Listing Thumbnail

    Zscaler Private Access (ZPA)

     Info
    Deployed on AWS
    Vendor Insights
    Zscaler Private Access (ZPA) applies the principles of least privilege to give users secure connectivity to private applications while eliminating unauthorized access and lateral movement. ZPA can be deployed in hours to replace legacy VPN and remote access tools with a holistic zero trust platform.

    Overview

    Play video

    Zscaler Private Access enables businesses to achieve:

    Peerless Security, beyond legacy VPNs and firewalls Connect users directly to apps - not the network - minimizing the attack surface and eliminating lateral movement

    Unrivaled Security against compromised app or users First-of-its-kind app protection, with inline prevention, deception, and threat isolation, minimizes the risk of compromised users

    Superior productivity for today's hybrid workforce Lighting-fast access to private apps extends seamlessly across remote users, HQ, branch offices, and third party partners

    Unified ZTNA platform for users, workloads & OT/IoT Securely connect to private apps, services, and OT/IoT devices with the industry's most comprehensive ZTNA platform

    Highlights

    • Minimize the attack surface - Make apps invisible, impossible to breach
    • Eliminate lateral movement - Enforce least-privileged access without putting users on the network
    • Stop compromised users and mitigate risk - Prevent app exploitation, find, active attackers and threats, and prevent data loss

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (4)

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Zscaler Private Access (ZPA)

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    ZPA_TFORM_500_ED
    ZPA Transformation Edition
    $155,000.00

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Zscaler global support is available around the clock, with dedicated customer support engineers providing personalized assistance to ensure that customers are getting the most value from our products. Our support engineers have significant experience in networking and security, working closely with operations, sales, and engineering teams to ensure rapid response and resolution. support.zscaler.com

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Business Intelligence & Advanced Analytics
    Top
    10
    In Network Infrastructure, Infrastructure as Code
    Top
    10
    In Device Connectivity

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    3 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    19 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Zero Trust Network Access
    Implements zero trust principles with direct application connectivity instead of network-level access
    Least Privilege Access Control
    Enforces granular access permissions by connecting users directly to specific applications
    Threat Prevention Mechanism
    Provides inline prevention, deception, and threat isolation capabilities to mitigate security risks
    Application Visibility Protection
    Makes private applications invisible and inaccessible to unauthorized network participants
    Multi-Environment Connectivity
    Supports secure connections across remote users, headquarters, branch offices, and third-party partner environments
    Network Protocol
    "Programmable networking software built on the WireGuard protocol for secure connectivity"
    Identity-Based Access Control
    "Network access control based on user identity, groups, services, and subnet ranges"
    Connection Management
    "Automatic network connection migration and direct device connections without manual port forwarding configuration"
    Infrastructure Compatibility
    "Cloud and hardware-agnostic overlay network deployment across multiple operating systems and platforms"
    DNS Resolution
    "Automatic hostname resolution with MagicDNS for simplified device and resource access without IP address management"
    Zero Trust Network Access
    Enforces least-privilege access based on user identity with continuous checks on device security, location, and identity
    Network Routing
    Supports application domain-based routing that efficiently routes traffic across private networks with overlapping IP address ranges
    Global Network Infrastructure
    Delivers connectivity through 30+ worldwide points of presence using full-mesh topology over high-speed internet access
    Threat Protection
    Includes built-in IDS/IPS that automatically filters and blocks malicious traffic with multi-pronged content detection and customizable DNS filtering
    Device Posture Control
    Implements device posture policies ensuring each device adheres to predefined security rules and access criteria

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    3 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    67%
    33%
    0%
    0%
    0%
    3 AWS reviews
    |
    7 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    reviewer1492392

    Ensuring seamless VPN connectivity while needing better troubleshooting support

    Reviewed on Jun 18, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We are using secure remote access for internal applications, and that's why we are using Zscaler Private Access (ZPA)  now. I work with Zscaler Private Access (ZPA) . I use it just for the VPN functionality.

    What is most valuable?

    The best advantage of the product is that it is always on as a VPN, which gives us much more functionality. It is basically easy to use and easy to configure. The solution for Zscaler Private Access (ZPA) is seamless for this.

    From a visibility perspective, they have added more content features where we can see security and other aspects through available dashboards. That's the only notable addition, plus they are implementing the overall security architecture of tenants, which gives much more information to work with.

    What needs improvement?

    The only room for improvement is the troubleshooting problem with iPhones as of now.

    The review should be anonymous; there should not be any personal or business details given. Both should be anonymous.

    For how long have I used the solution?

    I have been using it for around four or five years.

    What was my experience with deployment of the solution?

    The installation and deployments are straightforward; it is just a two-liner process. There is something in the documentation that might need changes, but it's pretty straightforward.

