"Zero Trust Protection That Substitutes VPN"
What I like most about Zscaler Zero Trust Cloud is that it enables secure and granular access without exposing the entire network or relying on a VPN. Continuous validation of identity, device, and context enhances protection. I find it valuable because trust is not granted solely upon login. Each access can be evaluated based on identity, device security status, location, and risk level. I find the complexity of the administrative portal and the problem diagnosis process cumbersome. When there are multiple policies, identity integrations, and connectors, identifying the exact cause of a blockage may require reviewing numerous logs. I find that Zscaler Zero Trust Cloud addresses the risks of remote access and replaces traditional VPNs. I value its secure and granular access control and the continuous validation of identity, device, and context that enhances our security.
"Safe, Expandable Zero Trust Access Without VPNs"
What I like most about Zscaler Zero Trust Cloud is its ability to provide secure, seamless access to applications and data from anywhere without depending on traditional VPN infrastructure. The platform's Zero Trust architecture has significantly reduced our attack surface while delivering a better user experience, as users can connect directly to the apps they need with minimal latency. The cloud-native design makes deployment and management straightforward, and the centralized policy engine offers excellent visibility and control across users, devices, and applications. I also appreciate how well it integrates with identity providers and security ecosystems, helping streamline security operations and enforce consistent access policies. Another major advantage is the platform's intelligence and analytics capabilities, which provide actionable insights into user activity, application usage, and potential security risks. This has helped improve security posture while reducing operational complexity. From a business perspective, supporting hybrid and remote work securely at scale has delivered significant value and a strong return on investment by reducing dependence on legacy network infrastructure and simplifying ongoing management. One area where Zscaler Zero Trust Cloud could improve is the complexity of the initial deployment and policy configuration process, particularly for organizations migrating from traditional network security architectures. Because the platform offers a wide range of granular controls and security policies, it can take time for administrators to fully understand and optimize configurations. From a UI and management perspective, some troubleshooting workflows could be more intuitive, especially when diagnosing connectivity or policy-related issues across multiple applications and user groups. While the platform provides extensive visibility and analytics, identifying the root cause of an issue can sometimes require additional expertise and familiarity with the environment. Organizations should also plan for a learning curve during onboarding, as both administrators and end users may need time to adapt to the Zero Trust model. More guided implementation resources, simplified policy recommendations, and enhanced AI-driven insights for troubleshooting could further streamline adoption and operational efficiency. That said, these challenges are largely outweighed by the platform's security capabilities, scalability, and long-term value. Before implementing Zscaler Zero Trust Cloud, we faced challenges related to secure remote access, VPN scalability, and maintaining consistent security controls for a distributed workforce. Traditional network-based access models created operational complexity, increased the attack surface, and often impacted the user experience, especially for remote employees. With Zscaler, we moved to a true Zero Trust approach, providing users with direct, policy-based access to applications instead of granting network-level access. This significantly improved security by reducing exposure to potential threats while simplifying access for end users. The platform has also given us greater visibility into user activity, application usage, and security events through a centralized cloud-native interface. From an operational standpoint, we have reduced the complexity associated with managing VPN infrastructure and security policies across multiple locations. Integrations with identity providers and the broader security ecosystem have streamlined access management and strengthened compliance efforts. The platform's analytics and intelligence capabilities help identify risks more quickly, enabling faster decision-making and incident response. Overall, Zscaler has enabled us to support hybrid work securely at scale, improve the user experience, strengthen our security posture, and reduce operational overhead, delivering measurable value and a strong return on investment.
