Zscaler Velocity Portfolio

The complete Zscaler Velocity portfolio now available to MSPs

Zero-touch access to every product in the Zscaler catalog — no commitments, low minimums, built for MSPs to sell and deliver at scale.

ZIASecure Internet Access

The world's most deployed Security Service Edge (SSE). ZIA replaces legacy firewalls and proxies with a cloud-native zero trust proxy that inspects 100% of TLS/SSL traffic at scale.

400B+

Transactions inspected daily

100%

TLS/SSL traffic inspected

150+

Countries with coverage

2,000+

Global threat intel partners

Stop advanced threats. Protect data. Eliminate legacy hardware.

Zscaler Internet Access (ZIA) delivers a true zero trust proxy architecture built on the Zscaler Zero Trust Exchange™—the world's largest inline security cloud. Unlike legacy firewall-centric approaches, ZIA connects users directly to the internet and SaaS applications without putting them on the corporate network, dramatically reducing your attack surface.

Key Capabilities

What's included in this SKU

Secure Web Gateway (SWG)

AI-powered URL filtering, malware detection, and real-time threat intelligence for every user.

TLS/SSL Inspection

Decrypt, inspect, and re-encrypt 100% of SSL/TLS traffic at cloud scale without performance degradation.

Advanced Threat Protection

Stop ransomware, botnets, C2 callbacks, zero-day threats, and phishing in real time.

Cloud Firewall & IPS

Full Layer 7 firewall with an integrated IPS providing threat coverage against botnets and zero-day exploits.

DNS Security

Filter malicious domains, detect DNS tunneling, and stop data exfiltration before it reaches the internet.

Cloud Sandbox

Detonate unknown files in an isolated environment with AI-powered instant verdicts.

Bandwidth Control

Prioritize business-critical applications and throttle recreational traffic.

AI-Powered Phishing Detection

Detect patient-zero phishing attacks with AI that analyzes page content, behavior, and intent in real time.

GenAI App Security

Inspect user prompts submitted to generative AI tools like Microsoft Copilot and ChatGPT inline.

Nanolog & SIEM Streaming

Stream granular log data to your on-premises SIEM or cloud log aggregator in real time.

Direct-to-Cloud Performance

Eliminate backhaul. ZIA connects users directly from 160+ data centers globally.

Shadow IT & CASB

Gain full visibility into unsanctioned cloud app usage and control data flows across SaaS apps.

Why MSPs choose ZIA for their clients

ZIA replaces the complexity of branch firewalls and proxy appliances with a single cloud service.

Inspect 100% of encrypted traffic without hardware or performance penalties
Protect remote, hybrid, and in-office users with identical policies
Reduce costs by eliminating branch firewalls and MPLS backhauling
Get instant threat intelligence from 400B+ daily transaction signals
Meet compliance requirements with detailed, granular audit logs
Deploy in hours, not weeks—no hardware, no appliances
AI-powered security that improves with every transaction globally
Integrated DLP, CASB, and browser isolation in a unified platform

Replace legacy secure web gateways

Decommission on-premise Blue Coat, Symantec, or Cisco WSA appliances with a cloud-native SWG.

Protect hybrid workforces

Enforce identical security policies for remote, branch, and in-office employees without backhauling.

Secure GenAI adoption

Enable safe use of ChatGPT, Copilot, and other AI tools with inline inspection and DLP.

SASE foundation

Use ZIA as the internet access pillar of a complete SASE architecture alongside ZPA.

ZPAZero Trust Private Access

The world's most deployed ZTNA solution. ZPA replaces legacy VPNs with identity-based, zero trust connectivity—connecting users directly to applications without putting them on the network.

91%

Of orgs concerned VPNs compromise security

56%

Suffered VPN-related attacks in 2023–2024

54%

Of VPN breaches involve lateral movement

#1

Most deployed ZTNA in the world

Kill the VPN. Connect users to apps, not the network.

Zscaler Private Access (ZPA) brokers direct, one-to-one connections between authorized users and specific private applications. Users never access the corporate network—apps are never exposed to the internet. ZPA's AI-powered app segmentation and context-aware policies automatically discover applications and enforce least-privilege access.

