Group Purchasing
Group Purchasing

Closing the Gaps: Zero Trust Microsegmentation in Hybrid Cloud with Zscaler

Closing the Gaps: Zero Trust Microsegmentation in Hybrid Cloud with Zscaler (PDF, 3.34MB)Published: 26 Sep, 2025
Created by:

Thank You To Our Sponsor

Closing the Gaps: Zero Trust Microsegmentation in Hybrid Cloud with Zscaler, published by SANS Institute in September 2025, documents a hands-on technical review of Zscaler Microsegmentation, an extension of the Zscaler Private Access platform. The review examines how the product delivers real-time asset discovery, granular policy enforcement, and unified zero trust controls across cloud and on-premises environments, tested in an AWS-based lab environment.

Key findings:

  • Zscaler Microsegmentation performs real-time asset discovery using metadata tags or cloud attributes like VPC or VNet identifiers, as well as on-premises assets identified by IP address or subnet definition
  • Deployment relies on installing an agent that automatically connects to the Zscaler cloud, performs certificate exchange, and adds the asset to account inventory, with dynamic AWS-tagged assets added to a resource group in under 30 seconds during testing
  • The platform registers with OS-specific enforcement mechanisms for network control, including Windows Filtering Platform and Linux NFTables, and uses Extended Berkeley Packet Filter (eBPF) for containerized workloads
  • Beyond standard Allow and Block policy actions, the platform offers a "Sim Block" action that permits traffic while generating alerts, useful for testing and tuning policies before full enforcement
  • Resource groups can be static (manually defined "known" assets), dynamic (automatically populated based on attributes and metadata), or unmanaged (added by IP address or subnet range for assets that can't run an agent)
  • The Application Map dashboard provides a visual representation of AppZones and asset relationships, letting reviewers click into connector lines to see the specific policy governing that communication path
  • Flow logs are retained and can be exported for 14 days, with Zscaler deduplicating repeated log entries of the same type, such as consolidating multiple DNS queries into a single entry
  • The product includes a machine learning-based recommendation feature for resource group assignment, though the review notes this feature was not fully explored during testing
  • A recommended zero trust microsegmentation project follows two phases: agent deployment and identification of test hosts, followed by a monitoring and visibility period of at least one to two weeks before enabling Block policies
  • A full proof of concept is recommended to run over a four- to six-week window, with production deployments taking substantially longer given more varied assets and larger environments
  • The review's overall assessment was that the platform's interface was intuitive for creating and assigning grouping, categorization labels, and policies, with no issues encountered during testing

The review's conclusion is that microsegmentation remains one of the most sought-after zero trust capabilities, but also one of the hardest for organizations to implement and sustain, with many initiatives failing before they get fully underway. Based on hands-on testing, Zscaler Microsegmentation was found to complement Zscaler's broader zero trust portfolio (ZTNA, cloud-based access controls) in a way that gives both IT operations and security teams practical, shared telemetry for troubleshooting, performance tuning, and policy enforcement. The review was conducted in a lab environment with agents deployed across AWS-based web, application, and database tier assets, testing agent deployment, resource grouping, policy creation, and the platform's flow log, telemetry, and dashboard capabilities directly.

Closing the Gaps: Zero Trust Microsegmentation in Hybrid Cloud with Zscaler

Related Webcast

In this webcast, SANS will share results from an in-depth hands-on review of Zscaler Microsegmentation, revealing how it enables real-time asset discovery, granular policy enforcement, and unified Zero Trust controls across cloud and on-premises environments.

Woman watching webcast on screen

FAQ

It's an extension of the Zscaler Private Access (ZPA) platform that provides real-time asset discovery, granular workload-level policy enforcement, and zero trust controls across both cloud and on-premises environments, deployed via an installed agent on each asset.

It discovers cloud assets using metadata tags or cloud attributes such as VPC or VNet identifiers, and discovers on-premises assets using IP addresses or network subnet definitions. In SANS testing, AWS-tagged assets were added to a dynamic resource group in under 30 seconds.

Sim Block is a policy action that allows traffic to pass through while still generating alerts, as if the traffic had been blocked. It's designed for testing and tuning, letting teams see what a stricter policy would catch before enforcing it.

The recommended timeline is four to six weeks, covering agent deployment, a monitoring period of at least one to two weeks to observe real traffic patterns, and a review of enforcement logs before moving from Allow/Sim Block policies to full Block enforcement.

The research notes that microsegmentation is one of the most sought-after zero trust capabilities but also one of the most difficult to implement and maintain, with many initiatives failing before they're fully underway, typically due to the operational burden of tracking policy and performance issues without a phased rollout plan.

Yes. The platform supports both physical and virtual systems, cloud APIs, and containers, allowing organizations to segment workloads across cloud and on-premises environments without relying solely on static IPs or manual rule creation, and it supports AWS, Azure, GCP, and on-premises deployment targets. 

Meet Your Author

Dave Shackleford
Dave Shackleford

Dave Shackleford

Senior Instructor

Cybersecurity leader Dave Shackleford combines decades of enterprise defense, cloud security, and hands-on consulting experience to help students master real-world security operations and modern threat defense.

Read more about Dave Shackleford