"Genuine Microsegmentation and Accelerated Cloud Access with Zscaler"
Genuine Microsegmentation (No Network Exposure): Direct Application Access - Unlike traditional VPNs that place users on the internal network, Zscaler connects authorized users directly to specific applications without granting network access. Prevention of Lateral Movement - If a user device or credential is compromised, attackers cannot scan the network or move laterally to infect other assets. Elimination of Traffic Backhauling: Direct-to-Cloud Connection - Remote and branch traffic routes straight to the nearest Zscaler cloud node rather than hairpinning back through a central corporate data center or VPN hub. Improved User Experience - This significantly reduces latency for cloud applications (like Microsoft 365, Salesforce, and SaaS tools), leading to faster performance for remote workforces. Scalable SSL/TLS Traffic Inspection: Complete Visibility - A huge percentage of enterprise web traffic is encrypted, making it a primary hiding spot for malware. Zscaler inspects SSL/TLS traffic at scale without performance degradation, eliminating the hardware bottlenecks common with traditional on-premise firewalls. Consolidated Cloud Security (SSE / SASE Architecture): All-in-One Security Stack - It unifies Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Data Loss Prevention (DLP) into a single cloud-native platform (ZIA and ZPA). Simplified Operations - Administrators manage policies, visibility, and threat intelligence from a central console rather than managing disparate point products. Network Performance and Throughput Drops: Reduced Speeds - Because Zscaler routes traffic through its cloud for deep packet inspection and SSL decryption, users frequently report a 10% to 20% drop in raw download/upload speeds. In poorly optimized setups, upload speeds can suffer even more drastically. Throughput vs. Latency - Zscaler optimizes for low latency rather than high throughput. While it is great for loading a SaaS web page securely, transferring massive files or running high-bandwidth applications can feel sluggish compared to a direct, unfiltered internet connection. Friction for Software Developers: SSL/Certificate Issues - Zscaler inspects encrypted traffic by acting as a 'man-in-the-middle' (MITM), replacing original website certificates with its own root CA. While web browsers easily accept this if the corporate IT team pushes the certificate via Group Policy, command-line developer tools (like Docker, npm, Python pip, Git, and AWS CLI) do not use the Windows/Mac system certificate store by default. The Result - Developers constantly face SSL Certificate Verify Failed errors and have to manually inject the Zscaler certificate into their individual toolchains, or beg IT to whitelist their domains. Client Connector (Agent) Conflicts and Quirks: Clashing with Other VPNs - If an organization is running Zscaler Client Connector (ZCC) alongside a legacy VPN (like Cisco AnyConnect or Palo Alto GlobalProtect) during a migration, the agents often fight for control of network routes, causing dropped connections. Local Network Blindness - Because Zscaler captures and tunnels DNS and web traffic, standard network troubleshooting tools (like Ping or Traceroute) often behave strangely or fail entirely, making it difficult for IT to diagnose basic local network issues. Administrative Complexity and UI: Fragmented Portals - Zscaler has historically maintained separate management portals for ZIA (Internet Access), ZPA (Private Access), and ZDX (Digital Experience). Administrators often complain that the UI feels dated and that managing holistic policies requires jumping between different screens and rule sets. Steep Learning Curve - It is not a 'plug-and-play' solution. Organizations without a highly mature network team often misconfigure MTU limits, UDP settings, or bypass rules, which leads to immediate user complaints. Premium Pricing and Customer Support: High Cost - Zscaler is often significantly more expensive than traditional firewall-based VPNs or some SSE competitors. Support Bottlenecks - Many enterprise administrators note that Tier 1 customer support can be slow to resolve complex routing issues, especially if the problem involves integrating Zscaler with a competitor's product or a niche cloud environment. The main problem Zscaler solves for us is securing a hybrid workforce without exposing our internal infrastructure to the public internet or compromised endpoints. Traditional perimeter security couldn't keep up with modern ransomware, encrypted threats, and shadow IT usage across remote devices. Benefits Received: Reduced Attack Surface - Our applications are hidden behind the Zero Trust Exchange, making internal resources invisible to unauthorized external scanners. Full SSL/TLS Inspection - Zscaler decrypts and scans web traffic at scale to stop malware hidden in encrypted streams without slowing down the network. Consistent Policy Enforcement - Security policies follow the user wherever they work, ensuring identical protection whether employees are in the office or remote.
M
Mid-Market (51-1000 emp.)
"Contemporary Cloud Security That Streamlines Access and Enhances Remote Performance"
Zscaler provides a modern, cloud-based approach to secure access that helps reduce reliance on traditional network infrastructure such as VPNs, perimeter firewalls, and similar tools. By consolidating multiple applications into a single product, it becomes easier to manage overall. It connects users directly to the applications and services they need when working out of the office, which simplifies network operations, supports cloud adoption, improves performance for remote users, and strengthens security. Zscaler’s AI-driven capabilities also enhance threat detection, security analysis, and visibility, which is important for our infrastructure and cybersecurity teams so they can respond quickly to risks and incidents. Zscaler did come with a learning curve during our implementation, especially around application setup and policy tuning, but the support team assisted us throughout that process. While Zscaler typically authenticates automatically after logging in to Windows, there are occasional times when users have to manually log back into the application, which can cause brief disruptions during the workday. This doesn’t happen often, but it has been a minor complaint within our organization. Zscaler Zero Trust Cloud helps address the challenges of securing a distributed workforce, supporting cloud adoption, and reducing reliance on traditional VPNs and perimeter-based security approaches.
"Robust Security and Usability, with Intuitive Administration and Dependable Performance"
What I appreciate most about Zscaler Zero Trust Cloud is that it provides secure access to internal applications without needing a traditional VPN. In my daily work, I can access business applications and shared resources from various locations with a consistent experience after authentication. The centralized management console offers useful visibility into traffic, user access, and policy enforcement, making it easier for administrators to handle security controls. Integration with identity providers like Microsoft Entra ID and other security tools helps streamline access management. Performance has generally been stable, and the cloud-based approach reduces the need to maintain legacy VPN infrastructure. I also find the reporting and analytics capabilities valuable for identifying access issues and potential security risks. Overall, it enhances both security and productivity while supporting remote and hybrid work environments. The biggest challenge is that initial configuration and policy design can be complex, especially in environments with many applications, user groups, and access requirements. New administrators may face a learning curve when troubleshooting access issues or understanding policy interactions. While performance is usually good, users may occasionally experience additional authentication prompts or need to reauthenticate when policies change. For organizations with advanced security needs, licensing costs can also rise as additional modules are added. I would also appreciate more AI-driven recommendations for policy optimization and faster root-cause analysis when troubleshooting user access problems. Overall, these are areas for improvement rather than major limitations. Zscaler Zero Trust Cloud helps address the challenge of providing secure access to internal applications for employees working remotely, traveling, or using different devices. Instead of relying on a traditional VPN that grants broad network access, users are connected only to the applications they are authorized to use. In practice, this reduces access complexity, improves security, and makes it easier to support a distributed workforce. The platform integrates with existing identity systems and centralizes policy management, which helps administrators manage access more efficiently. The benefit for end users is a smoother connection experience and reliable access to business applications, while IT teams gain better visibility, reporting, and security controls. This helps reduce operational overhead and improves the overall value of security investments.
"Flexible Zero Trust Security with Centralized Management for Remote and Hybrid Work"
What I value most about Zscaler Zero Trust Cloud is its Zero Trust security model, which provides secure access to applications without exposing the corporate network. It is cloud-native, easy to scale, and offers robust protection against cyber threats through secure web gateway, application access, and threat prevention. I also appreciate its centralized policy management, visibility into user traffic, and seamless support for remote and hybrid work environments. One drawback is that initial deployment and policy configuration can be complex, especially for organizations with large or legacy setups. Troubleshooting access issues may require a solid grasp of Zscaler policies, and there can be a learning curve for new administrators. In some cases, strict security policies may also impact application compatibility or require extra fine-tuning to avoid disrupting users. Zscaler Zero Trust Cloud helps secure access to applications and data without relying on traditional VPNs, reducing the organization's attack surface and enhancing overall security. It enables users to connect securely from anywhere while enforcing consistent security policies. This has boosted remote workforce productivity, simplified access management, and provided better visibility into network traffic and potential threats, resulting in a more secure and efficient IT environment.
"Robust Zero Trust Security, Yet Configuration and Troubleshooting Can Be Complicated"
What stands out most about Zscaler Zero Trust Cloud is securing cloud workloads without depending heavily on traditional network firewalls and VPNs. The centralized policy management, granular access controls, and visibility across cloud environments make it simpler to enforce consistent security. It also helps reduce lateral movement and attack surface while streamlining the overall security infrastructure. The primary drawback is the complexity in configuration and troubleshooting. Given the vast number of policies and security controls, administrators need time to fully understand and fine-tune the platform. Diagnosing connectivity issues can be difficult when logs or diagnostics don't immediately reveal the root cause. In some environments, Zscaler can affect network performance or create compatibility issues with certain applications and development tools. Licensing costs can also escalate as more features are added. Zscaler Zero Trust Cloud assists us in tackling several key security challenges, notably securing cloud workloads, controlling workload-to-workload communication, shrinking the attack surface, and preventing lateral movement if a system is compromised. It also offers centralized visibility and consistent security policies across our cloud environments instead of managing multiple separate security controls. This improves our overall security posture, simplifies administration, reduces operational complexity, and gives us better visibility and control over cloud traffic and access.
