What are URL Categories?
URL Categories are predefined or custom groups of web addresses that a security platform such as Zscaler Internet Access (ZIA) classifies automatically, for example social networking, cloud storage or malware hosting. Policies do not target individual domains but these categories: a rule such as “block cloud storage” automatically applies to every service captured in it, including ones added later. That keeps URL filtering maintainable, because nobody has to maintain thousands of individual domains. You can also create your own categories for company-specific exceptions or risk cases.
URL Categories in detail
ZIA maintains a continuously updated category database based on cloud threat data and automated crawling. Every requested URL is mapped to one or more categories in real time, before the policy engine decides whether to allow access, block it, or add a further check such as cloud sandboxing. Admins build their rules on these categories instead of on maintained domain lists.
A distinction is made between predefined standard categories in six classes (Bandwidth Loss, Business Use, General Surfing, Legal Liability, Productivity Loss, Privacy Risk) with super-categories and individual categories, and custom categories for special cases. One rule per super-category automatically covers every individual category within it, for less maintenance effort.
Why URL Categories matter in Zscaler operations
Without insight into the category logic, the helpdesk only sees “access blocked”, not why. Every follow-up question from employees then lands unnecessarily with Zscaler administration, even though the cause is often a single, clearly named category rule. That costs time on both sides and delays the first response on the ticket.
Categories are also an important signal source for shadow IT: unusual access patterns on categories such as cloud storage or collaboration tools show, from ZIA's perspective, which services are actually being used across the company, even when IT never officially approved them.
Common sources of error
- Outdated custom categories that nobody maintains any more and that by now contain wrong or dead domains.
- Categories set too broad block legitimate business tools and create unnecessary false positives.
- No documented override process: every exception ends up as an ad hoc ticket with administration.
- A helpdesk with no insight into category mapping cannot answer the user's “why is this blocked” question itself.
URL Categories in practice: what CentaurNexus contributes
Through User Support Center, CentaurNexus shows helpdesk roles which category a blocked page falls under and which rule applied in that specific case, with no Zscaler admin rights required. For maintenance, Category Forge adds to the diagnosis: it shows your own and predefined URL Categories, including quota, and lets you assign or remove individual URLs with a dry-run preview and Four-Eyes approval, each change made individually and traceably instead of as a bulk action. That answers the most common support question, why a page is blocked, on first contact, and sets the correction in motion cleanly. For how to maintain your own categories centrally, see the article Maintaining your own URL categories centrally.
Related terms
Frequently asked questions about URL Categories
Zscaler maintains predefined categories centrally through threat data and crawling, for example for cloud storage, adult content or malware hosting. Custom categories are created by the organisation itself, to group individual domains that predefined categories do not capture cleanly, such as internal exceptions or industry-specific services. Both category types can be combined in the same policy.
Zscaler maintains its category database continuously through cloud threat data and automated crawling of new domains. The exact update frequency and classification logic are internal to Zscaler and should be checked directly through Zscaler documentation if needed.
Because URL Categories are only one of several policy layers. SSL Inspection results, cloud sandbox findings, DLP rules or user-group-specific exceptions can also apply, for example. So an allowed category does not automatically guarantee access if another rule in the same rule set applies.
That depends on the internal process; usually it runs through a helpdesk ticket followed by a review from Zscaler administration. What matters is that the helpdesk can trace the reason for the block itself, instead of passing every request on to administration unchecked.
Conspicuous access to categories such as cloud storage or collaboration tools shows, from ZIA's perspective, which services are used across the company, even without IT ever officially introducing them. That provides indications of shadow IT, though it does not replace a dedicated discovery solution.
- Zscaler Help Portal: About URL Categories - help.zscaler.com/zia/about-url-categories
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.