Zscaler & Zero Trust operations glossary ยท Products & platform

What is Privileged Remote Access (PRA)?

Definition

Privileged Remote Access (PRA) is a clientless access service from Zscaler Private Access that lets users reach internal systems, such as servers, jump hosts or desktops, straight from a browser. It supports the RDP, SSH, VNC and RealVNC protocols, with no installed Zscaler Client Connector and no browser plugin required. The administrator can provide credentials and feed them into the session instead of handing them to users directly. Sessions can be recorded and traced through audit logs. PRA is built for privileged access to critical IT and OT systems, particularly for service providers and external partners who bring no managed device.

Privileged Remote Access in detail

PRA builds on ZPA's access logic and inherits its zero trust principle: target systems are never openly reachable from the internet, only through a session that has been explicitly approved and verified. The user signs in at an access portal and opens the target system's console directly in the browser. According to the documentation, RDP, SSH, VNC and RealVNC are available as protocols, complemented by features such as file transfer, clipboard and an on-screen keyboard.

The difference from a classic jump server lies in the control over credentials and sessions. Privileged login credentials can be fed into the session without ever exposing them to the user; alternatively, the user enters their own credentials. If session recording is active, every privileged session is captured as evidence and tied to a specific user. Access Policy and the posture profile still apply to the access itself.

Why Privileged Remote Access matters in Zscaler operations

Privileged access is the path attackers like best: high-level rights, often granted too broadly, rarely logged without gaps. The classic setup of VPN plus jump server opens up network access for this and hands out privileged passwords. PRA turns that around: no client, no open network access, just a browser-based session to exactly one target system, with controlled credentials. That fits particularly well for external service providers and for OT environments where you cannot roll out a managed device.

For evidence under NIS2 or DORA, session recording together with audit logs matters most. Anyone who has to prove who worked on a critical system, when, and with which rights has a solid basis in logged, recorded sessions. In daily operations, that adds another layer the helpdesk and security teams should keep an eye on: alongside ZIA, ZPA and ZDX, privileged sessions become an access channel of their own.

Common sources of error

Privileged Remote Access in practice: what CentaurNexus contributes

CentaurNexus uses Unified Support Center to bring together the extended 360-degree view of a user, including PRA sessions alongside status from ZIA, ZPA and ZDX. That lets the helpdesk see on one page whether and how a user has used privileged sessions, without needing a Zscaler admin account to look into it. The view stays read-only, so it changes nothing about access or recording, but it makes privileged access traceable in daily work. For how this 360-degree approach works without admin rights, see Zscaler support without admin rights.

Watch the live demo to see how privileged sessions show up in the 360-degree view of a user.Watch the live demo

Related terms

Frequently asked questions about Privileged Remote Access

What is the difference between PRA and ZPA?

ZPA is the overarching zero trust platform for private application access. Privileged Remote Access is a capability within it that specifically provides browser-based privileged access to servers, jump hosts and desktops. PRA uses ZPA's access logic but adds credential management and session recording for critical systems.

Which protocols does Privileged Remote Access support?

According to Zscaler's documentation, PRA supports the common remote access protocols RDP, SSH, VNC and RealVNC. That covers Windows desktops and servers, Linux systems over SSH, and other consoles. Access runs entirely in the browser, with no extra software to install on the client.

Does Privileged Remote Access need the Zscaler Client Connector?

No. PRA is clientless access: the user opens the privileged session in a modern browser, with no Zscaler Client Connector and no browser plugin. That is particularly practical for service providers, external partners, and rotating OT or IT administrators who do not bring a managed device.

How are credentials handled in PRA?

According to the documentation, the administrator can either provide configured credentials or prompt the user to enter their own. In the guided variant, login credentials are fed into the session without ever being exposed to the user. That keeps access possible without distributing privileged passwords widely.

Can PRA sessions be recorded?

Yes. If session recording is enabled, the user sees a notice about the recording during the privileged session. The recording serves as evidence and ties every action to a specific user. Together with audit logs, that creates a solid basis for evidence.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.