What is a Posture Profile?
A posture profile, or device posture profile, is a set of criteria defined in the Zscaler Client Connector Portal that a device must meet to count as trustworthy. Checks typically cover the operating system version, disk encryption, an active firewall, antivirus protection or a client certificate. The Zscaler Client Connector evaluates these conditions on the endpoint and reports the result to the cloud. Access policies in ZIA and ZPA use the profile as a criterion: a rule only applies as intended once the device state checks out. The posture profile therefore adds the question of device state to the question of identity.
Posture profile in detail
Zero trust checks not only who is accessing something, but also what they are accessing it with. The posture profile answers exactly that second question. In the Zscaler Client Connector Portal, the admin defines which conditions a device must meet, for example a current operating system version, encryption turned on, a running firewall, antivirus protection in place, a valid certificate, or domain membership. Device health from an endpoint protection product such as CrowdStrike can be factored in as well.
The check runs on the endpoint and is evaluated by the Client Connector. Trust levels let you grade the result instead of only distinguishing compliant from non-compliant. The profile then appears in the policy as a condition: in a ZPA access policy or a ZIA rule, it helps decide whether, and to what extent, access is granted.
Why posture profiles matter in Zscaler operations
A valid account on a poorly maintained device is a risk. To see how you can tell, in a single view, whether a failed access attempt is down to missing permissions or to device state, watch our video on the support cockpit. Posture profiles close this gap by tying access to a minimum device state: no access from a machine without encryption, without antivirus protection, or running an outdated operating system. That is a core building block of zero trust, and at the same time a tangible argument in audits, because device compliance can be evidenced as a precondition for access.
In day-to-day operations, though, posture profiles are also a common and easily overlooked source of trouble. When a user with the correct permissions still cannot reach an application, the cause is often not the access logic but the device state: an expired certificate, a disabled firewall, or a client that is not even running the check. Anyone who can look at identity and device state separately finds these silent blockers faster, without having to search through the entire rule set.
Common sources of error
- Posture as a silent blocker: access fails because of device state, but the search focuses on the access logic instead.
- Criteria set too strictly: an overly tight profile locks out legitimate devices, for example right after an operating system update.
- Client out of date: an outdated or inactive Client Connector does not evaluate the conditions cleanly.
- Certificates overlooked: once a certificate used for posture expires, the check silently tips over into blocking.
Posture profiles in practice: what CentaurNexus contributes
CentaurNexus displays posture profiles through Posture-Lens on a strictly read-only basis, so the helpdesk does not need a ZPA admin account. Combined with User Support Center, a failed access attempt can quickly be narrowed down to either missing permissions or a device that fails a posture criterion. Because the view stays read-only, first-line support cannot change the configuration, but can name the cause and hand the ticket on with the right context. For how this 360-degree view across ZIA, ZPA and ZDX works, see Zscaler support without admin rights.
Related terms
Frequently asked questions about posture profiles
Device posture profiles are created and managed centrally in the Zscaler Client Connector Portal. From there, they are available as a criterion to both ZIA and ZPA policies. The Zscaler Client Connector on the endpoint checks the stored conditions and reports the result back to the cloud.
Typical checks cover the operating system and its version, disk encryption, an active firewall, antivirus protection in place, a client certificate, or domain membership. Device health from an endpoint protection product such as CrowdStrike can be factored in as well. Which criteria make sense depends on how much protection the relevant application needs.
A posture profile is a criterion inside ZIA or ZPA access rules. If a device does not meet the required profile, the rule does not apply the way it is meant to. Trust levels let you grade access: a fully compliant device gets more than one that is only partly compliant.
Because the device does not meet a required criterion, for example missing encryption, an expired certificate, or antivirus protection that is not active. Access is then correctly denied even though the user and their permissions are fine. That is why, when troubleshooting, it matters to look at identity and device state separately.
A trust level summarises how well a device meets the posture criteria. Policies can attach graduated decisions to it, instead of only distinguishing between allowed and blocked. A fully compliant device therefore gets broader access than one that only meets the minimum requirements.
- Zscaler Help Portal: Configuring Device Posture Profiles - help.zscaler.com
- Zscaler Help Portal: Configuring Device Posture Profiles for ZPA - help.zscaler.com
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.