Zscaler Internet Access (ZIA)

Import your Zscaler Internet Access domains, locations, static IPs, VPN credentials, GRE tunnels, and IoT devices into Guard.

The Zscaler Internet Access (ZIA) integration imports the internet-facing inventory your ZIA tenant knows about into the Praetorian Guard Platform (PGP). Guard reads your organization's domains, locations, and traffic-forwarding configuration through Zscaler OneAPI and adds each domain and IP address as an asset. This guide walks you through creating a OneAPI client and connecting it to Guard.

What the integration does

Each time the integration runs, Guard signs in to Zscaler OneAPI and reads:

  1. Organization domains: the domains registered to your ZIA organization.
  2. Domain profiles: the custom domains in each domain profile.
  3. Locations: the IP addresses assigned to each location, and the FQDN and IP address of each VPN credential linked to a location.
  4. Static IPs: every static IP address configured for traffic forwarding.
  5. VPN credentials: the FQDN and IP address of each VPN credential.
  6. GRE tunnels: each tunnel's source IP address and internal IP range.
  7. IoT devices: the IP address of each IoT device ZIA has discovered.

Guard adds each domain, IP address, and IP range as an asset. When an entry has both an FQDN and an IP address, such as a VPN credential, Guard records them together on one asset. If your API client cannot read one of these sources, Guard skips that source and imports the rest. Organization information is the exception: Guard also uses it to check the connection, so if Guard cannot read it, the run fails.

Guard also drops assets it should not scan:

  • Loopback, link-local, multicast, and unspecified addresses.
  • IP addresses in public cloud provider ranges, and domains that resolve to a public cloud provider.
  • Private IP addresses, such as 10.0.0.0/8 or 192.168.0.0/16, and domains that do not resolve in public DNS.
  • Any single IP address, public or private, that does not answer a single ping within half a second. IP ranges are not pinged.

To import private and non-responding assets, contact Praetorian support.

The integration only reads from Zscaler. It does not change policies, locations, or settings.

Prerequisites

  • A ZIA tenant that signs in through Zidentity. Guard connects through Zscaler OneAPI, which requires Zidentity. Legacy ZIA API keys are not supported.
  • A Zidentity administrator account that can create API clients.
  • The Zidentity vanity domain for your tenant: the acme part of acme.zslogin.net.
  • Permission to add integrations in Guard.

Step 1: Create a OneAPI client in Zidentity

  1. In the Zidentity admin portal, create an API client.
  2. On the client's Resources tab, assign a read-only ZIA API role.
  3. Save the client, then copy the Client ID and Client Secret and store them safely.

One API client can serve several Zscaler products. To also import ZPA, EASM, or ZDX data through the same integration, assign an API role for each of those products too.

Step 2: Connect Zscaler in Guard

  1. In Guard, go to Integrations and open Cyber Asset Attack Surface Management → Zscaler.
  2. Enter:
    • Client ID: the OneAPI client ID from step 1.
    • Client Secret: the OneAPI client secret from step 1.
    • Vanity Domain: your Zidentity hostname prefix, for example acme. You can also enter the full host, acme.zslogin.net.
  3. Keep ZIA (Internet Access) selected. EASM and ZDX are also selected by default. Clear any product your API client has no role for.
  4. Click Connect.

Before saving, Guard requests an access token from Zidentity and reads your ZIA organization information. Guard checks every product you selected, and stops at the first one that fails, shows the error, and does not save the integration. Guard repeats these checks at the start of every run, so if the client later loses access to one selected product, no product imports until you restore the access or clear that product.

You can add more than one Zscaler integration, for example one per tenant.

Verify the integration

After the first run, go to Assets and search for one of your organization's domains or a public static IP address that answers ping. It should appear as an asset.

Troubleshooting

Message

What to do

Missing Module Selection

Select at least one Zscaler product.

Invalid Format: vanity_domain must be a hostname prefix (acme) or a Zidentity host (acme.zslogin.net)

Enter only the prefix, such as acme, or the host acme.zslogin.net.

Connection Failed: Could not reach the Zscaler API

Guard could not connect to Zidentity. Check the vanity domain, and try again in case of a network problem.

Validation Failed: Zscaler returned HTTP 400 or 404 during validation

Check the vanity domain, client ID, and client secret.

Authentication Failed

Check the client ID, client secret, and vanity domain. If Zidentity issued a token but OneAPI rejected it, confirm your tenant uses Zidentity and OneAPI.

Insufficient Permissions: authenticated but cannot read ZIA inventory

Assign a ZIA API role to the API client in Zidentity.

License Required: the Zscaler ZIA module is not licensed or unavailable

Your tenant does not have ZIA. Clear ZIA (Internet Access).

An error names a different product, such as EASM or ZDX

That product is selected but your client cannot read it. Clear it, or assign its API role.

Domains or addresses are missing from Assets

A domain may not resolve in public DNS or may resolve to a cloud provider. An address may be private, in a cloud provider range, or not answer ping. See What the integration does.

If you need help with this integration, contact support@praetorian.com.