Zscaler & Zero Trust operations glossary ยท Access & traffic

What is Browser Access?

Definition

Browser Access is a ZPA (Zscaler Private Access) method that lets users reach internal web applications through an ordinary web browser, with no Zscaler Client Connector installed on the device. A link to the application is all it takes; the Zero Trust Exchange checks and secures the connection in the background. That makes Browser Access particularly useful wherever no managed device is available, for example for external partners or on personal devices.

Browser Access in detail

Technically, the web application is set up as an App Segment with a Browser Access configuration. Instead of direct network access, the user gets a dedicated, protected URL and reaches the application through it once authentication succeeds. Identity and policy are checked on every access, exactly as with client-based ZTNA access.

The main difference from classic ZPA access with Client Connector is reduced visibility into device posture. Without an installed client, Zscaler can tell you less about the accessing device than it can for a managed endpoint.

Why Browser Access matters in Zscaler operations

Browser Access connections work differently from client-based access at a technical level, so they need their own diagnostic logic. An access problem can sit in the App Segment configuration, in authentication, or in the user's browser, without the usual visibility into device state.

For support, that means distinguishing clearly between client-based and browser-based access before troubleshooting starts, so nobody chases a client problem for a client that was never installed.

Common sources of error

Browser Access in practice: what CentaurNexus contributes

CentaurNexus shows a user's access type through User Support Center, client-based or browser-based, together with the current policy status across ZIA, ZPA and ZDX in one view, and the helpdesk needs no Zscaler admin rights to see it. That helps you classify Browser Access cases correctly instead of treating them like client-based access faults. The guide Zscaler support without admin rights shows the 360-degree view in detail.

See in the live demo how User Support Center classifies access types like Browser Access.Watch the live demo

Related terms

Frequently asked questions about Browser Access

What is Browser Access in Zscaler?

Browser Access is a ZPA method that lets users reach internal web applications through an ordinary web browser without installing the Zscaler Client Connector. Access runs through a link to the application, secured in the background by the Zero Trust Exchange.

Who is Browser Access suitable for?

Browser Access suits external users such as partners, contractors or job applicants who have no managed device with an installed client, and individual web applications that do not need a full client.

Is Browser Access as secure as access through Client Connector?

Browser Access applies the same zero trust checks on identity and policy as client-based access, but it is limited to web applications and gives less visibility into device state, because no client runs on the endpoint.

Why Browser Access matters in Zscaler operations

Because Browser Access runs without a client, troubleshooting differs from client-based access. Device state is barely visible, and problems usually show up directly as link or access errors in the browser.

Can every application be delivered through Browser Access?

No. Browser Access suits web-based applications with standard HTTP/HTTPS access. Applications that use other protocols or need deep client integration still require full ZPA access through the Client Connector.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.