Hi everyone, I'm new here but have been reading the forum for a while. I'm leading a project to evaluate and potentially implement a cloud proxy/SASE solution, and Zscaler Internet Access (ZIA) is a top contender. I've been digging into operational impacts, and I came across a statistic that really gave me pause.
A peer at another company mentioned that after they moved from a more passive monitoring stance to enforcing strict ZIA policies (things like full SSL inspection, strict application control for non-business categories, and blocking all uncategorized sites), their help desk ticket volume related to web access increased by 300% in the first month. It supposedly stayed elevated by about 150% even after the initial shock.
This has become a major concern for my TCO and rollout timeline models. I'm trying to understand the real-world operational friction here. My questions are:
* **Policy Rollout:** Was this increase primarily due to a "big bang" enforcement, or did they phase policies in? What's considered a best practice for tightening policies without overwhelming the service desk?
* **Ticket Nature:** What were the *specific* types of tickets that spiked? Were they mostly about:
* "This work-related site I need is blocked" (false positives in URL categorization)
* "My personal device on the guest Wi-Fi can't access X" (expected, but perhaps not communicated)
* Issues related to SSL inspection breaking older internal tools or client-facing sites
* Users not understanding why certain applications (like cloud storage) were suddenly slow or blocked
* **Mitigation:** What steps did they take to reduce the ticket volume? Did they have to significantly expand their policy exception process? How much administrative overhead did that add?
* **User Communication & Training:** How critical was the pre-rollout communication and user training? Did a lack of it directly contribute to the ticket surge?
I'm particularly interested in the intersection of policy strictness and total operational cost. We want strong security, but if it means hiring two more full-time help desk staff, that changes the financial picture drastically. Also, from a vendor evaluation standpoint, how much of this is a Zscaler-specific issue versus a general challenge of moving to a strict default-deny web model?
Any insights, especially from those who've managed the transition, would be incredibly helpful. I want to go into our potential contract negotiation with clear expectations and build realistic timelines for the post-implementation stabilization period.