![Aswindev P.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Aswindev P.")
AP

Aswindev P.

Consultant

Information Technology and Services

Enterprise (\> 1000 emp.)

7/12/2026

"Zscaler Zero Trust Cloud: Seamless Multi-Cloud Access with Strong Device Posture Controls"

4.5/5

What do you like best about Zscaler Zero Trust Cloud?

The absolute best thing about the Zscaler Zero Trust Cloud and the biggest upside from an architectural standpoint is how it completely obliterates the concept of network-level trust. For decades, we relied on legacy VPNs that punched a hole through the firewall, assigned a remote user an IP address on the corporate LAN, and effectively gave them the keys to the kingdom. Zscaler flips that on its head by decoupling the user from the network entirely. Users connect only to the specific applications they are authorized to use, via outbound micro-tunnels, making the underlying infrastructure completely invisible to the internet.

​Here is what I find most helpful about it in the field:

​1. Seamless Multi-Cloud Access

​When securing complex environments that span AWS, Azure, and GCP, traditional routing becomes a nightmare of site-to-site VPNs and complex firewall rules. Zscaler Private Access (ZPA) acts as a universal broker. An engineer sitting in a coffee shop can SSH into an AWS EC2 instance, access an Azure web app, and hit a legacy on-prem database simultaneously, all through a single lightweight client, without ever knowing where those workloads physically reside.

​2. Device Posture as the Ultimate Gatekeeper

​Identity is no longer enough to grant access; device health is just as critical. The biggest upside of the Zscaler Client Connector is how seamlessly it integrates with the broader security stack to enforce conditional access. Before Zscaler brokers a connection to a sensitive application, it can verify device posture in real-time. If an endpoint's Microsoft Defender agent flags an active threat, or if Tanium reports that critical patches are missing and the machine is non-compliant, Zscaler instantly dynamically revokes access to internal applications until the machine is remediated.

​3. Simplifying Compliance and Audits

​Dealing with strict ITGC (Information Technology General Controls) and SOC 2 audits is historically painful when access logs are scattered across dozens of different firewalls, VPN concentrators, and cloud gateways. Zscaler centralizes all of this. Because every single transactionwhether outbound to the internet (ZIA) or inbound to a private app (ZPA) is brokered and logged in one unified cloud platform, proving least-privilege access and demonstrating robust data governance to an auditor becomes a drastically streamlined process.

​Ultimately, the most helpful aspect of Zscaler isn't just that it secures the environment; it completely removes the friction of enforcing that security across a decentralized workforce. Review collected by and hosted on G2.com.

What do you dislike about Zscaler Zero Trust Cloud?

If I have to give you the unvarnished architectural reality, the biggest downside of Zscaler Zero Trust Cloud is that it operates as a massive, opaque man-in-the-middle proxy. While this architecture provides incredible security, it fundamentally breaks how traditional networking and custom applications expect traffic to flow.

​When you deploy Zscaler, you are no longer just managing a network; you are actively intercepting and decrypting almost every packet your enterprise generates. This introduces three major areas of friction:

​1. The Friction of TLS/SSL Inspection (The Developer Nightmare)

​To get the deep visibility and Data Loss Prevention (DLP) that Zscaler promises, you have to break and inspect SSL/TLS traffic using Zscaler's root certificates. If you have a large software development team, they will absolutely hate it. Zscaler will aggressively break any custom developer application, Python script, Azure DevOps pipeline, or CLI tool that uses certificate pinning or non-standard web protocols. Your infrastructure team will spend a frustrating amount of time troubleshooting why a specific API suddenly refuses to connect, forcing you to maintain massive, complex bypass lists just to keep development teams working.

​2. The "Middle Hop" Latency

​It is a simple physics problem: Zscaler routes your traffic through a third-party data center. Every request a user makes travels from their device, to a Zscaler Enforcement Node (ZEN) for inspection, and then to its final destination. While Zscaler peers heavily with major cloud providers to minimize this, the latency is still palpable compared to a direct, uninspected internet connection. The most common complaint you will field from end-users is that "the internet feels slow," and it is difficult to explain to an executive that the security tool making their laptop sluggish is actually operating exactly as designed.

