Zscaler & Zero Trust operations glossary ยท Products & platform

What is ZPA (Zscaler Private Access)?

Definition

ZPA, Zscaler Private Access, is the Zero Trust Exchange service that secures access to private business applications, such as internal web apps, file shares or server applications in the data centre or in a private cloud. Instead of a VPN tunnel that places the user inside the whole network, ZPA connects user and application directly through finely segmented application access. Every access request is checked and approved individually, and the application itself stays invisible to the open internet. That significantly reduces the attack surface compared with classic network VPNs.

ZPA in detail

Technically, ZPA brokers the connection between the Client Connector on the user side and the App Connector on the application side; both build only outbound connections to the Zero Trust Exchange. That means no port into the data centre needs to be opened, and no application needs to be made publicly reachable. Access rights are granted through app segments, small, clearly bounded groups of applications, rather than blanket network access.

For browser-based applications, Zscaler also offers Browser Access, which works without an installed Client Connector. ZPA differs from ZIA in that it secures only private, company-owned targets, while ZIA governs outbound access.

Why ZPA matters in Zscaler operations

App segments decide, at a granular level, who can reach which internal application. When a segment, a role assignment or the state of an App Connector changes, that has an immediate effect on access problems that arrive as tickets at the helpdesk. Without its own view into ZPA status, it often stays unclear whether an application is not assigned, not reachable, or technically faulty.

For audits under NIS2 and DORA, ZPA also provides evidence that access to critical internal applications is controlled and logged at a granular level, rather than through a blanket network tunnel.

Common sources of error

ZPA in practice: what CentaurNexus contributes

CentaurNexus brings a user's ZPA access status together with ZIA and ZDX in one view through User Support Center: which app segments are assigned, whether an application is reachable, and how the App Connector on the way there is performing. That lets the helpdesk see, with no Zscaler admin rights of its own, whether an access problem sits with the assignment, the connector, or the network. Details on the 360-degree view across ZIA, ZPA and ZDX are covered in the guide Zscaler support without admin rights. How the case ZPA application unreachable plays out in day-to-day support, from the ticket, through the initial finding, to resolution, is described at Zscaler helpdesk support without admin rights.

Watch the live demo to see how ZPA access status becomes visible per user.Watch the live demo

Related terms

Frequently asked questions about ZPA

What does ZPA stand for?

ZPA stands for Zscaler Private Access. It is the Zero Trust Exchange service that secures access to private business applications, such as internal web apps, file shares or server applications. Instead of a VPN tunnel into the whole network, every user gets access only to individual, predefined app segments.

Why does ZPA replace a VPN?

A VPN places the user inside the network, which potentially opens paths to many systems. ZPA connects user and application directly through app segments, without the device ever becoming part of the internal network. The attack surface shrinks, because a compromised device can only reach the approved application, not the whole network.

What is an App Connector in the context of ZPA?

The App Connector is the component that brokers ZPA traffic from the cloud to the target application in the data centre or in a private cloud, without the application needing to be reachable on the internet for this. It builds only outbound connections to the Zero Trust Exchange.

Why ZPA matters in Zscaler operations

ZPA app segments decide, at a granular level, who can reach which internal application. When a segment or an assignment changes, that has a direct effect on access problems that land with the helpdesk. Without insight into ZPA status, it is hard to tell whether an application is unreachable, unassigned, or technically faulty.

Does ZPA also work without the Client Connector, in the browser?

For browser-based applications, Zscaler offers Browser Access, a form of access that works without an installed Client Connector and brokers access directly through the web browser. For most business applications, though, the Client Connector is still the one in use.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.