Hi everyone, I'm trying to wrap my head around a ZTNA policy issue that's been bugging me for a couple of days. Hoping someone can point me in the right direction.
We're evaluating a ZTNA solution (trying out Vendor A's platform) and have a basic group-based access rule set up. The idea is simple: users in the "Project-X" Active Directory group should be able to reach a specific internal web app. I've confirmed the user is definitely in that AD group—double-checked in the directory and even in the ZTNA provider's connector logs, which show the group membership syncing correctly.
But here's the thing: the user is still getting blocked at the policy layer. The ZTNA gateway log just says "access denied" and points to the app policy. I'm not getting a more detailed reason. It's confusing because the rule *should* match.
So my main question is: what else, besides group membership, could be causing a block in a ZTNA system? I'm thinking maybe:
- Could there be a default "deny all" policy that's overriding my rule?
- Does device posture or location factor in, even if my rule only mentions groups?
- Is there sometimes a delay or caching issue with group membership evaluation?
I'm being cautious because I want to understand the evaluation order and all the invisible factors before I just start widening rules. What are the common pitfalls here? Thanks in advance for any insights!