Key Capabilities

What's included in this SKU

App-Never-Exposed Architecture

Apps sit behind ZPA with no inbound internet connections—completely dark to attackers.

Identity-Based Access

Access is granted per user identity, device posture, and context—not by network location.

AI-Powered App Segmentation

Automatically discover private applications and receive AI-generated recommendations for access policies.

Workload-to-Workload Segmentation

Secure cloud workload communications across hybrid and multi-cloud environments.

AppProtection

Full inline Layer 7 inspection of private app traffic, protecting against web attacks and API abuse.

Private Service Edge

Bring ZTNA on-premises for low-latency, direct access to private apps in the data center.

Advanced Threat Protection

Always-on ransomware protection, zero-day threat prevention for all private application traffic.

Third-Party & Contractor Access

Enable zero trust access for vendors and contractors without installing agents.

Browser Access

Provide seamless access to internal web apps through a browser—no client required.

Business Continuity

Ensure uninterrupted, policy-enforced access to mission-critical applications.

Inline Data Loss Prevention

Prevent data loss across private app traffic with full inline DLP inspection.

Deception & Active Defense

Deploy decoy applications to detect lateral movement and insider threats.

Replace VPNs. Eliminate lateral movement.

ZPA can replace legacy VPN and VDI solutions in hours—delivering better security, better performance, and dramatically less complexity.

Eliminate inbound firewall rules—apps are invisible to the internet
Stop lateral movement with user-to-app microsegmentation
Deploy in hours, not weeks—replaces VPN with zero hardware
Context-aware policies based on identity, device, and location
AI automatically discovers apps and recommends access policies
Scale from 5 to 50,000 users without infrastructure changes
Unified management across on-prem, cloud, and SaaS apps
Full inline inspection with AppProtection and threat prevention

VPN replacement

Migrate clients off Cisco AnyConnect, Pulse Secure, or Fortinet VPN to zero trust access in days.

M&A & third-party access

Connect acquired companies and contractors to specific apps without network merges.

Cloud & hybrid app access

Provide consistent access to apps in AWS, Azure, GCP, and on-premises data centers.

Zero trust for OT/IoT

Extend ZTNA to operational technology and industrial environments.

PRAPrivileged Remote Access

A clientless remote desktop gateway built on zero trust. PRA enables secure RDP, SSH, and VNC access to critical IT and OT systems without exposing jump hosts to the internet.

100%

Browser-based, no client required

RDP/SSH/VNC

All major protocols supported

Zero

Inbound internet connections to OT/IT

JIT

Just-in-time access enforcement

Secure privileged access without exposing your infrastructure.

Zscaler Privileged Remote Access (PRA) is a clientless remote desktop gateway that enables end users, third-party contractors, and IT administrators to securely connect to servers, jump hosts, and OT/IIoT systems directly from a browser. Unlike legacy PAM tools, PRA builds on the Zscaler Zero Trust Exchange to broker secure, policy-enforced sessions with full session recording and audit trails.

Key Capabilities

What's included in this SKU

Clientless Browser Access

Users access RDP, SSH, and VNC sessions entirely within a browser—no client software, no VPN required.

Session Recording

Every privileged session is recorded end-to-end for compliance audits and forensic analysis.

Just-in-Time (JIT) Access

Grant temporary, time-limited privileged access that auto-revokes after the session window expires.

Full Audit Trail

Log every command, keystroke, and action with tamper-resistant audit logs for compliance.

Privileged Credential Management

Manage and rotate privileged credentials with integrations to leading PAM vaults.

Real-Time Session Monitoring

IT admins can observe live sessions, send alerts, or terminate sessions if suspicious activity is detected.

Protocol Isolation

Full isolation for SSH, RDP, RealVNC, and VNC with configurable clipboard controls per policy.

Third-Party & Contractor Access

Zero trust privileged access for external vendors without providing VPN access or exposing jump servers.

OT & IIoT Access

Extend zero trust privileged access to operational technology and industrial IoT environments.

Multi-Factor Authentication

Enforce MFA at every privileged session initiation, integrating with your existing IdP.

File Sandboxing

Isolate and scan files transferred during privileged sessions to prevent malware from reaching critical systems.

Granular Access Policies

Define per-system, per-user, and time-based access policies with role-based controls.

