Skip to content
Notifications
Clear all

Step-by-step: Isolating a compromised device segment in ZPA in under 5 minutes.

1 Posts
1 Users
0 Reactions
0 Views
(@emmap)
Trusted Member
Joined: 4 days ago
Posts: 27
Topic starter   [#17547]

We had a scary moment last week—an alert from our EDR that a contractor's laptop had beaconing activity. The immediate question from our security team: "Can we isolate this device type from all internal apps *right now*?" The answer was yes, and we did it in under five minutes using ZPA's segment-based policies.

Here's the exact workflow we followed. The key is having your ZPA App Segments and Browser Access policies already structured by risk level, which is a best practice anyway.

1. **Identify the Device Segment:** In the ZPA Admin Portal, we went to **Administration > Device Posture > Device Segments**. We already had a segment for "Contractor-Managed Windows" based on the MDM attribute. If you don't have one, you can create a new segment on the fly using any posture attribute (OS, managed/unmanaged, disk encryption status, etc.).
2. **Create or Update the Access Policy:** We navigated to **Policy > Access Policy > Browser Access**. We already had a policy rule for "Contractor Low Trust Access" that granted limited app access to that device segment.
3. **Change the Rule Action to 'Block':** This was the one-minute fix. We simply edited that existing policy rule and changed the action from **Allow** to **Block**. We placed this new block rule *above* any other rules that might grant them access. The order is crucial.
4. **Verify & Test:** We had the contractor try to access an internal wiki (a low-risk app in the affected segment). Connection was immediately denied. Their access to public internet (via ZIA) was unaffected, so they could still work on non-corporate resources while we remediated.

The beauty was the granular control. We didn't block the user, their department, or the entire app. We blocked a specific *type of device* from all private apps behind ZPA. Once the laptop was cleaned and re-imaged, we switched the rule back to Allow.

Has anyone else used Device Segments for rapid isolation? I'm curious if you've set up proactive "Quarantine" segments for scenarios like this—I'm drafting a playbook for our team now.

—Emma



   
Quote