Zscaler & Zero Trust operations glossary · Policy hygiene & operations

What is Cloud Sandbox?

Definition

Cloud Sandbox is an isolated cloud environment where unknown or suspicious files run and get checked for malicious behaviour before they reach the user. Instead of only matching known malware signatures, the sandbox watches what a file actually does: does it try to encrypt other files, escalate system privileges, or connect to suspicious servers? Only after this behavioural check does policy decide whether the file gets delivered, blocked or isolated. That makes sandboxing effective against threats that have no known signature yet.

Cloud Sandbox in detail

In the ZIA architecture, the sandbox check runs inline in the data stream. Before a file reaches the user, a first stage checks known threat patterns; unknown or suspicious files also run in the isolated environment and get analysed by behaviour. The results feed into the policy decision on whether delivery goes ahead.

Cloud Sandbox is worth distinguishing from Browser Isolation. Sandboxing checks files before delivery, while Browser Isolation renders risky web content in a separate environment and sends only a safe image to the endpoint. The two mechanisms complement each other but address different attack paths.

Why Cloud Sandbox matters in Zscaler operations

Sandboxing is one of the functions included in many Zscaler licences but not switched on everywhere. Left unused, a paid protection mechanism sits idle, and the company stays more exposed to unknown malware than the licence actually allows for.

For operations, traceability matters too. When a sandbox decision blocks a file, the helpdesk needs to be able to explain why, without pulling in Zscaler administration every time.

Common sources of error

Cloud Sandbox in practice: what CentaurNexus contributes

As part of the licence health check, Policy Health Saga shows whether Cloud Sandbox is actively configured and how far the licence you hold is actually being used, instead of leaving paid protection unused. The score makes visible where tightening things up brings the biggest security gain. More on getting full value from your licence in the guide Getting more from your Zscaler licence.

See in the live demo how the licence health check uncovers unused protection features.Watch the live demo

Cloud Sandbox in operation: how to spot it

Sandbox tickets almost always come down to time. Either the user is waiting, or the file was already there before the verdict came in. Three distinctions resolve most cases.

“The file got through even though it was malicious.”

What it usually is: The key question is whether the file was already known. A known pattern gets judged immediately; an unknown one has to run first.

How you tell them apart: How the system handles the first run of an unknown pattern is a setting, not a property of the sandbox itself. That is exactly where it gets decided whether someone waits or the file gets delivered upfront.

“The user has been waiting minutes for the download.”

What it usually is: The verdict is still pending. That is by design and the safer path, but it needs explaining to the user, or they will find another way to get the file.

How you tell them apart: The wait is not a fault. A clear explanation to the user prevents the workaround that defeats the check.

“The sandbox says clean, our antivirus doesn't.”

What it usually is: Two different checks with different criteria. A behavioural analysis in a shielded environment and a signature-based check on the device can come to different conclusions without either one being wrong.

How you tell them apart: Both findings belong side by side in the case, not against each other. The contradiction is itself the information.

“Files from development keep getting held back.”

What it usually is: A recurring conflict between scanning and development work that individual exceptions rarely resolve well.

How you tell them apart: Sandbox Clear addresses this with a time-limited approval path for development and test environments, instead of creating a permanent exception.

Known or unknown, wait or deliver upfront, behaviour or signature: these three axes explain almost every sandbox ticket before anyone looks at the file itself.

Related terms

Frequently asked questions about Cloud Sandbox

How does Cloud Sandbox differ from classic antivirus?

Classic antivirus mostly compares files against known signatures. A Cloud Sandbox instead actually runs an unknown file in an isolated environment and observes its behaviour, for example whether it tries to encrypt files or connect to suspicious servers. That also catches new threats that have not been catalogued yet.

Does sandboxing delay file access for users?

That depends on the policy mode you choose. Under “Allow and Scan”, the file may be downloaded immediately while the sandbox analyses it in the background; if it later classifies the file as malicious, the service triggers its own alert for that. Under “Quarantine”, the file is only released once analysis is complete. AI-assisted instant scoring can already block clearly malicious files before the full behavioural analysis finishes.

Does every file go through the sandbox?

Usually only files that initial checks flag as unknown or potentially risky, not all traffic. The policy in place decides which file types and categories are included.

Is Cloud Sandbox included in every Zscaler licence?

No. According to Zscaler, rule-based sandbox policy with the full feature set requires its own licence tier (currently called “Advanced Sandbox”); the exact scope of ZIA licence packages can change and should be checked in your own contract. Whether a licence actually has sandboxing switched on can be confirmed with a configuration check.

What happens when the sandbox classifies a file as malicious?

The file is not delivered to the user, policy blocks delivery, and the incident gets logged. The exact follow-up steps, such as notification or quarantine, depend on the policy configured.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.