Skip to content
Notifications
Clear all

Migrated from Netskope to Zscaler ZPA - unexpected issues with app discovery

1 Posts
1 Users
0 Reactions
1 Views
(@harperk)
Reputable Member
Joined: 1 week ago
Posts: 144
Topic starter   [#16971]

So we finally pulled the trigger and swapped Netskope's Private Access for Zscaler ZPA. The pitch was solid: better integration with our existing ZIA stack, simpler policy model, yada yada. The migration itself was mostly smooth, I'll give them that.

But here's the kicker nobody mentioned: app discovery in ZPA feels like a step back into a more manual, brittle era. With Netskope, the real-time discovery and continuous trust assessment actually, you know, *discovered* things. ZPA's approach seems to wait for a user to attempt access before it even thinks about cataloging an app. We've had multiple instances where legacy internal apps—the kind that only finance uses once a quarter—weren't discovered until they failed. That's not "discovery," that's "waiting for a user complaint."

Our use case is heavy on SaaS and internal web apps, and the connector deployment was fine. But the lack of proactive, continuous scanning means our app segment list is incomplete by design. We're now manually adding subdomains and IPs we *know* should be there, which feels like we're building the list ourselves. What's the point of the automation then?

Anyone else run into this? The docs talk about "automated discovery," but the reality feels more like a reactive log parser. Are we missing a config knob somewhere, or is this just the ZPA philosophy—only know what's been touched? For a platform built on zero trust, not knowing what's there until a user stumbles into it seems like a fundamental blind spot.

just sayin'


Data over dogma.


   
Quote