    The documentation has to be perfect as it has not been updated for a long time. They need to update it based on the latest version and the commands we use.

    What do I think about the stability of the solution?

    The solution is stable enough.

    What do I think about the scalability of the solution?

    We are using cloud services, but I am not sure about the scalability specifically.

    Based on the limited users, this is perfectly fine since we are using only one box, and we haven't faced many issues with that.

    How are customer service and support?

    I am not happy with the technical support from Zscaler Private Access (ZPA), particularly in India, where reachability is an issue with salespersons. Sometimes we need to reach a salesperson to get issues resolved, especially for mobile problems we're still facing. We lack specific root causes, and it's tough to relay information to users, considering multiple contributors such as phone numbers and internet service providers. We need more visibility on what problems users are facing with reachability.

    I would rate technical support six points out of ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I have not used any other VPNs apart from Zscaler Private Access (ZPA).

    What was our ROI?

    I see some ROI in the product. Since we have a very small team, the ROI is around 20% to 30%. I would say 30%.

    What other advice do I have?

    I am not using AWS Backup  anymore since we spoke almost two years ago. I have a backup solution managed by another team, and there's a discussion about AWS  for backup. I am responsible for the IT security part only.

    I do not work with popular vendors such as Palo Alto or Fortinet, as my primary domain is Check Point, and it's all about security. I use Check Point for this purpose. I do not work with the product ZoneAlarm . We use only a specific firewall from Check Point and utilize only the firewall. We are not using Check Point CloudGuard  Web Application Firewall ; we are using a normal firewall, the Firewall as a gateway. The name of the product is Check Point Firewall Gateway.

    I am not using a web gateway. We do not use products such as Harmony  or Harmony  Browse. I am using a VPN from Cisco for endpoint protection. I am not using the cloud firewall from Zscaler Private Access (ZPA). I am not working with Zscaler B2B  or ZTNA  as a service.

    From a troubleshooting perspective, we face an issue with iPhones affecting about 10% of users. Even when we provide logs, they are not able to figure out what exactly is happening. It's not possible for users to collect logs each time, and this is a peculiar problem happening with 10 to 15 users.

    The operational flexibility is very effective; there are no problems, and I did not have any issues with that. The solution is affordable, but there are other parts that could add much more information, which may not be useful for us at the moment, making it a bit expensive. There is also a China-specific solution, which is really expensive.

    I agree to share my details with the Zscaler vendor. I do not want to be a reference for Zscaler Private Access (ZPA).

    On a scale of 1-10, I rate this solution a 9.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Eli Grosman

    Enables secure and seamless connectivity for distributed teams

    Reviewed on Jun 05, 2025
    Review from a verified AWS customer

    What is our primary use case?

    For our main use cases for Zscaler Private Access (ZPA) , it’s providing us a VPN solution for our clients, connecting to data build resources, and providing them security.

    What is most valuable?

    It's challenging to explain which features of Zscaler Private Access (ZPA)  are most valuable because the main client is the IT department in our company, and we, as DevOps, are deploying this solution as infrastructure for them. From our case, and as I'm familiar with this tool, the most value is the VPN connection because it provides access for all company members to data builds in a secure way.

    Zscaler Private Access (ZPA) does an excellent job offering secure remote access to internal applications for our distributed workforce because it provides a granular way to grant access for specific people with specific applications.

    Zscaler Private Access (ZPA) has been very effective in providing operational flexibility during our company's transition to cloud environments, as it helped us significantly, and it was deployed even before we migrated to the cloud itself.

    What needs improvement?

    Concerning improvements for Zscaler Private Access (ZPA), we have occasional issues, but I don't think they are related to the product itself; they may be related more to infrastructure problems or something else related to the network because it's a network application.

    The current pain points we sometimes experience relate to the additional security applications we have on the laptops, and sometimes I don't know if I didn't get any notification from the application because it's an agent problem or something security-wise blocking this.

    For how long have I used the solution?

    I have been using Zscaler Private Access (ZPA) for more than three years.

    What was my experience with deployment of the solution?

    I would describe my experience deploying Zscaler Private Access (ZPA) as very straightforward, but I think it could allow more automatic ways to deploy and configure instead of having to connect to each new instance manually and configure it.

    What do I think about the stability of the solution?

    We didn’t have any issues with Zscaler Private Access (ZPA)’s stability, availability, or reliability.

    What do I think about the scalability of the solution?

    I don’t know how Zscaler Private Access (ZPA)’s cloud-native architecture is used for scaling within my company, but we do use something deployed in the cloud, and from my perspective, we only deploy the agent, exactly what we took from the marketplace.

    How are customer service and support?

