Hey everyone, I'm new here and trying to wrap my head around ZTNA options. We're a retail chain with about 500 users across HQ and dozens of stores. Right now, everyone's on a clunky VPN to access inventory and HR systems, and it's a pain.
I keep hearing about Zscaler ZPA for "zero trust." For a setup like ours—mostly non-tech staff needing simple app access—is ZPA a good fit? I'm curious about real-world management overhead and if the per-user pricing gets crazy at our scale. Anyone in retail using it?
Still learning.
Hey user792, welcome. I'm a systems lead for a retail group with around 300 store staff plus HQ, and we replaced our old VPN with a ZTNA solution about a year ago to access our inventory and BI dashboards.
* **Pricing Reality:** ZPA's per-user cost is real. At your scale, list pricing tends to start around $12-15/user/month for annual commits. You'll want to budget for the "Secure Web Gateway" add-on if you need full internet filtering, which pushes it closer to $18-22/user/month. For 500 users, that's a big jump from a VPN appliance.
* **Management for Non-Tech Staff:** This is where ZPA does well for a retail chain. The user experience is just a client that auto-connects to approved apps. For your staff, it's a simple icon they click. Admin-side, setting up app segments for things like your inventory system is graphical and straightforward once it's integrated.
* **Deployment & Integration Effort:** The heavy lift is integrating your identity provider (like Azure AD or Okta) and defining your applications. For a dozen core systems, expect 2-3 weeks of focused work for an IT generalist to get it fully rolled out. The biggest time sink is testing each internal app's connectivity through the new model.
* **Where It Can Get Sticky:** It's very focused on *applications*, not full network access. If you have legacy systems that need raw SMB file share access or weird UDP protocols, you might need connectors or keep a limited VPN for those edge cases. Also, the monitoring dashboards are powerful but have a learning curve.
Given your scenario of 500 mostly non-tech users needing simple app access, ZPA is a strong technical fit. However, the pricing is its main hurdle. I'd recommend looking at it if your budget aligns, but also do a PoC with a competitor like Twingate or Cloudflare Zero Trust, which often come in at $5-9/user/month for core ZTNA features.
To make a clean call, tell us what your primary identity provider is (Azure AD, Google, etc.) and if you need to secure *only* specific web/apps or also require full internet filtering for all store traffic.
Data doesn't lie, but dashboards sometimes do.
Those integration timelines ring true. We went through a similar rollout last quarter. The identity provider sync is the easy part, honestly.
The real gotcha for us was legacy inventory apps that don't play nice with modern auth. We had a couple of on-prem systems that needed connector agents placed just right, and those took a solid week of tweaking firewall rules and DNS entries before the app segments worked reliably. Once it's done, it's solid, but that initial configuration can be a bear if you have any quirky internal stuff.
Did you run into that, or was your app stack all cloud/SaaS-based?
Ship fast, measure faster.
Oh, the legacy app dance. Been there, scowled at that. A whole week just to get some dusty inventory system on life support is exactly why the per-user pricing starts to feel like a joke.
You're not just paying for access, you're paying for the privilege of becoming a full-time shadow IT plumber for some vendor's forgotten code. And let's be honest, that "solid once it's done" state lasts until the next Java update or the server gets a patch Tuesday surprise.
Makes you wonder if the ROI math ever accounts for the admin sanity tax.
FOSS advocate
Zscaler's marketing push is something else, isn't it? The per-user pricing is the real kicker, and it's often buried until you're halfway through a sales call. At 500 users, you're looking at a six-figure annual bill before you even touch those legacy apps they'll inevitably need to connect.
It solves the VPN clunkiness by replacing it with budget clunkiness. For simple app access, there are lighter-weight brokers that don't require you to buy into their entire 'cloud firewall' universe.
Honestly, for a retail chain, the management overhead isn't in the client for staff, it's in re-architecting your network to feed Zscaler's cloud. That's the hidden cost they don't put on the datasheet.