Replace legacy PAM with zero trust privileged access

Traditional PAM tools require deploying jump servers, agents, and complex infrastructure—PRA eliminates this complexity with a cloud-delivered approach.

No jump servers or bastion hosts exposed to the internet
Clientless access from any browser—no agents to manage
Full session recording for compliance (SOC2, HIPAA, PCI-DSS)
JIT access eliminates standing privilege and reduces insider risk
Works for IT admins, contractors, and third-party vendors
Integrates with existing PAM vaults (CyberArk, BeyondTrust)
Extend zero trust to OT/IIoT infrastructure
Audit-ready logs for every privileged session

IT admin remote access

Replace RDP over VPN with browser-based zero trust sessions for internal IT staff.

Third-party vendor access

Grant time-limited, session-recorded access to contractors managing client infrastructure.

OT/IIoT environments

Secure access to industrial control systems, PLCs, and SCADA infrastructure.

Compliance & audit requirements

Meet SOC2, HIPAA, PCI-DSS, and NERC-CIP requirements with full session recording.

ZDXDigital Experience Monitoring

AI-powered end-to-end digital experience monitoring delivered as a service. ZDX gives IT teams full visibility across devices, networks, and applications—proactively detecting and resolving performance issues.

52%

Faster mean time to resolution

20%

Fewer work hours lost to IT issues

74%

Of orgs have 1+ outage per quarter

Zero

Additional infrastructure to deploy

Full visibility from endpoint to app—across every hop.

Zscaler Digital Experience (ZDX) is the only DEM solution that monitors performance from within users' devices, across multiple networks, through the Zscaler cloud, and all the way to SaaS, cloud, and data center applications. With AI-powered root cause analysis and the Zscaler Copilot AI assistant, IT teams can rapidly identify whether a performance issue is a device problem, Wi-Fi issue, ISP problem, or application degradation.

Key Capabilities

What's included in this SKU

User Experience Scoring

ZDX Score provides per-user, per-department, and global views of digital experience quality.

AI-Powered Root Cause Analysis

Instantly isolate whether issues are caused by the device, Wi-Fi, ISP, Zscaler service, or the application.

Zscaler Copilot AI Assistant

Ask performance questions in natural language. Copilot investigates and surfaces anomalies.

Device Health Monitoring

Monitor CPU, memory, battery, and process utilization on user endpoints.

Network Path Analysis (CloudPath)

Trace performance across every network hop—from the user's device through to the application.

Application Performance Monitoring

Probe SaaS and cloud app availability and performance from user devices and global probing locations.

Proactive Alerting

Receive alerts via email, Slack, Teams, or ServiceNow when ZDX detects anomalies.

ISP & WAN Insights

Identify ISP degradations and outages across your entire user population.

Executive & IT Dashboards

Customizable dashboards for executive overviews and deep-dive IT troubleshooting.

ServiceNow & API Integration

Auto-create ServiceNow tickets from ZDX anomalies with the REST API.

Self-Service Remediation

Empower end users to self-diagnose and fix issues with AI-guided step-by-step instructions.

Zero-Deploy Enablement

ZDX is enabled with a single switch in the Zscaler console—no additional agents or hardware required.

Stop reactive IT firefighting with proactive visibility

Legacy monitoring tools can't see inside the Zscaler path or correlate device, network, and app metrics. ZDX is purpose-built for the zero trust era.

52% faster MTTR—identify root cause in seconds, not hours
20% fewer work hours lost to IT-related downtime
Reduce help desk tickets with proactive issue detection
No additional infrastructure—runs on Zscaler Client Connector
Single pane of glass for device, network, and app health
Correlate security events with performance issues in one platform
AI assistant answers performance questions in plain English
Works for remote, office, and hybrid users identically

Help desk triage acceleration

Arm the help desk with root cause analysis before the first call—cut average handle time by over 50%.

Office 365 & SaaS performance

Monitor Microsoft 365, Salesforce, Zoom, and other critical SaaS apps end-to-end.

ISP and WAN diagnostics

Identify and document ISP degradations with objective, data-driven evidence.

Remote worker visibility

Get full visibility into the experience of home-based and distributed users.

Ready to add Zscaler to your stack?

No contracts. Low minimums. Monthly invoicing. Start protecting clients today.