Optimizing Zscaler configuration

Getting more from your Zscaler license: the configuration health check

Your Zscaler license can do more than is currently used. A configuration health check makes visible which capabilities are already paid for but not yet active, rates the health of your config as a score, and delivers a prioritized plan across all domains.

CentaurNexus · Reading time approx. 6 minutes
Configuration health check score, symbolic

Zscaler is a powerful platform. The Zero Trust Exchange sits inline in the data stream, ZIA protects internet and cloud access, ZPA replaces VPN with app segmentation, ZDX monitors the digital user experience. Many licenses include functions such as DLP, IPS, sandboxing, SSL inspection, or fine-grained segmentation. The decisive question in ongoing operations is rarely whether Zscaler is deployed, but how completely the existing license actually takes effect.

The silent problem: underutilization

After a rollout, the focus quickly shifts to daily operations. New sites, new applications, personnel changes in the team: the configuration grows, but no one regularly reconciles it against the full scope of the license. The result is a creeping underutilization. Paid capabilities run in default mode, are only partially rolled out, or were activated for a test case and then never adopted across the board.

This is not a criticism of the platform, on the contrary. Zscaler delivers the capabilities; the lever lies in the configuration. This is exactly where a configuration health check comes in: it answers the question of how much value is being extracted from the license you already have and where exactly potential and risk still lie.

Core idea: A health check does not buy new licenses. It shows how to get more out of the license you are already paying for, and at the same time makes open security gaps visible.

What a configuration health check evaluates

The health check from Policy Health reads the current state of your configuration via the official Zscaler OneAPI, across domains over ZIA, ZPA, and ZDX. The evaluation results in four building blocks.

1. A health score

The current state is compared against proven configuration patterns and condensed into an understandable score. Instead of hundreds of individual settings, management and team see one metric that makes the maturity of the configuration graspable at a glance. An illustrative example, not a real measurement: a tenant starts with a score of 62 out of 100 and reaches 84 after working through the top actions. The concrete values always depend on your environment.

2. A prioritized action plan

A score alone does not help. That is why the health check delivers every finding with a concrete, prioritized recommendation: what is affected, why it matters, and which step addresses it. The prioritization orders by impact and effort, so your team first tackles the points that bring the greatest security and value gain.

3. History tracking

Configuration health is not a one-time state, but an ongoing one. The health check records the score and findings over time, so improvements and regressions become traceable. This way, you demonstrate to management and to auditors not just a snapshot value, but a continuous development.

4. A structured PDF report

The PDF report combines score, findings, actions, and history for work and documentation in relevant review areas.

Actionable plan: The analysis prioritizes individual, verifiable actions with context and impact. Implementation follows the approval process defined by tenant policy.

Sovereign and without additional risk

CentaurNexus is a sovereign single pane of glass for Zscaler, with production operation for EU customers entirely on STACKIT in the EU and documented privacy and data paths. The health check works exclusively via the official Zscaler OneAPI, so it only accesses documented interfaces. No undocumented internals are tapped and no Zscaler admin screens are rebuilt. The added value lies in the cross-domain evaluation, the prioritization, and the audit preparation, which arise as a complement to your existing Zscaler environment.

How a health check runs

  1. Connect: The tenant is connected via the Zscaler OneAPI with the credential you provide. Least privilege, read-only access for the analysis.
  2. 1-click health check: You start the evaluation. Policy Health reads the configuration across ZIA, ZPA, and ZDX and compares it against best practices.
  3. View score and findings: You receive the health score and the list of findings, prioritized by impact.
  4. Work through the actions: Your team implements the recommended steps, individually and traceably, with approval under the tenant policy if desired.
  5. Pull the report and track the history: You export the PDF report for management or audit and observe the score development over time.

The double benefit

A configuration health check pays off in several directions at once. You extract more value from the license you already own by identifying and activating unused capabilities. You make security gaps visible and fixable before they turn into an incident. And you generate solid evidence for audits and for the management level, which wants to see a clear metric instead of a detail table.

The result is an operation that has not only deployed the Zero Trust Exchange, but continuously keeps it at a high level of maturity, measurable, prioritized, and documented.

See the health check on your config

In the prepared demo, you start a configuration health check, see the score, action plan, and PDF report, and experience operations without broad Zscaler admin rights.

Open the prepared demo

Separate licence, configuration and use

A licensed function is not automatically configured, and a configured function is not automatically used effectively. The health check therefore separates licence indication, current configuration, available coverage and observed use. Each layer answers a different question.

OneAPI provides supported current configuration and status values. NSS and LSS feeds can show observed access or rule activity within the available history. If a source is missing, the conclusion remains correspondingly limited.

From finding to a prioritised decision

The report orders findings by impact, dependency and required review step. An unused function can be intentionally unused. A configuration gap can require a technical prerequisite or a business decision. The health check separates these cases instead of hiding them in one score.

The responsible role selects the action. If it creates a target-system change, tenant policy, audit, activation and read-back apply. The report does not implement changes on its own.

Recurring review instead of a one-time inventory

A health check becomes more useful when repeated. Teams can see which findings were resolved, consciously accepted or remain dependent. Source state and data age make comparisons between review points traceable.

Management receives a clear view of used capabilities and open decisions. Concrete savings or ROI figures are derived only from customer-specific cost, licence and operating data and are not promised universally.

Frequently asked questions

What is a Zscaler configuration health check?

A health check reads the current state of your configuration across ZIA, ZPA, and ZDX via the Zscaler OneAPI, evaluates it against best practices, and condenses the result into a health score plus a prioritized action plan.

Why do many companies not fully use their Zscaler license?

Licenses often include capabilities such as DLP, IPS, sandboxing, or segmentation that are never fully activated or maintained after the rollout. Without regular reconciliation, this potential remains unused. A health check makes visible which already-paid-for capabilities are not yet taking effect.

Can the health check support documentation for NIS2 and DORA review areas?

The configuration health check produces a structured PDF report with score, findings, actions, and history for documentation in relevant review areas.

Sources & further reading: