This is the full catalog of what the Analysis Engine
checks in your tenant. The current build ships 86 templates:
| Family | Count | Applies to |
|---|
| Named ZIA analyses | 19 | ZIA and Experience Center tenants |
| Named ZPA analyses | 15 | ZPA and Experience Center tenants |
| Unreachable policies and assignments | 28 | Both planes, one variant per entity type |
| ZCC configuration checks | 24 | Experience Center tenants |
A template is not a single check. One template usually evaluates many settings and runs once per
affected object: the ATP settings template alone compares 22 individual options against their
recommended values, and an entity-level template runs against every entity of its type, so a tenant
with 136 URL categories runs that template 136 times. Counting templates, which is what this page
does, gives you the smallest and most stable number. Counts you see elsewhere may be counting the
individual settings or the evaluations performed, which are much larger.
How to read these tables
- Severity is the template’s baseline. Most templates compute the real severity per finding, so
an individual result can land higher or lower depending on how bad the instance is.
- Scope says what a finding is attached to: an entity (one finding per affected object), an
entity type (one aggregate finding for the whole set), or the tenant.
- Fix says whether the template can generate a proposed change you can stage in
Pending Changes. Twelve templates can:
eleven on ZIA and one on ZPA, the DNS port check. Everywhere else the finding tells you what to
change and where, and you make the change in the Zscaler console. The staging path belongs to the
template, not to the entity type: two findings on the same SSL inspection policy can differ, one
offering the buttons and the other not.
- Advanced marks templates that read traffic logs or run heavier computations. They are gated
and may not be enabled on every tenant, and some also need OneAPI.
ZIA templates
Threat protection
| Template | Severity | Scope | Fix | What it checks |
|---|
| ATP Settings: Security Features Activation | High | Entity | Yes | Whether the recommended Advanced Threat Protection features are enabled. Each disabled feature narrows protection against a specific threat class. |
| ATP Settings: Risk Tolerance Review | Medium | Entity | Yes | Whether the ATP risk tolerance sits below the recommended threshold. |
| ATP Security Exceptions: File Blocking | Low | Entity | Yes | Whether unscannable files and password-protected archives are blocked. Files that cannot be inspected should not pass by default. |
| ATP Security Exceptions: Bypass URLs Review | Medium | Entity | Yes | The ATP bypass URL list. Every entry is a blind spot where ATP does not apply. |
| Malware Protection Best Practices | High | Entity | Yes | Whether malware protection blocks the full set of threat types according to best practice. |
SSL inspection
| Template | Severity | Scope | Fix | What it checks |
|---|
| SSL Inspection Bypassing CDN Category ⭐ | Critical | Entity | No | Do-not-inspect rules covering CDN categories. CDNs host arbitrary customer content, so a blanket bypass is a large uninspected surface. |
| SSL Bypass Skipping Other Policies | Critical | Entity | No | Bypasses that also skip the rest of the policy chain, graded by how much traffic each one exempts from inspection. |
| SSL Inspection: Legacy TLS Versions | High | Entity | Yes | Policies still allowing TLS 1.0 or 1.1 on client or server connections, in both decrypt and do-not-decrypt actions. |
| Missing/Misconfigured ANY/ANY Inspect Catch-All ⭐ | Medium | Entity type | Yes | Whether a correctly configured final ANY/ANY inspect rule exists, so traffic no specific rule matches is still inspected. |
| Apple Device SSL Exception Configuration ⭐ | Medium | Entity type | No | Whether the SSL exceptions Apple requires for device setup, management and core services are present. |
| Android Device SSL Exception Configuration ⭐ | Medium | Entity type | No | Whether the SSL exceptions Android Enterprise requires are present. |
| SSL Inspection Traffic Analysis (Last 30 Days) ⭐ | Info | Entity type | No | The actual inspection rate over 30 days of web logs, with daily trend. This is the check that gates the ZIA posture score. |
Firewall
| Template | Severity | Scope | Fix | What it checks |
|---|
| Firewall Rule Uses Wildcard Network Services (TCP_ANY / UDP_ANY) | Critical | Entity | No | Rules using TCP_ANY or UDP_ANY. These cover every port for the protocol, making a rule far broader than it reads. |
| Firewall Policy QUIC Exposure Analysis ⭐ | Critical | Entity type | Yes | Whether the policy as a whole effectively blocks or allows QUIC on UDP/443 and UDP/80, evaluated in rule order. |
| This Firewall Rule Allows QUIC Traffic ⭐ | Medium | Entity | Yes | Which specific rule is the QUIC leak, given the policy evaluation order. QUIC that escapes inspection is traffic you never see. |
| Default Firewall Rule Should Block | High | Entity type | No | Whether the final default rule blocks rather than allows. Deny-by-default is the baseline; a default-permit firewall only stops what an explicit rule catches. |
Locations, categories and identity
| Template | Severity | Scope | Fix | What it checks |
|---|
| Location Firewall Control Disabled | Medium | Entity | Yes | Locations with Firewall Control off. Clients from those locations never reach the firewall policy engine. |
| Redundant URL Entries | Low | Entity | Yes | URLs already covered by a wildcard entry in the same category, across both custom and DB-categorized lists. |
| IdP Certificate Expiry Monitor | Critical | Entity type | No | SAML IdP certificate expiry dates, with warning ahead of time. An expired certificate locks every user out of SSO. |
ZPA templates
Access policy exposure
| Template | Severity | Scope | Fix | What it checks |
|---|
| Catch-All Policy Detection | Critical | Entity | No | Access policies with no user or group restriction (source catch-all) or no application segment restriction (destination catch-all). Severity escalates when both are missing. |
| Missing Domain-Join Posture Enforcement | Critical | Entity type | No | Whether access policies require a domain-joined device, either per policy or through an effective high-order block rule. Without it, valid credentials from any unmanaged device reach private applications. |
| Missing EDR/Antivirus Posture Enforcement | High | Entity type | No | Whether access policies require an EDR or antivirus posture (CrowdStrike, SentinelOne, Microsoft Defender, Carbon Black or generic antivirus detection). Marker postures such as a registry key or file path never count. |
Both posture templates read the full policy condition tree, so machine-tunnel scoped rules and
block rules are excluded rather than counted as gaps. They are powered by the classified posture
families described in
ZCC Posture Profiles.
