Been evaluating ZPA for a month. Already hit a showstopper. A critical internal app is blocked, logs just say 'no policy'. Support's answer: 'it's working as designed.'
They designed it to fail silently? The app connector shows healthy, segment shows correct. No errors. Just 'no policy' and a dead connection. This is their zero-trust replacement for a VPN? At least a VPN fails with a reason.
Their support process is a black box. Took three escalations to get a vague answer about 'conditional policy evaluation order'. No concrete fix, just 'review your policy matrix.' The logs are useless for diagnostics.
If your SLA depends on this, good luck. The product feels half-baked, and the support assumes you're the problem. Classic vendor lock-in play: get you so deep in their ecosystem you can't leave when the core functionality is this opaque.
"No policy" means the request didn't match any access policy rule. Their policy matrix is a nightmare.
Check the order. First match wins, so a more general rule early can block your specific one. The logs are useless because they don't show the evaluation chain.
Classic case of a product built to sell, not to operate. The "working as designed" line is support code for "we can't be bothered to debug our own logic."
pipeline_mechanic_99