​3. Opaque Troubleshooting and "Black Box" Routing

​When an application fails to load or a connection drops, troubleshooting a cloud-native proxy is exponentially harder than troubleshooting a legacy on-premises firewall. Because the routing and inspection happen in Zscaler's cloud, you lose local visibility. If a user is experiencing a mysterious block or random CAPTCHA requests, it can be incredibly difficult to pinpoint whether the issue is a Zscaler policy, an SSL decryption failure, or the destination web server blocking Zscaler's public IP range.

​4. A Fragmented Administrative Experience

​Historically, Zscaler Internet Access (ZIA) for outbound web traffic and Zscaler Private Access (ZPA) for internal applications were built as two completely separate platforms. While the integration has improved by 2026, the administrative interface still often feels like two disjointed ecosystems glued together under a single login. Setting up granular, unified policies that seamlessly span both environments requires a steep learning curve and careful tuning to avoid breaking critical business workflows.

​Ultimately, the downside isn't that Zscaler fails to secure the environment; it is that enforcing that security requires a highly mature IT operations team capable of constantly managing exceptions, bypasses, and complex proxy logic. Review collected by and hosted on G2.com.

What problems is Zscaler Zero Trust Cloud solving and how is that benefiting you?

When architecting enterprise environments, the core business problem Zscaler Zero Trust Cloud solves is the fundamental breakdown of the traditional network perimeter. Historically, organizations relied on a "castle-and-moat" architecture, using VPNs and firewalls to secure a centralized network. However, with the rapid shift to remote work, multi-cloud deployments (AWS, Azure, GCP), and the proliferation of mobile devices, this model became inherently flawed. Users are now bypassing the enterprise gateway to access cloud applications directly, and traditional defenses cannot keep pace with evolving threats or provide the necessary architectural flexibility.

​Zscaler solves this by shifting security from the network layer to the edge, operating as a cloud-native proxy. By decoupling users from the underlying network, Zscaler ensures that users connect only to specific, authorized applications, completely hiding the infrastructure from the public internet.

​This architectural shift benefits the business in several concrete ways:

​Drastic Cost Reduction & Complexity Elimination: By retiring legacy VPNs and centralizing security policies, organizations can significantly lower management overhead and operational costs. Zscaler consolidates multiple point products such as Secure Web Gateways (SWG), Cloud Access Security Brokers (CASB), and Zero Trust Network Access (ZTNA) into a single cloud platform. This eliminates the need for expensive hardware appliances and the associated costs of public cloud transit and bespoke networking architectures. ​Enhanced Cybersecurity Posture: Zero Trust architecture minimizes the attack surface by eliminating public IP exposure and preventing inbound connections. It enforces least-privileged access and continuous monitoring, effectively stopping lateral movement if an endpoint is compromised. Zscaler's real-time inspection of all traffic, including encrypted data, blocks threats and prevents sensitive data leakage. ​Improved User Productivity and Experience: By providing direct-to-app connectivity, Zscaler removes the latency and bottlenecks associated with backhauling traffic through traditional data centers. This results in a superior digital experience for remote and hybrid workforces, accelerating business application deployments and boosting overall efficiency.

​Ultimately, Zscaler allows organizations to securely support digital transformation initiatives, enabling seamless and secure access to resources regardless of the user's location or the device they are using. Review collected by and hosted on G2.com.

Show More

Our network of Icons are G2 members who are recognized for their outstanding contributions and commitment to helping others through their expertise. G2 IconCurrent UserValidated ReviewerIncentivizedSource: G2 invite

See what 80 reviewers think of Zscaler Zero Trust Cloud

4.5 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/zscaler-zero-trust-cloud/reviews)