Zscaler Advanced Self Paced

Master secure user access and Zero Trust implementation using Zscaler Internet Access (ZIA)

Programme focus

Master secure user access and Zero Trust implementation using Zscaler Internet Access (ZIA)

About the Zscaler Advanced Self Paced programme

This course is designed to provide a comprehensive understanding of how to deploy, configure, and manage secure user access using the Zscaler platform. In today’s cloud-first world, traditional perimeter-based security is no longer sufficient. This course introduces learners to the Zero Trust architecture, where access is granted based on user identity, device posture, and security policies rather than network location. Participants will gain hands-on knowledge of Zscaler Internet Access (ZIA), including traffic forwarding, authentication, policy creation, and security enforcement. The course also covers integration with Identity Providers (IdPs) using SAML and OpenID Connect (OIDC) to enable secure and seamless user authentication. By the end of this course, learners will be able to confidently manage user access, enforce security policies, monitor traffic, and troubleshoot issues within a real-world enterprise environment.

Course at a glance

  • Duration: 2 Month
  • Level: Advanced
  • Training format: Live Online
  • Prerequisites: Networking Fundamentals, Security Basics, General IT Knowledge

What you will learn

  • Understand the fundamentals of Zero Trust architecture and its real-world implementation
  • Configure and manage Zscaler Internet Access (ZIA) for secure user connectivity
  • Deploy and manage Zscaler Client Connector across endpoints
  • Implement user authentication using SAML and OpenID Connect (OIDC)
  • Create and enforce security and access policies based on user identity
  • Configure traffic forwarding methods for different environments
  • Perform SSL/TLS inspection for enhanced security visibility
  • Monitor user activity using logs, reports, and analytics
  • Troubleshoot common issues in Zscaler deployments
  • Integrate Zscaler with directory services and Identity Providers (IdPs)
  • Apply best practices for secure web gateway (SWG) and cloud security

Course highlights

  • Real-world implementation of Zero Trust Architecture
  • Step-by-step guidance on user management and policy enforcement
  • Practical exposure to Zscaler Client Connector deployment
  • In-depth understanding of traffic forwarding and SSL inspection
  • Monitoring, logging, and troubleshooting techniques

Curriculum modules

Introduction to Zero Trust Exchange

  • Zero Trust in Action: Zscaler Learning Journey
  • Introduction to Zero Trust Exchange - How Traditional Architectures Function
  • Introduction to Zero Trust Exchange - Zscaler Zero Trust Exchange Architecture
  • Zscaler Experience Center - Exploring the Zscaler Experience Center

User Management

  • Introduction to User Management
  • Identity Fundamentals - Overview of Security Assertion Markup Language (SAML)
  • Identity Fundamentals - OAuth 2.0 workflow
  • Authentication with ZIdentity - Configuring Microsoft Entra ID as an External IdP
  • Authorization with ZIdentity - Workflow of SCIM Provisioning
  • Authorization with ZIdentity - Configuring SCIM
  • User Management in the Zscaler Experience Center - Adding a user to the Zscaler Experience Center
  • User Management in the Zscaler Experience Center - Add a user group in the Zscaler Experience Center
  • User Management in the Zscaler Experience Center - Adding User Attributes
  • User Management in the Zscaler Experience Center - Adding Session Attributes
  • User Management in the Zscaler Experience Center - Adding ZIdentity Admin Role
  • User Management in the Zscaler Experience Center - Assigning Administrative Entitlements
  • User Management in the Zscaler Experience Center - Adding User to Service Entitlements
  • Multi-Factor Authentication - Enabling MFA or FIDO2 in ZIdentity
  • Multi-Factor Authentication - Authentication flow in Zscaler

