Zscaler Private Access (ZPA) Architecture
ZPA is a cloud-delivered Zero Trust Network Access (ZTNA) service that brokers per-application access between users and private applications, without ever placing those applications on the public internet or putting the user on the corporate network.
Core components
| Component | Where it runs | Role |
|---|---|---|
| Client Connector (Z-App) | User’s device | Authenticates the user against your IdP and checks device posture before requesting a session |
| Policy engine (Central Authority) | Zscaler cloud | Evaluates identity, device posture, group membership, time of day, etc. and authorizes (or denies) each session |
| Service Edge (Public / Private / Microtenant) | Zscaler cloud (or your site, for Private Service Edge) | Brokers the connection — stitches the user’s tunnel and the App Connector’s tunnel together |
| App Connector | Your data center or cloud VPC, next to the app | Lightweight VM/container that dials outbound to the Service Edge; never accepts inbound connections |
How a connection is brokered
- The Client Connector authenticates the user and checks device posture, then dials outbound to the Service Edge.
- The App Connector, sitting next to the private application, also dials outbound to the Service Edge.
- The Service Edge stitches these two outbound-only streams together into a single brokered session, after the Policy engine has authorized it.
- No inbound port is ever opened on either side — the app has no public IP, no public DNS record, and isn’t discoverable by internet scanners.
This “double inside-out tunnel” is what lets ZPA give a user access to exactly one authorized application instead of broad network reach, the way a VPN would.
Service Edge deployment options
- Public Service Edge — multi-tenant, Zscaler-operated. Simpler and cheaper; the default choice for most organizations.
- Private Service Edge — same brokering/enforcement logic, but runs inside your own site. Used for data-residency, latency, or regulatory requirements (common in banking and government).
Other notes
- Per-app access, not network access — this is the core difference from a VPN. A VPN grants a subnet; ZPA grants a brokered session to one named application at a time, based on policy.
- Browser Access — lets third-party or BYOD users reach an internal web app through a browser session, without installing the Client Connector.
- ZPA is focused on application-level access control and session brokering; it’s not a substitute for host-based microsegmentation or a service mesh inside Kubernetes clusters.