Zscaler Private Access (ZPA) Architecture

ZPA is a cloud-delivered Zero Trust Network Access (ZTNA) service that brokers per-application access between users and private applications, without ever placing those applications on the public internet or putting the user on the corporate network.

ZPA Archtitecture

Core components

ComponentWhere it runsRole
Client Connector (Z-App)User’s deviceAuthenticates the user against your IdP and checks device posture before requesting a session
Policy engine (Central Authority)Zscaler cloudEvaluates identity, device posture, group membership, time of day, etc. and authorizes (or denies) each session
Service Edge (Public / Private / Microtenant)Zscaler cloud (or your site, for Private Service Edge)Brokers the connection — stitches the user’s tunnel and the App Connector’s tunnel together
App ConnectorYour data center or cloud VPC, next to the appLightweight VM/container that dials outbound to the Service Edge; never accepts inbound connections

How a connection is brokered

  1. The Client Connector authenticates the user and checks device posture, then dials outbound to the Service Edge.
  2. The App Connector, sitting next to the private application, also dials outbound to the Service Edge.
  3. The Service Edge stitches these two outbound-only streams together into a single brokered session, after the Policy engine has authorized it.
  4. No inbound port is ever opened on either side — the app has no public IP, no public DNS record, and isn’t discoverable by internet scanners.

This “double inside-out tunnel” is what lets ZPA give a user access to exactly one authorized application instead of broad network reach, the way a VPN would.

Service Edge deployment options

  • Public Service Edge — multi-tenant, Zscaler-operated. Simpler and cheaper; the default choice for most organizations.
  • Private Service Edge — same brokering/enforcement logic, but runs inside your own site. Used for data-residency, latency, or regulatory requirements (common in banking and government).

Other notes

  • Per-app access, not network access — this is the core difference from a VPN. A VPN grants a subnet; ZPA grants a brokered session to one named application at a time, based on policy.
  • Browser Access — lets third-party or BYOD users reach an internal web app through a browser session, without installing the Client Connector.
  • ZPA is focused on application-level access control and session brokering; it’s not a substitute for host-based microsegmentation or a service mesh inside Kubernetes clusters.

Zscaler documentation