Device Management

  • Introduction to Device Management
  • Introduction to Tunneling - Tunneling Overview
  • Zscaler Client Connector Installation - Downloading the Zscaler Client Connector Installer File
  • Managing Zscaler Client Connector and Forwarding Traffic - How to configure Client Connector notifications
  • Managing Zscaler Client Connector and Forwarding Traffic - How to configure a Forwarding Profile
  • Managing Zscaler Client Connector and Forwarding Traffic - Steps to configure App Profiles
  • Managing Zscaler Client Connector and Forwarding Traffic - How to configure App Supportability
  • Zscaler Client Connector - Device Postures and Profiles -- Configuring Device Postures for ZIA Enforcement Policies

Core Platform Management

  • Introduction to Core Platform Management
  • App Connector Deployment - App Connector Components - Working Together
  • Provisioning Keys - Deploy App Connector Process: Provisioning Keys and Certificates
  • Provisioning Keys - Private Application App Connector-- Demonstration
  • DNS Control - Zscaler DNS Control

Understanding ZIA Policies

  • Introduction to Understanding ZIA Policies
  • Firewall Rules - Firewall Control Policy
  • Firewall Rules - Firewall Filtering Policy
  • Firewall Rules - NAT control functions, its key components
  • File Type Control - File Type Identification
  • URL and Cloud App Control - URL Filtering rules
  • URL and Cloud App Control - Cloud App Control Overview
  • TLS/SSL Inspection - Key Facets of TLS Inspection
  • TLS/SSL Inspection - How does ZIA TLS Inspection/TLS Proxy Work?
  • TLS/SSL Inspection - Certificate Chain with TLS/SSL Inspection
  • Advanced Threat Protection - Advanced Threats Policy
  • Malware Protection - Malware Protection Policy
  • Sandbox Policy - Zscaler Cloud Sandbox
  • Sandbox Policy - Sandboxed File flow per policy

Configuring DLP Policies

  • Introduction to Configuring DLP Policies
  • Data Loss Prevention (DLP-Inline) -- Data Discovery and Classification
  • Cloud App Security (CASB) - Monitor Shadow IT

Implementing ZPA Policies

  • Introduction to Implementing ZPA Policies

Reviewing Dashboard and Logs

  • Introduction to Reviewing Dashboard and Logs
  • Dashboard and Log Review - logging architecture within zscaler
  • Log Streaming - How Log Streaming Works?

Security Reporting and Risk Analytics

  • Introduction to Security Reporting and Risk Analytics
  • Risk360 - Risk360 Demo Video

Monitoring with ZDX

  • Introduction to Monitoring with ZDX

Troubleshooting and Incident Response

  • Introduction to Troubleshooting and Incident Response
  • Filter User/Network/Location Activities with Poor ZDX Score
  • Analyze Live Logs and User Activities
  • Monitor PSE/Connector Utilization - ZIA Private Service Edge Health Dashboard
  • Review Audit Logs for Unauthorized Access - Review Audit Logs for Unauthorized Access in the Experience Center

Integrations and Optimization

  • Introduction Integrations and Optimization
  • App Connector Health and Updates - Version Profiles
  • Performance Tuning - Review and Refine SSL Inspection Bypasses
  • Performance Tuning - Monitor and Adjust Resource Allocation for ZPA Private Service Edges/Connectors
  • Security Information and Event Management (SIEM) - Log Forwarding(NSS/LSS) to SIEM Platforms

Tools and platforms covered

  • Zscaler Internet Access (ZIA)
  • Zscaler Client Connector
  • Zscaler Admin Portal
  • Active Directory (AD)
  • Microsoft Entra ID (Azure AD)
  • Okta
  • Ping Identity
  • SSL/TLS Inspection Tools
  • Cloud Firewall
  • Data Loss Prevention (DLP)
  • Secure Web Gateway (SWG)

Career outcomes

Target job roles

  • Cloud Security Engineer
  • Security Operations (SOC) Analyst
  • Zero Trust / SASE Engineer
  • System Administrator
  • Network Administrator
  • Security Administrator
  • IT Administrator