What is ZTNA?
ZTNA (Zero Trust Network Access) is a security model that gives users access not to an entire network, but only to individual, explicitly authorized applications. Identity and device context are checked on every access, not just once at login the way a classic VPN works. The application itself stays invisible on the internet; only authorized connections through the Zero Trust Exchange get through. ZTNA is therefore the replacement for network-wide VPN access and a core building block of modern access architectures such as SSE and SASE.
ZTNA in detail
Technically, Zscaler implements ZTNA through ZPA (Zscaler Private Access). Applications are grouped into app segments, and App Connectors establish the connection to the application without an inbound port ever having to open on the internet. Users only get access to the app segments they have been explicitly assigned to.
Unlike with a VPN, this creates no flat network segment that a compromised device could roam freely inside. Every connection is authorized individually and can be traced individually.
Why ZTNA matters in Zscaler operations
For day-to-day operations, ZTNA means that access problems rarely sit with the network itself, but often with segment assignment: a user simply has not been authorized for an application, or a policy change has removed access. Without visibility into app segments and assignments, support has no option but to escalate to administration.
ZTNA-related access requests pile up especially during rollouts of new applications or reorganisations, and the right diagnostic view clears them noticeably faster.
Common sources of error
- A user is not assigned to new app segments in time after switching teams.
- App Connector availability gets mistaken for a general ZTNA outage.
- No distinction is made between access denied because of policy and access denied because of a technical fault.
- Device state fails to meet access requirements, without this being shown to the user in an understandable way.
ZTNA in practice: what CentaurNexus contributes
CentaurNexus uses User Support Center to show a user's access status across ZIA, ZPA and ZDX in one view, with no Zscaler admin rights at all. That makes it quick to see whether a ZTNA access denial comes down to app segment assignment, device state or another cause, instead of passing every case on to administration. The guide below describes exactly how this 360-degree view of Zscaler works without admin rights: Zscaler support without admin rights.
ZTNA in operation: how to spot it
The definition tells you what ZTNA is. A ticket rarely says 'ZTNA is not working'; it says 'the application does not work'. Four phrasings almost always narrow down the cause before anyone needs to escalate.
'It does not work for me, but it works for my colleague.'
What it usually is: Almost always the assignment, not the technology. If the application works for others, the App Connector and the application itself are fine; what differs is segment or group membership.
How to tell: Look at the user's groups and assigned app segments. User Support Center shows both alongside device and connection, with no need for 1st Level to have admin rights.
'It worked yesterday.'
What it usually is: A change, not an outage. Either group membership has changed, or an access rule has been adjusted.
How to tell: The question is not 'is something broken', but 'what changed'. Access Review Desk routes the case, with an initial finding and the requested action, to the role responsible, instead of treating it as an incident.
'It does not work from home, but it works in the office.'
What it usually is: Usually the device state or trusted-network detection. The access condition is met as long as the device sits on a known network, and falls away outside it.
How to tell: Look at device state and network context together. Connectivity Triage Map combines user, device, ZIA, ZPA and ZDX signals into one picture, instead of opening three views one after another.
'The application loads, but agonisingly slowly.'
What it usually is: That is not an access problem. Access is binary: either the connection comes up or it does not. Slowness points to the path, not to the authorization.
How to tell: This is where ZTNA parts ways with the performance question. The path from the endpoint, over Wi-Fi and the ISP, to the App Connector needs measuring, not the policy checking.
The difference between these four cases decides whether a ticket stays at 1st Level or gets escalated. It can be settled in minutes once assignment, device and path are visible side by side.
Related terms
Frequently asked questions about ZTNA
ZTNA stands for Zero Trust Network Access. Instead of giving users access to an entire network segment the way a classic VPN does, ZTNA grants access only to individual, explicitly authorized applications. Identity and device context are checked on every access, not just once at login.
A VPN effectively places the device inside the corporate network, which potentially opens access to many systems at once. ZTNA only opens the path to one specific, authorized application. That reduces the attack surface significantly, because a compromised device does not automatically reach the entire network.
Zscaler implements ZTNA through ZPA (Zscaler Private Access): applications are defined in app segments, and users get access tailored to them through the Zero Trust Exchange, without the application itself ever having to be exposed on the internet.
Anyone diagnosing access problems needs to understand whether a user has even been authorized for an app segment in the first place. Without that visibility, ZTNA-related access denials quickly end up as an unclear 'it does not work' with 1st Level, which can barely help without context.
No. ZTNA is one of the access capabilities bundled within an SSE or SASE architecture. SSE brings together several cloud-based security services, and SASE adds networking functions on top. ZTNA is one building block of that, not a substitute for the overall concept.
- Zscaler Help Portal: ZPA and Zero Trust Network Access - help.zscaler.com
- In-house guide: Zscaler support without admin rights
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.