Zscaler & Zero Trust operations glossary ยท Access & traffic

What is an App Segment?

Definition

In Zscaler Private Access (ZPA), an App Segment is the access unit that groups one or more internal applications by their domains or IP addresses, together with ports and protocols. Access policies apply to App Segments: users reach exactly the applications in the approved segment, not the network behind it. That is how the App Segment technically implements the ZTNA principle of granting access per application rather than per network. An App Connector establishes the connection from inside the internal network; the application itself stays invisible from the internet. How App Segments are cut therefore directly shapes security, troubleshooting, and operational effort.

App Segment in detail

Technically, an App Segment consists of application definitions (FQDNs, including wildcards, or IP ranges) and the associated TCP and UDP port ranges. Several App Segments can be bundled into segment groups, which access policies then reference. When a user reaches an approved application, the ZPA cloud brokers the connection: the Zscaler Client Connector opens an outbound tunnel from the endpoint, and an App Connector in the internal network establishes the connection to the application. No inbound firewall ports are needed for this.

The model differs fundamentally from classic network access: a VPN routes users into a network where they can reach whatever is not specifically filtered out. An App Segment reverses that logic: only what is explicitly defined and assigned by policy is allowed. For web applications, Browser Access also provides a clientless access path, for example for partners or personal devices.

Why App Segments matter in Zscaler operations

Day to day, how the App Segments are cut decides how quickly access problems get resolved. The typical helpdesk ticket reads: "I can't reach application X." The answer almost always comes down to three questions: which segment the application sits in, which policy applies to this user, and whether the responsible App Connector is healthy. Anyone who cannot see this chain ends up guessing, escalating, or waiting for an administrator with console access.

Cut size is also central for security and evidence. Segments that are too broad, with wildcard domains or large IP ranges, undercut least privilege because they effectively grant network access again. Segments that are too fine-grained raise maintenance effort and error rates. For audits, for example under NIS2, you need to be able to show who can access which applications through which segment, and when that last changed.

Common sources of error

App Segments in practice: what CentaurNexus contributes

With User Support Center, CentaurNexus shows App Segments and per-user access status in context: a 360-degree user finding across ZIA, ZPA, and ZDX in a single view, without the helpdesk needing Zscaler admin rights. That means the question "Why can't this user reach application X?" gets resolved at 1st Level instead of escalated. The guide below shows what that looks like in everyday support: Zscaler support without admin rights. CentaurNexus runs as a sovereign single pane of glass in Germany, GDPR-compliant.

See in the live demo how the helpdesk views App Segments per user, with no Zscaler admin rights at all.Watch the live demo

Related terms

Frequently asked questions about App Segments

What is the difference between an App Segment and a segment group?

An App Segment defines concrete applications through domains or IP ranges, together with ports and protocols. A segment group bundles several App Segments into one unit that access policies then reference. So the group structures the rule base, while the segment holds the technical definition of the applications. In practice, policies mostly reference groups.

How does an App Segment differ from VPN access?

A VPN connects users to a network where they can, in principle, reach many systems. An App Segment grants access only to the explicitly defined applications; the network itself stays invisible. That noticeably shrinks the attack surface and makes lateral movement across the network considerably harder.

How many App Segments does a company need?

There is no fixed number. A cut by application, protection need, and ownership has proven effective: coarse enough that maintenance effort stays manageable, fine enough that no blanket permissions creep in. What matters more than the count is that every segment has an owner and a documented purpose.

Why can't users reach an application despite a matching App Segment?

Common causes are missing ports or protocols in the segment definition, an access policy that does not include the user, overlapping segments with unexpected matching, or an App Connector with no connection to the application. It helps to check the chain of user, policy, segment, and connector systematically.

What is Browser Access in the context of App Segments?

Browser Access allows access to an App Segment's web applications directly through the browser, without an installed Zscaler Client Connector. That is practical for partners, service providers, or personal devices. The segment's access policies still apply; only the access path for web-based applications changes.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.