Zscaler & Zero Trust operations glossary · Policy hygiene & operations

What are URL Categories?

Definition

URL Categories are predefined or custom groups of web addresses that a security platform such as Zscaler Internet Access (ZIA) classifies automatically, for example social networking, cloud storage or malware hosting. Policies do not target individual domains but these categories: a rule such as “block cloud storage” automatically applies to every service captured in it, including ones added later. That keeps URL filtering maintainable, because nobody has to maintain thousands of individual domains. You can also create your own categories for company-specific exceptions or risk cases.

URL Categories in detail

ZIA maintains a continuously updated category database based on cloud threat data and automated crawling. Every requested URL is mapped to one or more categories in real time, before the policy engine decides whether to allow access, block it, or add a further check such as cloud sandboxing. Admins build their rules on these categories instead of on maintained domain lists.

A distinction is made between predefined standard categories in six classes (Bandwidth Loss, Business Use, General Surfing, Legal Liability, Productivity Loss, Privacy Risk) with super-categories and individual categories, and custom categories for special cases. One rule per super-category automatically covers every individual category within it, for less maintenance effort.

Why URL Categories matter in Zscaler operations

Without insight into the category logic, the helpdesk only sees “access blocked”, not why. Every follow-up question from employees then lands unnecessarily with Zscaler administration, even though the cause is often a single, clearly named category rule. That costs time on both sides and delays the first response on the ticket.

Categories are also an important signal source for shadow IT: unusual access patterns on categories such as cloud storage or collaboration tools show, from ZIA's perspective, which services are actually being used across the company, even when IT never officially approved them.

Common sources of error

URL Categories in practice: what CentaurNexus contributes

Through User Support Center, CentaurNexus shows helpdesk roles which category a blocked page falls under and which rule applied in that specific case, with no Zscaler admin rights required. For maintenance, Category Forge adds to the diagnosis: it shows your own and predefined URL Categories, including quota, and lets you assign or remove individual URLs with a dry-run preview and Four-Eyes approval, each change made individually and traceably instead of as a bulk action. That answers the most common support question, why a page is blocked, on first contact, and sets the correction in motion cleanly. For how to maintain your own categories centrally, see the article Maintaining your own URL categories centrally.

Watch the live demo to see how helpdesk teams trace block reasons themselves.Watch the live demo

Related terms

Frequently asked questions about URL Categories

What is the difference between predefined and custom URL Categories?

Zscaler maintains predefined categories centrally through threat data and crawling, for example for cloud storage, adult content or malware hosting. Custom categories are created by the organisation itself, to group individual domains that predefined categories do not capture cleanly, such as internal exceptions or industry-specific services. Both category types can be combined in the same policy.

How current are URL Categories?

Zscaler maintains its category database continuously through cloud threat data and automated crawling of new domains. The exact update frequency and classification logic are internal to Zscaler and should be checked directly through Zscaler documentation if needed.

Why is a page blocked despite an allowed category?

Because URL Categories are only one of several policy layers. SSL Inspection results, cloud sandbox findings, DLP rules or user-group-specific exceptions can also apply, for example. So an allowed category does not automatically guarantee access if another rule in the same rule set applies.

Can employees request access themselves?

That depends on the internal process; usually it runs through a helpdesk ticket followed by a review from Zscaler administration. What matters is that the helpdesk can trace the reason for the block itself, instead of passing every request on to administration unchecked.

How are URL Categories and shadow IT connected?

Conspicuous access to categories such as cloud storage or collaboration tools shows, from ZIA's perspective, which services are used across the company, even without IT ever officially introducing them. That provides indications of shadow IT, though it does not replace a dedicated discovery solution.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.