Zscaler & Zero Trust operations glossary

Zscaler & Zero Trust operations glossary: 61 terms from A to Z

All the terms behind Zscaler operations, from products and traffic control to governance and sovereignty, explained compactly for helpdesk, administration and audit.

See the terms live in the live demo.Watch the live demo

Products & platform (14)

App ConnectorA software component of Zscaler Private Access that runs close to internal applications and only ever opens outbound connections to the ZPA cloud to broker access. Branch ConnectorA Zscaler component that connects traffic from devices at a location to the Zero Trust Exchange, including devices without Client Connector. Private Service EdgeA locally run Zscaler component that enforces policy closer to the customer site, for example to meet latency or sovereignty requirements. Privileged Remote Access (PRA)A clientless access service in Zscaler Private Access that lets users reach internal systems such as servers, jump hosts or desktops through a browser. ZDX (Zscaler Digital Experience)A Zero Trust Exchange service that measures the digital user experience across device, network and application, and provides it as a score plus deep tracing data. Zero Trust ExchangeZscaler’s cloud platform, the shared foundation for ZIA, ZPA, ZDX and ZIdentity; it inspects traffic inline according to the zero trust principle. ZIA (Zscaler Internet Access)A Zero Trust Exchange service that inspects internet and cloud access inline: firewall, URL filtering, SSL inspection, sandboxing and DLP in a single cloud service. ZIdentityZscaler’s identity service within the Zero Trust Exchange, which provides user and device identity for ZIA, ZPA and ZDX and connects to identity providers. ZPA (Zscaler Private Access)A Zero Trust Exchange service that secures access to private company applications through finely segmented app access instead of classic VPN tunnels. ZPA MicrotenantA delineated management area within a ZPA tenant, through which subsidiaries or departments manage their own app segments, connectors and policies independently, by delegation. Zscaler Client Connector (ZCC)The Zscaler platform’s endpoint agent, which authenticates users, forwards device traffic to ZIA and ZPA, and supplies telemetry for ZDX. Zscaler Experience CenterZscaler’s unified administration console, bringing together the management of internet and SaaS access, private access, digital experience monitoring and Client Connector under one interface and one sign-in. Zscaler OneAPIZscaler’s unified API access, through which configuration and operational data from services such as ZIA, ZPA and ZDX can be read and controlled programmatically. Zscaler tenantAn organisation’s isolated instance in the Zscaler cloud, with its own configuration, administrators, users, policies and separate data.

Access & traffic (16)

App SegmentAn App Segment bundles internal applications in Zscaler Private Access into a single access unit that users reach in a targeted way, not across the whole network. Browser AccessA ZPA access type where users reach internal web applications through an ordinary web browser, without having Zscaler Client Connector installed. Forwarding profileA configuration unit in Zscaler Client Connector that determines, based on the detected network location, whether and how device traffic is forwarded to the Zscaler cloud. Intermediate CA certificateThe certificate of an intermediate certificate authority that Zscaler uses to sign the dynamically issued inspection certificates during SSL/TLS inspection; it protects the root CA and must be installed as trusted on end devices. Kerberos authenticationA ticket-based authentication method that lets Zscaler identify users without a password prompt or browser interaction; it requires a Kerberos-capable PAC file, a realm trust, and synchronised system time. PAC fileA configuration file containing a JavaScript function that decides, for each destination URL, whether traffic goes direct or through which proxy. Posture profileA set of criteria defined in the Zscaler Client Connector Portal that a device must meet to count as trustworthy and be granted access. SAML authenticationA browser-based single sign-on method in which an identity provider confirms a user’s identity, and Zscaler uses that sign-in, along with the attributes it carries, for policy and assignment. SASEAn architecture model that bundles network functions such as SD-WAN with cloud-based security services such as Zero Trust access, firewall and web protection into a single cloud platform. Source IP Anchoring (SIPA)A Zscaler function that sends outbound internet traffic out through fixed IP address ranges assigned to the organisation, for destinations that use IP whitelisting. SSEA bundle of cloud-based security services, such as Zero Trust access, web protection, cloud firewall and data protection, forming the security part of a SASE architecture. SSL inspection bypassA deliberate exception that excludes certain applications or domains from SSL/TLS inspection, typically because they use certificate pinning and would drop the connection if it were decrypted. SSL/TLS inspectionA process in which encrypted traffic is decrypted at a trusted intermediary, checked for threats and data loss, and then re-encrypted. Surrogate IPA Zscaler service that maps an authenticated user to a private IP address, so that user-based policy also applies to traffic the service cannot authenticate directly. Z-Tunnel 2.0A modern tunnelling mechanism in Zscaler Client Connector that carries device traffic to the Zscaler cloud encrypted and broken down by application. ZTNAA security model that grants users access only to individual, approved applications rather than a whole network, checking identity and context on every access.

