Blog de Zscaler

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Products & Solutions

What's New in GovCloud: September 2026 Zscaler Product Updates

image
JOSE ARVELO NEGRON
September 30, 2026 - 7 min read

With fiscal year-end, audit cycles, and shifting mission priorities all competing for attention, it's easy for product updates to stack up unread. Here is a curated roundup of notable Zscaler GovCloud updates from September, with quick context and scan-friendly takeaways you can share across security, network, and operations teams. Highlights include the rollout of Experience Center (a unified management console for the Zero Trust Exchange platform), AI-powered application segment recommendations in ZPA, a fully managed Zero Trust Gateway offering in AWS, and expanded DLP controls for Google Drive link expiration and Claude tenant profiles in ZIA.

Experience Center, Unified Management Console

Zscaler has started rolling out Experience Center to GovCloud. Experience Center is a unified, cloud-native management console for the Zscaler Zero Trust Exchange platform. It is designed for CISOs, CIOs, network administrators, cybersecurity practitioners, and service desk teams who manage zero trust security policies, endpoint agents, internet and SaaS access, private application access, and digital experience monitoring.

Experience Center consolidates these management functions into a single interface with persona-driven workflows, role-based access control, and unified analytics, replacing the fragmented multi-console workflows that traditional point product environments require.

For more details, check out our blog.

Zscaler Internet Access (ZIA)

Zscaler Internet Access (ZIA) is Zscaler's secure internet and SaaS access service, providing policy-based protection and visibility for users wherever they work. For many federal environments, ZIA is central to enforcing acceptable use, protecting sensitive data, and maintaining consistent security controls across a distributed workforce.

This month's ZIA updates expand governance controls for generative AI applications, strengthen DLP capabilities with proximity matching and automated link expiration, and extend cloud app control for Google Gemini.

Highlights

  • Support for Claude in Tenant Profile: The Tenant Profiles feature now extends to the Claude application, allowing admins to provide access to specific workspace IDs for Claude. This helps agencies govern AI application usage at a tenant level. (FedRAMP Moderate and High)
  • Support for External Link Expiration in Google Drive: Admins can now set periodic or custom expiration periods for Google Drive links (internal or external), after which file access is automatically revoked. Four new expiration-based actions are available in the Edit DLP rule window (Remove Collaborators, Remove External Sharing Links, Remove Internal Sharing Links, and Remove Sharing After Expiry), with manual expiration available under Remediation Actions on the SaaS Assets with Incidents page and matching fields added to the /casbDlpRules APIs. (FedRAMP Moderate)
  • Support for New Match Type on Custom DLP Dictionaries: Custom DLP dictionaries now support near and not-near proximity matching, letting admins define how close (in bytes) phrases from phrase groups must be for a dictionary to detect and count them as a match. This adds precision to content detection without requiring additional dictionaries. (FedRAMP Moderate and High)
  • Cloud App Control Policy: Upload Action for Google Gemini: The Cloud App Control policy now supports a granular Uploading action for the Google Gemini application and its instances, added under Allow application access in the Add/Edit AI & ML Rule window. (FedRAMP Moderate and High)
  • Expanded SSPM Controls for Box: Four new Advanced SaaS Security Posture Management controls were added for Box. (FedRAMP Moderate and High)

For full release notes: https://help.zscaler.us/zia/release-upgrade-summary-2026

Zscaler Private Access (ZPA)

Zscaler Private Access (ZPA) provides secure, zero trust connectivity between users and private applications without exposing those applications to the internet. It helps organizations reduce attack surface while improving access experience, which is especially important for distributed users, mission partners, and hybrid work environments common across federal agencies.

This month's ZPA updates introduce AI-powered capabilities in Limited Availability that help teams optimize application segment configuration and gain visibility into segment usage patterns.

Highlights

  • AI Recommendations for Application Segments (Limited Availability): ZPA now offers AI-powered recommendations for application segments. This feature analyzes user logs and suggests application segments based on application similarity or user behavior, helping teams refine their segmentation strategy and reduce manual configuration effort. (FedRAMP Moderate and High)
  • Application Segments Usage (Limited Availability): Admins can now view or download Application Segments Usage reports from the Zscaler Admin Console to review which application segments are actively used and which user groups are accessing them. This provides visibility that supports access reviews and optimization. (FedRAMP Moderate and High)

For full release notes: https://help.zscaler.us/zpa/release-upgrade-summary-2026

Zscaler Digital Experience (ZDX)

Zscaler Digital Experience (ZDX) provides visibility into end-user device health, application performance, and network path quality. For federal teams managing distributed endpoints across agencies and field locations, ZDX helps identify and resolve experience issues before they impact productivity or mission delivery.

This month's ZDX updates deliver Cloud Path probe enhancements and a refreshed filter design across the console.

Highlights

  • TCP Type Enhancements: Admins can now select a specific TCP traceroute type when configuring a Cloud Path probe. Resilient TCP retries using the Conventional TCP type if the initial connection fails, while Strict TCP does not fall back if the connection fails. These options give teams more control over probe behavior in environments where firewalls may block SYN-based traceroutes. (FedRAMP Moderate and High)
  • Design Update for Filters: Filters across ZDX have been updated with a new color palette and typography for improved readability and consistency. (FedRAMP Moderate and High)

For full release notes: https://help.zscaler.us/zdx/release-upgrade-summary-2026

Zscaler Client Connector

Zscaler Client Connector is the unified endpoint agent that steers traffic to ZIA, ZPA, and ZDX services. It ensures consistent policy enforcement regardless of where users connect from, which is critical for agencies supporting remote and hybrid workforces.

