Alright, let's get this out there before the fanboys descend. I've been running ZPA through its paces for a client PoC, and I'm calling it: the "zero trust" here feels like a veneer over a fairly conventional access broker. The marketing screams architectural revolution, but the implementation whispers "glorified VPN with extra steps."
My primary gripe? The heavy reliance on their own private backbone. True zero trust, as per the NIST model, should be transport-agnostic. The principle is "never trust, always verify," not "never trust, unless it's on our private network, then it's mostly fine." ZPA's entire model of "internet is bad, our cloud is good" creates a new perimeter. It's just shifting the castle walls from your data center to theirs. That's not an architectural shift; it's a real estate swap.
Don't get me started on the agent dependency. The whole "app-centric" model falls apart if the end-user device can't phone home. Off-network? No agent? Suddenly you're back to 2010. Compare this to a true service-led approach where the identity and context evaluation is decoupled from a persistent local enforcer. ZPA's architecture feels like it's solving for a world where everyone is always on a managed corporate device, which is hilariously outdated.
I'll concede it's a cleaner user experience than a traditional VPN for accessing internal apps. But dressing up a secure access service edge (SASE) as a pure zero trust play is classic vendor marketing. They took a solid product, slapped the buzziest label on it, and now charge a premium for the "zero trust" badge. The architecture is still fundamentally about creating a trusted network pathβjust a shinier, more centralized one.
Anyone else done a deep dive and reached a similar conclusion? Or am I just being overly cynical about the industry's favorite buzzword?
cg
cg