Blog da Zscaler

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Products & Solutions

Private Access That Scales With Your App Catalog

image
SANJOG SAHU
August 06, 2026 - 5 Min. de leitura

As your private app environment grows, the real challenge isn’t creating secure access. It’s keeping access fast and manageable while the number of internal apps keeps climbing. ZPA Application Scaling is a built-in capability that lets ZPA support very large private app catalogs by sending user devices running Zscaler Client Connector (ZCC) a smaller “parent domain” list, and letting the ZPA cloud confirm the exact app and policy decision only when it’s needed.

In other words: ship the index, not the entire catalog. That’s the core idea and it’s what makes large-scale private access stay smooth as you grow.

Why App Growth Creates Scaling Pressure

In a large enterprise, application growth is normal:

  • Business units add new internal apps
  • Teams create new environments and hostnames
  • Acquisitions bring in whole new sets of domains
  • “Temporary” systems stick around

Security teams don’t want growth to create a new kind of work: bigger configs, heavier client updates, and more time spent managing app definitions.

The capability goal here is to keep the experience consistent even as the number of private apps grows.

What ZPA Application Scaling Changes

ZPA Application Scaling changes what ZPA sends to ZCC so you can publish and control access to far more private apps without making the client heavier. Instead of sending ZCC a full list of all private app definitions, ZPA sends a smaller list of parent domains (TLD+1 domains like acme.com).

A clean mental model I like to use to think about this is: Don’t hand every device the full corporate directory. Give it the index and look up details when someone actually asks.

How it Works

  1. ZPA sends ZCC a short list of parent domains. Example: ZCC receives acme.com, not 1.acme.com through 10.acme.com.
  2. When a user goes to something under that domain, ZCC asks ZPA: “Is this a private app we publish, and what should happen?”
  3. ZPA evaluates policy and DNS and returns a decision (allow, block, or bypass).
  4. ZCC caches the result so repeat access is fast. If the destination isn’t a private app, ZCC routes it based on your forwarding setup (through ZIA or directly to the internet).

What Customers Get: Bigger Scale, Lighter Clients, Easier Operations

1) It supports much larger app catalogs

With Application Scaling, customers can expand from roughly 6,000 applications to approximately 100,000 applications per tenant. That matters because it turns “app growth” into a normal operational event and not a scaling project.

2) It keeps the client lighter as you grow

Because ZCC receives less configuration data, you typically improve:

  • Startup time
  • Policy download size
  • Device resource usage

3) It supports modern ways to organize access at scale

Application Scaling is also the foundation for advanced segmentation features like:

  • Pattern Match
  • Multimatch
  • Metadata Tagging

And the overview is explicit that future ZPA enhancements will depend on Application Scaling being enabled, so enabling it is also a way to stay aligned with the platform’s direction.

More than Scale: A Foundation for What’s Next

With Application Scaling enabled, ZPA supports up to 100,000 application segments per tenant. But this is not just about supporting larger environments. Application Scaling is also a foundational prerequisite for several current and upcoming capabilities, including Policy Modernization, B2B Federation, and Increased Access Policy Limits. Going forward, Application Scaling is expected to be a standard prerequisite for most new ZPA features that depend on enhanced scalability and a modernized policy architecture, so enabling it helps you take advantage of capabilities available today and stay ready for what’s coming next.

What this Looks Like for Customers Today

ZPA Application Scaling is how ZPA stays simple and fast when your private app environment stops being “a few important apps” and becomes “the full internal universe.” It does that with one clean shift: ZCC carries a small index of parent domains, ZPA confirms the exact destination and policy decision when needed, and ZCC caches the result. 

For customers today, ZPA Application Scaling is mostly invisible, in a good way. Users keep connecting to the same private apps, but the system is built to stay fast and manageable as the private app catalog grows. The practical difference shows up behind the scenes: ZCC carries a smaller “index” of domains, ZPA confirms the exact destination and policy in the cloud when needed, and ZCC caches the result. The outcome is that customers can expand from thousands of apps toward ~100,000 apps per tenant without turning app growth into bigger client payloads, slower startup, or a new operational ceiling. 

Current ZPA customers don’t need to do anything day-to-day and there’s no user workflow change. If you want to ensure Application Scaling is enabled for your tenant, the next step is to open a backend support ticket. Once your environment meets the standard prerequisites (like supported component versions), Zscaler will turn the feature on for you.* If you’re new to Zscaler and evaluating private access for a large application environment, ask your Zscaler account team for a ZPA demo and an overview of Application Scaling.

*Roadmap note: A dedicated per-platform setting for Application Scaling is planned for a future release (expected after February 2027). For now, enablement is handled via a backend support ticket.

form submtited
Obrigado por ler

Esta postagem foi útil??

Aviso legal: este post no blog foi criado pela Zscaler apenas para fins informativos e é fornecido "no estado em que se encontra", sem quaisquer garantias de exatidão, integridade ou confiabilidade. A Zscaler não se responsabiliza por quaisquer erros, omissões ou por quaisquer ações tomadas com base nas informações fornecidas. Quaisquer sites ou recursos de terceiros vinculados neste post são fornecidos apenas para sua conveniência, e a Zscaler não se responsabiliza por seu conteúdo ou práticas. Todo o conteúdo está sujeito a alterações sem aviso prévio. Ao acessar este blog, você concorda com estes termos e reconhece que é de sua exclusiva responsabilidade verificar e utilizar as informações conforme apropriado para suas necessidades.

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Ao enviar o formulário, você concorda com nossa política de privacidade.