What is an App Segment?
In Zscaler Private Access (ZPA), an App Segment is the access unit that groups one or more internal applications by their domains or IP addresses, together with ports and protocols. Access policies apply to App Segments: users reach exactly the applications in the approved segment, not the network behind it. That is how the App Segment technically implements the ZTNA principle of granting access per application rather than per network. An App Connector establishes the connection from inside the internal network; the application itself stays invisible from the internet. How App Segments are cut therefore directly shapes security, troubleshooting, and operational effort.
App Segment in detail
Technically, an App Segment consists of application definitions (FQDNs, including wildcards, or IP ranges) and the associated TCP and UDP port ranges. Several App Segments can be bundled into segment groups, which access policies then reference. When a user reaches an approved application, the ZPA cloud brokers the connection: the Zscaler Client Connector opens an outbound tunnel from the endpoint, and an App Connector in the internal network establishes the connection to the application. No inbound firewall ports are needed for this.
The model differs fundamentally from classic network access: a VPN routes users into a network where they can reach whatever is not specifically filtered out. An App Segment reverses that logic: only what is explicitly defined and assigned by policy is allowed. For web applications, Browser Access also provides a clientless access path, for example for partners or personal devices.
Why App Segments matter in Zscaler operations
Day to day, how the App Segments are cut decides how quickly access problems get resolved. The typical helpdesk ticket reads: "I can't reach application X." The answer almost always comes down to three questions: which segment the application sits in, which policy applies to this user, and whether the responsible App Connector is healthy. Anyone who cannot see this chain ends up guessing, escalating, or waiting for an administrator with console access.
Cut size is also central for security and evidence. Segments that are too broad, with wildcard domains or large IP ranges, undercut least privilege because they effectively grant network access again. Segments that are too fine-grained raise maintenance effort and error rates. For audits, for example under NIS2, you need to be able to show who can access which applications through which segment, and when that last changed.
Common sources of error
- Definitions too broad: wildcard domains or large IP ranges turn the App Segment back into network access in practice.
- Overlapping segments: the same domain or IP in several segments leads to hard-to-predict matching and confusing troubleshooting.
- Missing ports or protocols: the application "doesn't work" even though the policy is correct, because only some of the required ports are open.
- Orphaned segments: once an application is decommissioned, the segment stays behind with no owner and no purpose, a dead permission and an audit finding waiting to happen.
App Segments in practice: what CentaurNexus contributes
With User Support Center, CentaurNexus shows App Segments and per-user access status in context: a 360-degree user finding across ZIA, ZPA, and ZDX in a single view, without the helpdesk needing Zscaler admin rights. That means the question "Why can't this user reach application X?" gets resolved at 1st Level instead of escalated. The guide below shows what that looks like in everyday support: Zscaler support without admin rights. CentaurNexus runs as a sovereign single pane of glass in Germany, GDPR-compliant.
Related terms
Frequently asked questions about App Segments
An App Segment defines concrete applications through domains or IP ranges, together with ports and protocols. A segment group bundles several App Segments into one unit that access policies then reference. So the group structures the rule base, while the segment holds the technical definition of the applications. In practice, policies mostly reference groups.
A VPN connects users to a network where they can, in principle, reach many systems. An App Segment grants access only to the explicitly defined applications; the network itself stays invisible. That noticeably shrinks the attack surface and makes lateral movement across the network considerably harder.
There is no fixed number. A cut by application, protection need, and ownership has proven effective: coarse enough that maintenance effort stays manageable, fine enough that no blanket permissions creep in. What matters more than the count is that every segment has an owner and a documented purpose.
Common causes are missing ports or protocols in the segment definition, an access policy that does not include the user, overlapping segments with unexpected matching, or an App Connector with no connection to the application. It helps to check the chain of user, policy, segment, and connector systematically.
Browser Access allows access to an App Segment's web applications directly through the browser, without an installed Zscaler Client Connector. That is practical for partners, service providers, or personal devices. The segment's access policies still apply; only the access path for web-based applications changes.
- Zscaler Help Portal: ZPA documentation, help.zscaler.com/zpa
- Zscaler Help Portal: Configuring Defined Application Segments - help.zscaler.com/zpa/configuring-application-segments
- Zscaler Help Portal: About Segment Groups - help.zscaler.com/zpa/about-segment-groups
- NIST SP 800-207: Zero Trust Architecture, csrc.nist.gov/pubs/sp/800/207/final
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.