
The ability to replace slow, legacy VPNs with direct, identity-based Zero Trust connectivity is exceptional. Zscaler securely connects users directly to authorized applications rather than placing them onto the corporate network, which completely eliminates lateral threat movement and drastically reduces our external attack surface. The centralized cloud console makes enforcing granular access policies, SSL inspection, and DLP rules seamless across all remote and hybrid endpoints without managing hardware appliances. While Zscaler sits at an enterprise premium price point, the ROI justifies the cost. It allowed us to consolidate multiple legacy point products—including standalone VPN appliances, separate web filtering gateways, and branch hardware—into a single cloud architecture. The operational hours saved on infrastructure maintenance and reduced helpdesk connectivity tickets provide clear value for the investment. Review collected by and hosted on G2.com.
The platform has a steep learning curve when it comes to policy management and troubleshooting. Because there are numerous overlapping security policies, SSL inspection rules, and posture checks, pinpointing why a specific application or developer toolchain is blocked can require digging through dense logs. Additionally, the Zscaler Client Connector (ZCC) occasionally conflicts with local network adapters or developer environments (like CLI tools failing on SSL inspection certificates), which requires ongoing admin fine-tuning and domain bypass configurations. Review collected by and hosted on G2.com.