In our ongoing FinOps review of security service expenditures, my team conducted a detailed feature-utilization analysis of our Zscaler Private Access (ZPA), Internet Access (ZIA), and Digital Experience (ZDX) subscriptions over the last fiscal quarter. The objective was to correlate our actual usage patterns with the licensed feature sets, identifying areas of both high value and potential waste. The findings, summarized in the table below, reveal significant discrepancies between deployed capabilities and operational necessities.
Our methodology involved parsing API logs, admin console configuration snapshots, and conducting interviews with platform engineering and security teams. We categorized features as "Core-Used," "Enabled-Not-Optimized," or "Licensed-Unused."
| Product | Tier | Core-Used Features | Licensed-Unused / Underutilized Features | Estimated Cost Impact |
| :--- | :--- | :--- | :--- | :--- |
| **ZIA** | Business | • SSL Inspection
• Cloud Firewall (Standard Policies)
• Cloud Sandbox
• URL Filtering (Cats: Malware, Phishing) | • Advanced Cloud Firewall (App-Specific rules)
• DNS Security (beyond base)
• URL Filtering (Full 100+ categories)
• Bandwidth Control (not configured) | High. ~40% of licensed URL categories had <5 hits. |
| **ZPA** | Business | • App Connectors for on-prem apps
• Browser Access
• Basic Device Posture | • IdP Integration (beyond one)
• Advanced Inline Inspection (not configured)
• Multiple DNS/VPN options (using one) | Medium. Unused IdP slots and inspection profiles represent stranded capacity. |
| **ZDX** | Professional | • Synthetic Tests (Critical Apps)
• Experience Scores Dashboards | • Custom Synthetic Locations (using only 3 of 10)
• Advanced Root-Cause Analysis modules
• Full API access for automation | Low-Medium. Custom location surplus is a clear reservation-like over-provision. |
**Key Observations and Optimization Strategies:**
* **Feature Bundling Creates Waste:** The ZIA Business tier bundles numerous URL filtering categories. Our traffic analysis shows we consistently use only ~60 categories for enforcement. The remainder incur a licensing cost without providing measurable risk reduction. A conversation with our account team is required to explore custom bundling.
* **Reservation Model for ZDX:** The unused synthetic locations in ZDX function similarly to unused reserved instances. We are over-provisioned for peak testing scenarios that never materialize. The strategy is to:
* Reduce committed custom locations from 10 to 5.
* Utilize on-demand locations for temporary, seasonal testing needs.
* **Configuration Debt in ZPA:** The "Enabled-Not-Optimized" features, like Advanced Inline Inspection, are configured but with default or overly permissive policies. This represents a security and cost gap—we pay for the capability but derive no value. The action item is to either deactivate these modules or develop specific, stringent policies to justify their cost.
**Proposed Action Plan:**
1. Initiate contract renegotiation focusing on unbundling ZIA URL categories.
2. Right-size ZDX synthetic location commitment at next renewal.
3. Conduct a 60-day "feature audit" for ZPA to either fully implement or remove advanced modules, aligning configuration with license spend.
This exercise underscores a principle common in cloud cost optimization: purchased capacity must be matched by active configuration and consumption. Visibility, through granular logging and inventory, is the first step toward control.
-cc
every dollar counts