M
Market Research Specialist
"Swap Out Traditional VPN"
The best part is how it swaps out cumbersome traditional VPNs by linking users directly to specific apps rather than our whole corporate network, immediately halting lateral threat spread. Being fully cloud-native, we enjoy consistent, global security without managing or updating physical firewalls. Ultimately, it provides our remote workforce exceptionally fast, secure access without typical bottlenecks. The biggest downside is the steep learning curve and complexity of managing detailed policies across large enterprises, making troubleshooting access problems tedious. The endpoint agent (Zscaler Client Connector) can sometimes cause latency spikes or conflict with developer tools and local environments. Additionally, strict SSL inspection occasionally produces false-positive blocks on legitimate traffic, and modular licensing can get quite pricey as you expand features. Zscaler resolves the critical security weaknesses and latency bottlenecks of traditional VPNs by replacing our legacy network perimeter with a direct-to-app connection model. By connecting users only to the apps they are authorized to use, it completely stops threats from moving laterally across our infrastructure. Ultimately, this cloud-native approach eliminates the cost of managing physical firewalls while significantly boosting connection speeds for our global remote workforce.
M
Market Research Specialist
"Cloud-Native App Access Replacing VPNs with Swift, Worldwide Security"
The best part is how it swaps out cumbersome traditional VPNs by linking users directly to specific apps rather than our whole corporate network, immediately halting lateral threat spread. Being fully cloud-native, we enjoy consistent, global security without managing or updating physical firewalls. Ultimately, it provides our remote workforce exceptionally fast, secure access without typical bottlenecks. The biggest downside is the steep learning curve and complexity of managing detailed policies across large enterprises, making troubleshooting access problems tedious. The endpoint agent (Zscaler Client Connector) can sometimes cause latency spikes or conflict with developer tools and local environments. Additionally, strict SSL inspection occasionally produces false-positive blocks on legitimate traffic, and modular licensing can get quite pricey as you expand features. Zscaler resolves the critical security weaknesses and latency bottlenecks of traditional VPNs by replacing our legacy network perimeter with a direct-to-app connection model. By connecting users only to the apps they are authorized to use, it completely stops threats from moving laterally across our infrastructure. Ultimately, this cloud-native approach eliminates the cost of managing physical firewalls while significantly boosting connection speeds for our global remote workforce.
S
Sr. Tech/Pre-Sales Engineer – Backup & Storage
"Centralized Policy Management and Swift Secure Remote Connectivity"
Replacing sluggish legacy VPNs with direct, identity-based Zero Trust connectivity is outstanding. Zscaler links users securely straight to authorized apps instead of putting them on the corporate network, fully eradicating lateral threat movement and notably minimizing our external attack surface. The centralized cloud console makes enforcing detailed access policies, SSL inspection, and DLP rules smooth across all remote and hybrid endpoints without needing hardware appliances. Although Zscaler carries an enterprise-level price tag, the return on investment justifies the expense. It enabled us to merge multiple legacy point products—including standalone VPN hardware, separate web filtering gateways, and branch equipment—into one cloud architecture. The hours saved on infrastructure upkeep and fewer helpdesk connectivity issues clearly demonstrate value for the money. The platform has a significant learning curve regarding policy management and issue resolution. With numerous overlapping security policies, SSL inspection rules, and posture checks, identifying why a specific app or developer toolchain is blocked can require sifting through dense logs. Also, the Zscaler Client Connector (ZCC) sometimes clashes with local network adapters or developer setups (like CLI tools failing on SSL inspection certificates), requiring ongoing admin adjustments and domain bypass settings. It completely removes our dependence on legacy, hardware-based VPNs and stops our internal infrastructure from being directly exposed to the public internet. It addresses the critical risk of lateral movement by connecting authenticated users directly to specific apps rather than granting full network access. This significantly shrinks our external attack surface and bolsters our overall security stance. For daily operations, it removes WAN bottlenecks and backhauling latency for remote staff, resulting in faster app performance, simpler policy management across distributed branches, and far fewer connectivity-related helpdesk tickets.