What is ZPA (Zscaler Private Access)?
ZPA, Zscaler Private Access, is the Zero Trust Exchange service that secures access to private business applications, such as internal web apps, file shares or server applications in the data centre or in a private cloud. Instead of a VPN tunnel that places the user inside the whole network, ZPA connects user and application directly through finely segmented application access. Every access request is checked and approved individually, and the application itself stays invisible to the open internet. That significantly reduces the attack surface compared with classic network VPNs.
ZPA in detail
Technically, ZPA brokers the connection between the Client Connector on the user side and the App Connector on the application side; both build only outbound connections to the Zero Trust Exchange. That means no port into the data centre needs to be opened, and no application needs to be made publicly reachable. Access rights are granted through app segments, small, clearly bounded groups of applications, rather than blanket network access.
For browser-based applications, Zscaler also offers Browser Access, which works without an installed Client Connector. ZPA differs from ZIA in that it secures only private, company-owned targets, while ZIA governs outbound access.
Why ZPA matters in Zscaler operations
App segments decide, at a granular level, who can reach which internal application. When a segment, a role assignment or the state of an App Connector changes, that has an immediate effect on access problems that arrive as tickets at the helpdesk. Without its own view into ZPA status, it often stays unclear whether an application is not assigned, not reachable, or technically faulty.
For audits under NIS2 and DORA, ZPA also provides evidence that access to critical internal applications is controlled and logged at a granular level, rather than through a blanket network tunnel.
Common sources of error
- App segments that are too broad effectively cancel out the segmentation advantage over VPN.
- An App Connector in the wrong location leads to long detours and poor performance.
- Access policies and role assignments drift apart without anyone noticing.
- A lack of visibility for the helpdesk leads to unnecessary escalations to ZPA administrators.
ZPA in practice: what CentaurNexus contributes
CentaurNexus brings a user's ZPA access status together with ZIA and ZDX in one view through User Support Center: which app segments are assigned, whether an application is reachable, and how the App Connector on the way there is performing. That lets the helpdesk see, with no Zscaler admin rights of its own, whether an access problem sits with the assignment, the connector, or the network. Details on the 360-degree view across ZIA, ZPA and ZDX are covered in the guide Zscaler support without admin rights. How the case ZPA application unreachable plays out in day-to-day support, from the ticket, through the initial finding, to resolution, is described at Zscaler helpdesk support without admin rights.
Related terms
Frequently asked questions about ZPA
ZPA stands for Zscaler Private Access. It is the Zero Trust Exchange service that secures access to private business applications, such as internal web apps, file shares or server applications. Instead of a VPN tunnel into the whole network, every user gets access only to individual, predefined app segments.
A VPN places the user inside the network, which potentially opens paths to many systems. ZPA connects user and application directly through app segments, without the device ever becoming part of the internal network. The attack surface shrinks, because a compromised device can only reach the approved application, not the whole network.
The App Connector is the component that brokers ZPA traffic from the cloud to the target application in the data centre or in a private cloud, without the application needing to be reachable on the internet for this. It builds only outbound connections to the Zero Trust Exchange.
ZPA app segments decide, at a granular level, who can reach which internal application. When a segment or an assignment changes, that has a direct effect on access problems that land with the helpdesk. Without insight into ZPA status, it is hard to tell whether an application is unreachable, unassigned, or technically faulty.
For browser-based applications, Zscaler offers Browser Access, a form of access that works without an installed Client Connector and brokers access directly through the web browser. For most business applications, though, the Client Connector is still the one in use.
- Zscaler Help Portal: official documentation on Zscaler Private Access - help.zscaler.com
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.