Skip to content
Notifications
Clear all

Anyone actually using Zscaler ZPA in production for sensitive data?

1 Posts
1 Users
0 Reactions
0 Views
(@gracec)
Estimable Member
Joined: 3 weeks ago
Posts: 121
Topic starter   [#23299]

Hello everyone,

I've been spending a lot of time lately evaluating zero-trust network access (ZTNA) solutions for our internal projects, particularly for teams that handle financial and PII data. Zscaler ZPA consistently comes up in conversations and vendor shortlists, but I'm keen to move beyond the sales demos and high-level whitepapers. I'm looking for real-world, production experiences.

Specifically, I'd love to hear from anyone who has rolled out ZPA to secure access to applications containing sensitive data. My team is deep in the weeds of Jira and Asana workflow design, so we think a lot about how a tool integrates into daily user habits and security postures.

Could you share your experiences on a few practical points?

* **User Experience & Adoption:** Was the shift from a traditional VPN transparent for your non-technical teams (like finance or HR accessing their systems)? Any major workflow disruptions or training hurdles?
* **Performance with Sensitive Data:** For applications dealing with large datasets or real-time transactions, did you notice any latency introduced by ZPA's brokering? We're especially concerned about internal database tools and reporting platforms.
* **Policy Granularity & Management:** How fine-grained have you been able to get with access policies? For example, can you realistically set policies like "Contractors can only access this one specific application server on port 8443 from these approved devices, and only during business hours" without it becoming an administrative nightmare?
* **The Coexistence Phase:** Most organizations don't flip a switch. Did you run ZPA alongside a legacy VPN during a transition period? If so, how did you handle the overlap and eventual decommissioning?
* **Unexpected Costs or Pitfalls:** Beyond the listed licensing, were there hidden costs in terms of additional staffing (security or networking teams), necessary infrastructure changes, or third-party integration work to make it function as needed?

I'm particularly interested in the day-to-day project management of such a rollout. What were the major phases? What would you do differently?

Any insights, even if they're just on one of these bullet points, would be incredibly valuable for us and likely for others in the community who are on a similar evaluation path.

grace


The right tool saves a thousand meetings.


   
Quote