    As for support from Zscaler Private Access (ZPA), I might have used it, but it’s primarily handled by the IT team.

    Which solution did I use previously and why did I switch?

    I know we had something before Zscaler Private Access (ZPA) to address similar needs, but I don’t remember the application name. The decision to move to Zscaler Private Access (ZPA) was possibly because it’s more native in the cloud environment and provides us an easier way to get or configure this.

    Which other solutions did I evaluate?

    In regard to other solutions I considered before implementing Zscaler Private Access (ZPA), I don’t know because the decision on what to use and what to install came from management.

    What other advice do I have?

    Regarding the micro-segmentation feature of Zscaler Private Access (ZPA), I can explain less, and I think the IT team who are managing it can explain better.

    I don't know how Zscaler Private Access (ZPA) has helped minimize lateral movement within our network because I don't know how to measure this reduction.

    Since implementing Zscaler Private Access (ZPA), I've not noticed any changes in the visibility or monitoring of user access patterns because it's not part of our responsibility. We deploy it, and the IT team is configuring and monitoring it, fixing issues if it's working or not.

    I'm not familiar with all benefits from using Zscaler Private Access (ZPA) that I haven't discussed, as I am only familiar with the VPN-related functionality and the segmentation which provides granular security access for the clients.

    I rate Zscaler Private Access (ZPA) eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    reviewer2711850

    Enables seamless management and secure access to internal networks

    Reviewed on May 28, 2025
    Review from a verified AWS customer

    What is our primary use case?

    Our use case for Zscaler Private Access (ZPA)  is that it provides Private Access.

    Zscaler Private Access (ZPA)  means allowing users access to the internal network in AWS  in a secure way.

    I use Zscaler Private Access (ZPA) to secure remote access to internal applications.

    What is most valuable?

    The most valuable feature of Zscaler Private Access (ZPA) is the ability to manage access with policies, all in one, which provides our security team the ability to provide the required permission for each team, and also visibility. If something goes wrong, I have a very friendly UI to see what's going wrong, why the user is blocked, or what the issue might be.

    Zscaler has allowed an easy, secure way for us to access our internal resources from outside.

    Its effectiveness for my organization is mainly security, as users can access those applications only if they have the permission to go through Zscaler.

    Zscaler has helped with operational flexibility because when a new employee starts, it's very easy to give them the required permissions. Everything is managed in an Active Directory or Okta in our case, and it's very easy to have the user ready to start working with just a few clicks.

    What needs improvement?

    Zscaler Private Access (ZPA) is a very good product, though there are some areas for improvement.

    The solution is not scalable; we deploy it in a high-availability environment, but it's not automated. We need to deploy it and ensure it will be available in two different Availability Zones, but it's not something that can be done with automation, such as auto-scaling.

    I would appreciate seeing dynamic scaling implemented because it would be beneficial if an instance goes down to automatically start another one.

    For how long have I used the solution?

    I have used Zscaler Private Access (ZPA) for a minimum of two to three years.

    What was my experience with deployment of the solution?

    When we tried to deploy it, the first thing it indicated was that we were not subscribed, so we subscribed, and then the product was available for us.

    What do I think about the scalability of the solution?

    The solution is not scalable; we deploy it in a high-availability environment, but it's not automated. We need to deploy it and ensure it will be available in two different Availability Zones, but it's not something that can be done with automation, such as auto-scaling.

    Regarding auto-scaling or dynamically scaling, I am not familiar with this capability if it exists as a new feature.

    How are customer service and support?

    I have not worked with customer support, as our IT department takes care of anything that isn't working and requires support.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The deployment process is actually very easy; we manage it with Terraform , so we are deploying the instance, activating it, and it's ready to go.

    After we have the Terraform  set up, it takes just minutes to deploy.

    What other advice do I have?

    I do not use the micro-segmentation feature.

    I'm not exposed to the pricing, so I cannot give feedback on that as I'm just a technical DevOps person deploying it.

    Zscaler has helped to manage complexity and cost compared to traditional network architecture.

    On a scale of 1-10, I rate Zscaler Private Access (ZPA) a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Erez Gilron

    Empowering secure remote access and control for distributed workforces

    Reviewed on May 28, 2025
    Review from a verified AWS customer

    What is our primary use case?

    The main use cases for Zscaler Private Access (ZPA)  include allowing network access. We use it mostly for private laptops and Macs, and we are also using it for communication between EC2s.

    I can provide examples of how it has been effective in the organization. We use Zscaler Private Access (ZPA)  to control the communication, mostly for the bands and working groups within the organization itself, so we can have complete control of who can access which resources on Amazon.

    What is most valuable?

    The features I appreciate the most about Zscaler Private Access (ZPA) are that it is very easy to use, and we have Terraform  for it, which makes it even easier and very straightforward.

