIA and ZDX are unremarkable. The cause is thus clearly identified.
- The agent resolves the ticket within the scope of their role or escalates in a targeted way with full context, instead of passing on an empty guess.
- Where a write change is necessary, the approval process defined by the tenant policy optionally applies, and the action is fully recorded in the audit trail.
The result is twofold: the user is unblocked faster because there is less escalation and less guessing, and IT management retains control because no one is given rights they do not need. The help desk becomes capable of acting without the attack surface growing.
What IT management gains
For IT management, this is a matter of both risk and efficiency. Fewer privileged accounts mean a smaller attack surface and a cleaner rights landscape. A capable first-level relieves scarce admin resources and lowers the average resolution time. The continuous audit trail provides traceable inputs for internal and external reviews. Zscaler remains the control and enforcement layer; CentaurNexus makes it operable and traceable for day-to-day operations.
See 360-degree support without admin rights live
Experience in the prepared demo how User Support Center and Unified Support Center show the relevant user context across ZIA, ZPA, and ZDX, role-based scoped and auditable, entirely without Zscaler admin rights.
Open the prepared demoAbout 70 data points form a context, not a fixed guarantee
The user finding can combine about 70 data points from supported sources across identity, device, Client Connector, web access, private applications, policy context and digital experience. Not every tenant supplies every value. Licence, API scope, data source and source state determine coverage.
CentaurNexus shows source, data age and coverage. A missing point is not presented as a benign state. The help desk can see whether the finding supports first resolution or should be handed to second level with a precise question.
First resolution and handover use the same facts
If first level resolves the case, diagnosis and action remain documented in the workflow. If a handover is needed, the next role receives the same technical and time context. The user does not need to repeat email address, device, time and symptom at every support level.
Quality can be assessed in the customer's own environment through fewer follow-up questions, more complete handovers and a higher share of cases classified without broad vendor-admin rights. Improvements are measured by tenant rather than promised as a universal performance figure.
Frequently asked questions
No. With CentaurNexus, the help desk sees the 360-degree user picture across ZIA, ZPA, and ZDX in a single view, without a single admin login to the Zscaler console. CentaurNexus reads the data via the official Zscaler OneAPI and displays it role-based and scoped, so first-level staff get exactly the information needed for diagnosis.
User Support Center provides the 360-degree baseline picture of a user across ZIA, ZPA, and ZDX in one view. Unified Support Center extends this view with additional domains such as ZIdentity, PRA, and EASM and is aimed at roles that need deeper, broader context for analysis and root cause.
For EU customers, CentaurNexus production operation runs entirely on STACKIT in the EU and documented privacy and data paths. Access to Zscaler is exclusively via the official OneAPI using a customer-provided credential, and every security-relevant action is logged in a traceable manner.
- Zscaler: About API Clients – official OneAPI and role documentation.
- CentaurNexus for help desk and second level: user context, role scope, audit, and approvals under the tenant policy.
- STACKIT company information and the CentaurNexus privacy notice.