Skip to content
Notifications
Clear all

Is Zscaler ZPA worth the price? 24-month honest review from a 1000-user org

2 Posts
2 Users
0 Reactions
1 Views
(@grafana_guy_night)
Reputable Member
Joined: 4 months ago
Posts: 126
Topic starter   [#9740]

We've been running Zscaler Private Access for two years now, ~1000 users. Just renewed for another term, so I have some real data.

The good: Our attack surface shrank immediately. No more open VPN ports. The app segmentation is fantastic. We can give contractors access to one app and nothing else. The user experience is smoother than our old VPN – they just get a client and it works. The admin console is powerful, once you learn it.

The not-so-good: The price is… significant 😅. You're paying for the zero-trust model and the global backbone. The logging can be a beast. Had to build custom Grafana dashboards to make sense of it all. Here's a snippet of a query we use to track connection trends:

```promql
rate(zpa_audit_log_connections_total[5m]) * 60
```
We also found the initial policy setup complex. Took us a few tries to get the "least privilege" rules right without breaking things.

So, worth it? For us, yes – but only because we fully use the segmentation and have the budget. If you just need basic remote access, it might be overkill. Happy to share more details or dashboard configs!



   
Quote
(@consultant_carl_42_v2)
Estimable Member
Joined: 4 months ago
Posts: 115
 

I'm Carl, a consultant who's handled SaaS procurement for a few dozen mid-size companies. In my last full-time role at a 1500-user manufacturing firm, we ran ZPA in production for three years alongside ZIA before a consolidation project.

My comparison framework for this decision:

1. **Real Cost of Ownership**
The license is just the start. At my last shop, ZPA's enterprise agreement landed between $9-12 per user, per month, factoring in a 36-month commitment. The hidden operational cost was in log management. We had to pipe everything to a SIEM and dedicate about 20-25 hours of an engineer's time per month to maintain our dashboards and audit policies. If your team is lean, budget for this overhead.

2. **Setup & Policy Complexity**
Implementation isn't a light switch. For our ~100 applications, the initial policy build and testing phase took 11 weeks with a partner. The biggest gotcha was service accounts and non-interactive traffic; we had to create a separate, more permissive app segment for those, which added a layer of management. The "default deny" model is powerful, but the learning curve is real.

3. **Clear Win: Security Posture & Segmentation**
It's unmatched for precise access. We had a merger where we needed to integrate 200 contractors from the acquired company within a week. We stood up a new app segment tied to their identity provider, giving them access only to the two legacy ERP systems they needed. No network access, no lateral movement. That specific use case justified the annual cost alone.

4. **Where Alternatives Might Fit**
If your primary need is basic, user-to-network tunneling for a remote workforce, ZPA is over-engineered. We evaluated a split-tunnel VPN like Pritunl for a simpler user group and it was 70% cheaper. The trade-off is you lose the app-level control and the implicit zero-trust model; you're back to managing firewall rules and hoping your NAC works.

My pick is ZPA, but only if you're committed to using its core strength of micro-segmentation. If you have contractors, M&A activity, or a mix of legacy on-prem and cloud apps that need strict isolation, it's worth the premium. If your need is simply "remote access to the corporate LAN," tell us your team's size and the number of distinct applications you need to expose - the answer becomes much clearer.


null


   
ReplyQuote