    I have utilized the segment feature, and we call it segmentation, though I am not certain if there is a difference between micro-segmentation and segmentation itself.

    It has helped my organization in terms of minimizing lateral movement within the network, and I can confirm that.

    What needs improvement?

    I have not thought about how Zscaler Private Access (ZPA) can be improved, so I do not have any specific suggestions.

    For the next release, I hope to see features that would make Zscaler Private Access (ZPA) even better, but I am quite satisfied with the product, so I am unsure if there is anything better they can implement.

    For how long have I used the solution?

    I have used Zscaler Private Access (ZPA) for two years now, as I have been with the company for two years.

    What do I think about the scalability of the solution?

    I have not used Zscaler Private Access (ZPA)'s cloud-native architecture for scaling.

    How are customer service and support?

    I have not had to use their customer service or technical support.

    Perhaps our IT department did, but I have not had any issues since then.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    In terms of the setup, I am using Terraform  for it, so it is very straightforward. We are using Infrastructure as Code , so I am not certain if there is an interface that can be improved.

    What about the implementation team?

    I was not involved in the setup as it was implemented before I joined the company.

    What was our ROI?

    I have found Zscaler Private Access (ZPA) to be very effective at providing operational flexibility during my organization's transition to cloud environments.

    Which other solutions did I evaluate?

    I do not remember the name of any other solutions that were considered before implementing Zscaler Private Access (ZPA), but there were several POCs conducted before the company decided on Zscaler Private Access (ZPA).

    What other advice do I have?

    It is pretty straightforward and easy to use. On a scale of one to ten, I would rate Zscaler Private Access (ZPA) a ten.

    Which deployment model are you using for this solution?

    On-premises
    TarunKumar5

    Security features improve while response time needs attention

    Reviewed on May 22, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I worked with these organizations for implementing Secure Service Edge and SASE  solutions, including Cloud Access Security Brokers, such as Netskope  and Zscaler.

    Zscaler and Netskope  are the main solutions I work with for various use cases.

    Based on my experience, I have worked at the enterprise level only, for large companies such as banks and financial institutions that are transitioning from traditional solutions to new secure service edge solutions.

    What is most valuable?

    Zscaler has three components. Specifically, Zscaler Internet Access  for secure web access, Zscaler Private Access (ZPA)  that is a replacement of traditional VPN solution for securely accessing internal private applications without giving access to the whole network. It works by giving access to the particular application the user wants to access, and it checks numerous factors before granting access to the particular application, including posture checks, authentication, and authorization. Zscaler Digital Experience is a monitoring tool that monitors all application performance, network performance, and more. It helps us troubleshoot issues in a very short time.

    When discussing Zscaler Private Access (ZPA)  mainly, it is very helpful as a replacement for traditional VPN. In traditional VPN, we used to give access to the whole network, which increased attack vectors. Zscaler Private Access (ZPA) is more secure than these particular VPN solutions. We have implemented this solution for enhanced security. As a cybersecurity professional, I approach these answers from a security perspective.

    Micro-segmentation, authentication, and authorization are key features in Zscaler Private Access (ZPA). We can implement role-based access and limit user access by creating different groups. For example, if the HR department needs access to only HR applications, we can create specific groups with appropriate access levels. This segregates access and makes it more secure. They also provide features such as browser isolation, which creates a separate browser when users are accessing content, thus creating an isolated environment to prevent attacks.

    They provide integrations with various other security tools. The solution utilizes AI capabilities for various detections and responses. The solution has inbuilt AI for all detection capabilities.

    What needs improvement?

    Sometimes the team takes more time to provide responses on certain issues, which is why I do not rate it a perfect 10 out of 10.

    For how long have I used the solution?

    Overall, with Zscaler, I have worked for around five years, and particularly with Zscaler Private Access (ZPA), I have three years of experience.

    What was my experience with deployment of the solution?

    The deployment took approximately six months.

    What do I think about the stability of the solution?

    Sometimes connection errors occur when users are unable to connect to the particular cloud.

    These connection errors started occurring post rollout, not just during the implementation.

    What do I think about the scalability of the solution?

    For small and medium enterprises, it will be too expensive.

    How are customer service and support?

    I have worked with the Zscaler technical team.

    I would rate them around eight as they were pretty good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    The traditional solutions were still in use when we migrated to the current solutions. The migration process required extensive documentation and multiple testing phases.

    What's my experience with pricing, setup cost, and licensing?

    Prices for Zscaler Private Access (ZPA) are higher than traditional solutions, but it provides enhanced security.

    What other advice do I have?

    Product-wise, I would give Zscaler Private Access (ZPA) a seven. The overall rating for the solution is eight out of ten.

    View all reviews