Navigation Area
Private access, from the model to the policy
Notes, field experiences and architecture reflections about Zscaler Private Access: private application access, identity-based segmentation, App Connectors, access policy design and VPN modernization.
Written as a series and best read in order, though each part stands on its own if you already know where your problem is.
Part One • Remote Access • Zero Trust
6 August 2026
Why ZPA Is Not Just a VPN Replacement
Why ZPA is a different access model rather than a different tunnel: the attack surface a public VPN endpoint creates, what a compromised laptop reaches under each model, and why discovery comes before least privilege.
Read article →Part Two • App Connectors • Reachability
10 August 2026
How App Connectors Reach Private Applications
The private side of the architecture: outbound-only connectors, the source address the application actually sees, synthetic IPs, connector groups and failure domains, and why reachability is not authorization.
Read article →Part Three • Segments • Segmentation Design
13 August 2026
A Resource Nobody Declared Does Not Exist
Default deny and what it costs the teams who used to get reachability for free. Application segments, segment groups and server groups, why specificity works by subtraction rather than priority, port discipline, and the discovery effort that pays twice.
Read article →Part Four • Policies • Evaluation Order
14 August 2026
The Access Logic
The order in which everything is actually evaluated, and why a name resolves before anybody checks whether you are allowed. Client forwarding and access policy, why the wildcard rule belongs last, segmenting by purpose rather than by resource, and the tunnel that runs before anybody logs in.
Read article →