Zenith Live 2019 Keynotes Watch Now
Zenith Live 2019 Keynotes Watch Now

Transforming the Enterprise

Watch Keynotes
Products > ZPA for Azure

Your apps moved to Azure,
but how are you securing access to them?

Time for a better approach to secure remote access

Request Demo

Network-centric security makes moving to Azure painful

Today 40% of enterprises are running apps in Azure to increase scalability and speed. This move has extended the perimeter to the internet. Yet, many enterprises still rely on remote access VPNs, which are network-centric, and not built to secure access to the internet. They also place users on the network, and require physical or virtual appliances that increase complexity and limit scalability.

Common pitfalls of network-centric approaches:
  • Places users on-net to provide access to Azure
  • Requires appliances, ACLs and FW policies
  • Provides a poor end user experience
  • Inbound connections create opportunity for DDoS attacks
  • No ability to provide true application segmentation
  • Lack visibility into app-related activity
diagram of remote user Internet-bound traffic routed through a data center security stack before it heads to the azure cloud and returns

Zscaler Private Access for Azure

Enabling user and application-centric security for Azure

Zscaler Private Access (ZPA) for Azure is a cloud service from Zscaler that provides zero-trust, secure remote access to internal applications running on Azure. With ZPA, applications are never exposed to the internet, making them completely invisible to unauthorized users. The service enables the applications to connect to users via inside-out connectivity versus extending the network to them. Users are never placed on the network. It provides a software-defined perimeter for Azure, that supports any device and any internal application.

Read the Solution Brief
a diagram showing ZPA solution delivers a direct-to-cloud experience for all users, taking them quickly to the app that runs within Azure
See Our Solution View the Challenge

Zscaler Private Access for Azure benefits

Better remote user experience

Users have fast, direct-to-cloud access without having to login to remote access VPN client each time.

Less complexity for admins

Network admins can segment based on application from within the web UI. No need to segment by network. No IP address segmentation or access control lists required.

Secure remote access, w/o network access

Policy based access, with no access to network. Visibility into apps being accessed by users and ability to discover unsanctioned apps running within Azure.

Traffic remains private via internet network

Service uses dynamic, application specific TLS-based end to end encryption. All data remains private and enterprises can bring their own PKI.

No hardware appliances, lower costs

The cloud service requires no hardware. Enterprises can easily scale across multiple Azure and Zscaler data centers with no need to replicate gateways.

Scale elastically, reduce latency

The service uses the global Azure network to ramp up new users and route them to the app location nearest to them via internet-based networking.

Simplify secure remote access to internal apps on Azure

Zscaler Private Access takes a user and application-centric approach to network security. It ensures that only authorized users and devices have access to specific internal applications on Azure. Rather than relying on physical or virtual appliances, ZPA uses lightweight infrastructure agnostic software to connect both users and applications to the Zscaler Security Cloud, where the brokered connection is stitched together. ZPA is complementary to Azure ExpressRoute.

1.  Zscaler Enforcement Node
  • Hosted in cloud
  • Used for authentication
  • Customizable by admins
  • Brokers a secure connection between a Z-App and
    a Z-connector
2.  Zscaler App
  • Mobile client installed on devices
  • Requests access to an app
3.  App Connector
  • Sits in front of apps in the datacenter, Azure, AWS, and other public cloud services
  • Provides inside-out TLS 1.2 connections to broker
  • Makes apps invisible to prevent DDoS attacks

Leverage the Power of the Azure Network

With Zscaler Private Access for Azure, Zscaler Enforcement Nodes (ZENs), which broker access between a remote user and an internal application, run within the Azure cloud. This enables networking admins to leverage the Azure network and its many data center locations. This reduces latency by minimizing hops and boosts user productivity.

a diagram showing that enterprises can combine the benefits of the Azure cloud with the enhanced security and SDP delivered by ZPA
capture from zpa for azure showing how zpa helps enterprises to manage access to internal apps and also reduces latency

Choose application segmentation, not network segmentation

In the past admins needed to segment networks to ensure secure user connections. Today, enterprises use ZPA to control which users access which applications. Admins can easily set granular policies at the application level for specific users, users groups, applications, application groups and associated subdomains.

1.  Create and define policy names
2.  Set different permissions levels for users and user groups
3.  Define the applications each policy is associated with
4.  Easily add new rules and policies for users and applications within the UI

Key Integrations Accelerate The Journey To Azure

We have developed integrations for Azure ecosystems. Integrations with Azure AD enables admins to use ZPA to set access policies for user groups based on their existing configurations. Additionally the Z-Connector is available on the Azure Marketplace. The connector front-ends apps on Azure, and send an inside-out connection to the Zscaler Security Cloud, where the brokered connection between authorized users and application takes place.

capture showing azure marketplace enables admins to use ZPA to set access policies for user groups based on their existing configurations
capture showing the z-connectors, which sit in front of apps, also run within Azure, providing inside-out connections to the zens

Suggested Resources

Customer Story

See how MAN Energy Solutions uses ZPA to provide zero-trust access to internal apps, at global scale

Read Case Study 


Watch the ZPA for Azure webinar recording

Watch Webinar 

Case Study

Microsoft and Zscaler partner for success

Read More