What is Browser Access?
Browser Access is a ZPA (Zscaler Private Access) method that lets users reach internal web applications through an ordinary web browser, with no Zscaler Client Connector installed on the device. A link to the application is all it takes; the Zero Trust Exchange checks and secures the connection in the background. That makes Browser Access particularly useful wherever no managed device is available, for example for external partners or on personal devices.
Browser Access in detail
Technically, the web application is set up as an App Segment with a Browser Access configuration. Instead of direct network access, the user gets a dedicated, protected URL and reaches the application through it once authentication succeeds. Identity and policy are checked on every access, exactly as with client-based ZTNA access.
The main difference from classic ZPA access with Client Connector is reduced visibility into device posture. Without an installed client, Zscaler can tell you less about the accessing device than it can for a managed endpoint.
Why Browser Access matters in Zscaler operations
Browser Access connections work differently from client-based access at a technical level, so they need their own diagnostic logic. An access problem can sit in the App Segment configuration, in authentication, or in the user's browser, without the usual visibility into device state.
For support, that means distinguishing clearly between client-based and browser-based access before troubleshooting starts, so nobody chases a client problem for a client that was never installed.
Common sources of error
- The application is not configured correctly for Browser Access and stays tied to the client.
- The user mistakes the Browser Access link for a regular internet link and reports the wrong fault.
- A missing authorisation for external users gets reported as a technical fault instead of a permissions issue.
- Browser compatibility problems get mistaken for a Zscaler outage.
Browser Access in practice: what CentaurNexus contributes
CentaurNexus shows a user's access type through User Support Center, client-based or browser-based, together with the current policy status across ZIA, ZPA and ZDX in one view, and the helpdesk needs no Zscaler admin rights to see it. That helps you classify Browser Access cases correctly instead of treating them like client-based access faults. The guide Zscaler support without admin rights shows the 360-degree view in detail.
Related terms
Frequently asked questions about Browser Access
Browser Access is a ZPA method that lets users reach internal web applications through an ordinary web browser without installing the Zscaler Client Connector. Access runs through a link to the application, secured in the background by the Zero Trust Exchange.
Browser Access suits external users such as partners, contractors or job applicants who have no managed device with an installed client, and individual web applications that do not need a full client.
Browser Access applies the same zero trust checks on identity and policy as client-based access, but it is limited to web applications and gives less visibility into device state, because no client runs on the endpoint.
Because Browser Access runs without a client, troubleshooting differs from client-based access. Device state is barely visible, and problems usually show up directly as link or access errors in the browser.
No. Browser Access suits web-based applications with standard HTTP/HTTPS access. Applications that use other protocols or need deep client integration still require full ZPA access through the Client Connector.
- Zscaler Help Portal: ZPA Browser Access - help.zscaler.com
- Internal guide: Zscaler support without admin rights
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.