This month includes a significant Windows release, an Android/ChromeOS update addressing multiple security vulnerabilities, and Admin Console fixes.

Highlights

  • Zscaler Admin Console 4.5.5: Fixes a pagination issue affecting user search results on the Enrolled Devices page, a Device Details file download timeout, a blank Protocol dropdown when adding a custom IP-based application bypass in Experience Center, and a sync issue where users added to groups already entitled to Private Access did not receive access after Update Policy. (FedRAMP Moderate, August 14; FedRAMP High, August 7)
  • Zscaler Client Connector 4.9.0.465 for Windows: Addresses a range of stability and connectivity issues, including a stuck Restarting service status, Internet Unreachable errors over machine tunnels in no-default-route environments with an explicit proxy, partner-tenant reauthentication failures, slow connections with many hostname-based trusted networks, Endpoint DLP detection when enabled pre-enrollment, disconnections with FIPS libraries, several VDI re-enrollment and AWS Windows Server issues, slow app loading from loopback proxy delays, and excessive memory use with unsupported certificates. Parallel maintenance releases 4.8.0.300 and 4.7.0.376 shipped the same day.
  • Zscaler Client Connector 4.2.0.173 for Android and ChromeOS: Adds support for the ind.zscalertwo.net subcloud, fixes multiple Firebase-reported crashes, and addresses security vulnerabilities including a local denial-of-service vector (CVSS 7.0), remote code execution vulnerabilities (CVSS 7), and an authentication bypass for portal-only communications (CVSS 6.8). Also fixes a ChromeOS-only authentication failure with Google Workspace Always On VPN and improves Z-Tunnel 2.0 and Private Access reconnection after connectivity is restored. A follow-up release, 4.2.0.174, fixes a reauthentication failure introduced in 4.2.0.173.
  • Additional Releases: Windows 4.9.0.455 and 4.8.0.291 include installer mitigation logic for a rare blue-screen upgrade condition, a Firewall posture check fix, and a captive-portal high-CPU fix.

For full release notes: https://help.zscaler.us/client-connector/release-upgrade-summary-2026

Cloud & Branch Connector

Zscaler Cloud & Branch Connector helps extend Zscaler policy enforcement and traffic forwarding for workloads running in public cloud environments. It supports organizations that need consistent security controls for cloud-hosted services while enabling architectures aligned to modernization initiatives.

This month introduces a fully managed, cloud-native security offering in AWS, available in Limited Availability.

Highlights

  • Zscaler Zero Trust Gateways in Amazon Web Services (Limited Availability): Zscaler has introduced a fully managed, cloud-native SaaS security offering in AWS that allows organizations to secure workload traffic and eliminate the need to manage security infrastructure in their AWS environment. It provides the same security controls for cloud-to-internet and cloud-to-cloud communication. Zscaler supports AWS commercial on the FedRAMP Moderate cloud. (FedRAMP Moderate)

For full release notes: https://help.zscaler.us/cloud-branch-connector/release-upgrade-summary-2026

Authentication Service (Zidentity)

The Zscaler Authentication Service (Zidentity) provides centralized identity and access management for the Zscaler platform. It supports authentication policies, MFA enforcement, and user lifecycle controls that help agencies meet identity-centric zero trust requirements.

Highlights

  • Customize Password Policy: Admins can configure the password policy to deactivate a user account after a specific number of unsuccessful authentication attempts and reject a specific number of previously used passwords. Both values are customizable from 3 to 10 in the Zscaler Admin Console. (FedRAMP Moderate and High)

For full release notes: https://help.zscaler.us/zidentity/release-upgrade-summary-2026

Conclusion

Want the full details? Use the links above to review the complete release summaries, and check back next month for the next GovCloud update roundup.

Zscaler continues to invest in a robust GovCloud roadmap and remains committed to supporting the unique security, compliance, and operational requirements of the federal market. We'll keep delivering enhancements that help agencies and federal partners strengthen resilience, simplify operations, and advance mission success.

form submtited
Gracias por leer

¿Este post ha sido útil?

Descargo de responsabilidad: Esta entrada de blog ha sido creada por Zscaler con fines únicamente informativos y se proporciona "tal cual" sin ninguna garantía de exactitud, integridad o fiabilidad. Zscaler no asume ninguna responsabilidad por cualquier error u omisión o por cualquier acción tomada en base a la información proporcionada. Cualquier sitio web de terceros o recursos vinculados en esta entrada del blog se proporcionan solo por conveniencia, y Zscaler no es responsable de su contenido o prácticas. Todo el contenido está sujeto a cambios sin previo aviso. Al acceder a este blog, usted acepta estos términos y reconoce su exclusiva responsabilidad de verificar y utilizar la información según convenga a sus necesidades.

Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler

Al enviar el formulario, acepta nuestra política de privacidad.