Skip to content
Notifications
Clear all

Zscaler after 18 months - honest review from a mid-market IT team

2 Posts
2 Users
0 Reactions
13 Views
(@annaw)
Estimable Member
Joined: 1 week ago
Posts: 96
Topic starter   [#3846]

Alright, team. We rolled out Zscaler Private Access (ZPA) and Internet Access (ZIA) about a year and a half ago to replace our old VPN and on-prem proxies for a 500-person company. The pitch was solid: better security, a smoother user experience, and less network overhead. After living with it, I have some strong, nuanced feelings.

**The Good (Where It Shines)**
* **User Experience for Remote Access:** This is the win. Moving from a clunky VPN to app-specific access via ZPA is a game-changer for our teams. No more "connect to the VPN to get that file" reminders. Once configured, it's seamless and people actually forget it's there—which is the point of good tech.
* **Admin Visibility & Control:** The dashboard for ZIA is fantastic. Seeing traffic patterns, setting granular policies, and getting real-time threat alerts has made our security posture much more proactive. Policy-based access in ZPA is powerful once you get it dialed in.
* **Scalability & Cloud-Native Fit:** As we've moved more to SaaS (Salesforce, Figma, AWS), Zscaler has kept up effortlessly. No more backhauling traffic to the data center. Performance for cloud apps is noticeably better.

**The Not-So-Good (The Implementation Reality)**
* **Initial Configuration Complexity:** "Out of the box" is a bit of a misnomer. The initial setup, especially for ZPA, is **intense**. Defining app segments, connectors, and policies requires careful planning. Our first rollout had some hiccoughs where teams couldn't access legacy internal tools because we mis-scoped an application segment.
* **The Cost Conversation:** It's expensive. When renewal time came, the sticker shock was real. You have to really justify it by measuring reduced VPN support tickets, potential security incidents avoided, and the admin time saved. For us, it penciled out, but it was a tough sell to finance.
* **Agent & Endpoint Reliance:** It adds another agent to your endpoints. While mostly stable, we've had a handful of weird issues where the Zscaler service conflicted with another local app, causing connectivity drops. Took a while to diagnose.

**Bottom Line for Mid-Market Teams:**
If you're cloud-heavy and your users are distributed, Zscaler is a powerhouse that can dramatically improve both security and daily UX. However, go in with eyes open:
* **Dedicate internal resources** to the design phase. Don't rush it.
* **Pilot, pilot, pilot** with a diverse group of users and applications.
* Build a **business case beyond security**—focus on user productivity and IT operational gains to justify the cost.

For us, the initial pain was worth the long-term gain in a modern, zero-trust environment. But it's a journey, not a flip-of-a-switch.

Anyone else on a similar path? Would love to compare notes on app segmentation strategies or how you handled legacy system access.

Happy evaluating!



   
Quote
(@crm_hopper_2026)
Reputable Member
Joined: 3 months ago
Posts: 164
 

The transition from a broad VPN tunnel to app-specific access is indeed a transformative shift. Your point about users forgetting it's there aligns perfectly with a core principle of zero trust: the security model should enforce policy without becoming a user's daily concern. However, that seamless experience you praised is entirely predicated on the initial configuration being flawless.

The granular policy engine in ZPA is powerful, but I've found its complexity becomes a significant pain point when you need to model exceptions for non-standard applications or legacy systems that weren't designed for this paradigm. You can spend days tuning policies for a single, obscure internal tool that a handful of people use. The dashboard visibility is excellent, as you said, but it's also where you'll see those policy misconfigurations manifest as inexplicable access denials that are notoriously difficult to trace for a junior admin.

Did your team develop a specific framework for documenting and testing those ZPA policies before rollout, or was it more iterative? We attempted to map every application dependency beforehand and still encountered substantial drift.



   
ReplyQuote