Zscaler Digital Experience (ZDX)
Import the hostnames and IP addresses of your Zscaler Digital Experience managed devices into Guard as assets.
The Zscaler Digital Experience (ZDX) integration imports your ZDX managed devices into the Praetorian Guard Platform (PGP). Guard reads each device's hostname and network addresses through Zscaler OneAPI and adds them as assets. This guide walks you through creating a OneAPI client and connecting it to Guard.
What the integration does
Each time the integration runs, Guard signs in to Zscaler OneAPI and:
- Lists the devices in your ZDX tenant.
- Reads each device's details. A device that ZDX no longer returns is skipped.
- Adds each of the device's IPv4 and IPv6 addresses as an asset. When the device's hostname is a fully qualified domain name, such as
laptop-42.example.com, Guard records it together with the address. Short hostnames, such asLAPTOP-42, are not recorded.
Guard also drops assets it should not scan:
- Loopback, link-local, multicast, and unspecified addresses.
- IP addresses in public cloud provider ranges, and domains that resolve to a public cloud provider.
- Private IP addresses, such as
10.0.0.0/8or192.168.0.0/16, and domains that do not resolve in public DNS. - Any single IP address, public or private, that does not answer a single ping within half a second. IP ranges are not pinged.
Device addresses are often private, so this filter drops them by default. To import private and non-responding assets, contact Praetorian support.
The integration only reads from Zscaler. It does not change devices, probes, or settings.
Prerequisites
- A ZDX tenant that signs in through Zidentity. Guard connects through Zscaler OneAPI, which requires Zidentity. Legacy ZDX API keys are not supported.
- A Zidentity administrator account that can create API clients.
- The Zidentity vanity domain for your tenant: the
acmepart ofacme.zslogin.net. - Permission to add integrations in Guard.
Step 1: Create a OneAPI client in Zidentity
- In the Zidentity admin portal, create an API client.
- On the client's Resources tab, assign a read-only ZDX API role.
- Save the client, then copy the Client ID and Client Secret and store them safely.
One API client can serve several Zscaler products. To also import ZIA, ZPA, or EASM data through the same integration, assign an API role for each of those products too.
Step 2: Connect Zscaler in Guard
- In Guard, go to Integrations and open Cyber Asset Attack Surface Management → Zscaler.
- Enter:
- Client ID: the OneAPI client ID from step 1.
- Client Secret: the OneAPI client secret from step 1.
- Vanity Domain: your Zidentity hostname prefix, for example
acme. You can also enter the full host,acme.zslogin.net.
- Keep ZDX (Digital Experience) selected. EASM and ZIA are also selected by default. Clear any product your API client has no role for.
- Click Connect.
Before saving, Guard requests an access token from Zidentity and reads one device from ZDX. Guard checks every product you selected, and stops at the first one that fails, shows the error, and does not save the integration. Guard repeats these checks at the start of every run, so if the client later loses access to one selected product, no product imports until you restore the access or clear that product.
You can add more than one Zscaler integration, for example one per tenant.
Verify the integration
After the first run, go to Assets and search for the public IP address of a ZDX device that is outside cloud provider ranges and answers ping. It should appear as an asset.
Troubleshooting
If you need help with this integration, contact support@praetorian.com.