Zero trust security

Make it possible

Your Mission
Products > ZPA for Azure

Your apps moved to Azure,
but how are you securing access to them?

Time for a better approach to secure remote access

Request Demo

Network-centric security makes moving to Azure painful

Today 40% of enterprises are running apps in Azure to increase scalability and speed. This move has extended the perimeter to the internet. Yet, many enterprises still rely on remote access VPNs, which are network-centric, and not built to secure access to the internet. They also place users on the network, and require physical or virtual appliances that increase complexity and limit scalability.

Common pitfalls of network-centric approaches:
  • Places users on-net to provide access to Azure
  • Requires appliances, ACLs and FW policies
  • Provides a poor end user experience
  • Inbound connections create opportunity for DDoS attacks
  • No ability to provide true application segmentation
  • Lack visibility into app-related activity
As applications have moved to cloud but remote access to Azure still rely on the data center

Zscaler Private Access for Azure

Enabling user and application-centric security for Azure

Zscaler Private Access (ZPA) for Azure is a cloud service from Zscaler that provides zero-trust, secure remote access to internal applications running on Azure. With ZPA, applications are never exposed to the internet, making them completely invisible to unauthorized users. The service enables the applications to connect to users via inside-out connectivity versus extending the network to them. Users are never placed on the network. It provides a software-defined perimeter for Azure, that supports any device and any internal application.

Read the Solution Brief
Relying on UTM and NGFW appliances to secure internet traffic is costly, results in appliance sprawl, and compromises branch security.
See Our Solution View the Challenge

Zscaler Private Access for Azure benefits

Better remote user experience

Users have fast, direct-to-cloud access without having to login to remote access VPN client each time.

Less complexity for admins

Network admins can segment based on application from within the web UI. No need to segment by network. No IP address segmentation or access control lists required.

Secure remote access, w/o network access

Policy based access, with no access to network. Visibility into apps being accessed by users and ability to discover unsanctioned apps running within Azure.

Traffic remains private via internet network

Service uses dynamic, application specific TLS-based end to end encryption. All data remains private and enterprises can bring their own PKI.

No hardware appliances, lower costs

The cloud service requires no hardware. Enterprises can easily scale across multiple Azure and Zscaler data centers with no need to replicate gateways.

Scale elastically, reduce latency

The service uses the global Azure network to ramp up new users and route them to the app location nearest to them via internet-based networking.

Simplify secure remote access to internal apps on Azure

Zscaler Private Access takes a user and application-centric approach to network security. It ensures that only authorized users and devices have access to specific internal applications on Azure. Rather than relying on physical or virtual appliances, ZPA uses lightweight infrastructure agnostic software to connect both users and applications to the Zscaler Security Cloud, where the brokered connection is stitched together. ZPA is complementary to Azure ExpressRoute.

1.  Zscaler Enforcement Node
  • Hosted in cloud
  • Used for authentication
  • Customizable by admins
  • Brokers a secure connection between a Z-App and
    a Z-connector
2.  Zscaler App
  • Mobile client installed on devices
  • Requests access to an app
3.  App Connector
  • Sits in front of apps in Azure, AWS, and other public cloud services
  • Listens for access requests to apps
  • No inbound connections

Leverage the Power of the Azure Network

With Zscaler Private Access for Azure, Zscaler Enforcement Nodes (ZENs), which broker access between a remote user and an internal application, run within the Azure cloud. This enables networking admins to leverage the Azure network and its many data center locations. This reduces latency by minimizing hops and boosts user productivity.

Choose application segmentation, not network segmentation

In the past admins needed to segment networks to ensure secure user connections. Today, enterprises use ZPA to control which users access which applications. Admins can easily set granular policies at the application level for specific users, users groups, applications, application groups and associated subdomains.

1.  Create and define policy names
2.  Set different permissions levels for users and user groups
3.  Define the applications each policy is associated with
4.  Easily add new rules and policies for users and applications within the UI

Key Integrations Accelerate The Journey To Azure

We have developed integrations for Azure ecosystems. Integrations with Azure AD enables admins to use ZPA to set access policies for user groups based on their existing configurations. Additionally the Z-Connector is available on the Azure Marketplace. The connector front-ends apps on Azure, and send an inside-out connection to the Zscaler Security Cloud, where the brokered connection between authorized users and application takes place.

Suggested Resources

Customer Story

See how MAN Energy Solutions uses ZPA to provide zero-trust access to internal apps, at global scale

Read Case Study 


Watch the ZPA for Azure webinar recording

Watch Webcast 

Case Study

Microsoft and Zscaler partner for success

Read More