Experience & diagnostics (6)

Policy hygiene & operations (16)

Access Policy (ZPA)A rule set in Zscaler Private Access that decides, per user and device, which internal applications are reachable, following the principle of least privilege. Any-any ruleA firewall or access rule that covers all sources and all destinations at once, making it unusually broad and harder to reconcile with least privilege and traceability. Browser IsolationA security mechanism that renders risky web content in a separate cloud environment and shows the user only a safe image of the page. CASBA security layer between users and cloud services that makes SaaS usage, configuration and data flow visible, and applies policy to them. Cloud SandboxAn isolated cloud environment where unknown or suspicious files are run before delivery and checked for malicious behaviour. Configuration rollbackDeliberately resetting a configuration to an earlier, working state after a change has caused problems. Configuration snapshotA point-in-time snapshot of the configuration state, for example the Zscaler rule set, used as a restore point and comparison baseline before critical changes. DLPPolicies and technical controls meant to detect and prevent sensitive data leaving unintentionally or without authorisation. Four-eyes principleAn organisational control principle in which critical changes are reviewed and approved by a second person before taking effect, with a documented record of that approval. Policy conflictA policy conflict arises when security rules contradict or override one another, so a rule ends up behaving differently than intended. Policy driftThe gradual drift of a rule set away from its originally intended security state, through many individually traceable changes made without an ongoing overall view. Shadow ITIT systems, and cloud services in particular, that employees use without the IT department’s knowledge or approval, usually to get work done faster than through the official route. Shadowed rulesRules that never fire because an earlier-evaluated rule already covers their entire scope; a common, hard-to-spot defect in firewall and web gateway rule sets. Stale rulesOutdated or unused rules in a rule set that no longer serve any purpose, but add complexity, troubleshooting effort and security risk in operations. URL categoriesPredefined or custom groups of web addresses that Zscaler automatically classifies, so policies can build on categories instead of individual domains. Zscaler block pageThe notice page that the Zscaler service shows users when it blocks access to a website, file or application because of a policy or a faulty certificate.

Governance & sovereignty (9)

Audit trailComplete, chronological, tamper-proof logging of security-relevant actions that proves who made and approved which change, and when; the basis for evidencing compliance. Compliance evidenceDocumented, verifiable proof that a required security measure has been implemented and is working, mapped to requirements such as NIS2, DORA or ISO 27001. DORA in IT operationsThe ongoing operational implementation of the EU regulation DORA: traceable ICT risk management, verified access controls and robust logs in the financial sector. EU data sovereigntyThe ability to keep data and its processing fully under European law and your own control, from data residency to operational and audit data. Log pseudonymisationReplacing directly identifying details in log data, such as usernames or IP addresses, with pseudonyms so people can no longer be identified directly. Multi-tenancyA system’s ability to manage several independent tenants in strict separation, giving each tenant access only to its own data. NIS2 in IT operationsThe ongoing operational implementation of the EU directive NIS2: maintained access controls, traceable configuration and robust logs instead of one-off documentation. RBACA permissions model that ties access rights to roles rather than individual people; users gain rights through role assignment, which makes consistency, least privilege and traceability easier. User isolationQuickly containing a compromised user or device by cutting off access to the internet and internal applications, to limit damage.

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.