Application segments
| Template | Severity | Scope | Fix | What it checks |
|---|
| Broad Scope Domain Detection | Critical | Entity | No | Segments defined with first-level wildcards, deep wildcards or large CIDR ranges, which expose more than intended. |
| DNS Port (53) Exposed on Application Segment | High | Entity | Yes | Segments exposing TCP or UDP port 53. In ZPA, DNS resolution belongs to the App Connector, not the endpoint. The fix removes port 53 and cleanly splits any wider range around it. |
| Unused Application Segment | High | Entity | No | Segments no enabled access or client forwarding policy references. ZPA defaults to block, so they are configured but unreachable. Severity escalates when the segment is also broad. |
| Unused Application Segment Group | Low | Entity | No | Segment groups no enabled policy references. |
Infrastructure and resilience
| Template | Severity | Scope | Fix | What it checks |
|---|
| Zombie Connector | Critical | Entity | No | App Connectors that are enabled but disconnected from the control channel. Severity escalates per day of disconnection, and starts higher when the group has no redundancy. |
| Connector Group Without Redundancy | Critical | Entity | No | Connector groups with zero connected connectors (critical), exactly one connected among several (single point of failure), or a deliberate single-connector deployment (noted, not alarmed). |
| Connector Deprecated Operating System | High | Entity | No | Connectors on an end-of-life OS line. No security patches, and a deprecated connector platform. |
| Connector Version Drift | Medium | Entity | No | Connectors whose version differs from the one the control plane expects, or that rolled back to an older version. |
| Application Segment At Risk | Critical | Entity | No | Segments whose access path depends on a down connector group, or only on non-redundant groups. Infrastructure risk propagated to the application boundary. |
| No Geographic Redundancy | Medium | Entity | No | Segments served by a single connector group: one data-centre event takes the application down regardless of how many connectors that group holds. |
| Segment Group With Members At Risk | High | Entity | No | Segment groups containing at-risk or non-redundant segments, rolled up. |
| App Connector Fleet Health Summary | High | Entity type | No | The whole-fleet roll-up: status counts, zombies, version drift, and the share of connector groups without redundancy. |
Unreachable policies and assignments
Two families, cloned across every entity type that can appear in policy criteria. They are the
engine behind Unreachable Policy Detection.
| Family | Baseline severity | Variants | What it detects |
|---|
| Potentially Useless (policy type) | Medium | 5 | Rules unreachable for every configured criterion, or ANY/ANY rules made redundant by a preceding ANY/ANY rule. Covers ZIA firewall, SSL inspection and URL filtering, plus ZPA access and client forwarding policies. |
| Unreachable Policy Assignments | Low | 23 | Individual criteria that can never be evaluated, because a catch-all or broader rule runs first. |
The 23 assignment variants cover, on ZIA: cloud apps, departments, destination IP groups, device
groups, device trust levels, locations, location groups, network services, network service groups,
source IP groups, URL categories, users and user groups. On ZPA: application segments, application
segment groups, client types, machine groups, platforms, posture profiles, risk factor types,
trusted networks, users and user groups.
Both families score as hygiene rather than exposure, and all variants of a family share a single
score cap between them, so a tenant with hundreds of dead assignments does not see its posture
score collapse for what is, in the end, clutter.
ZCC configuration checks
These 24 checks run on Experience Center tenants and drive
ZCC Fleet Health. Each is scored per app
profile or PAC file, per platform, and each carries the console path where the setting lives.
Because Zscaler exposes ZCC App and Forwarding profiles as read-only over the API, these checks do
not generate applicable fixes: they tell you the setting, the recommended value and where to change
it in the console.
Security
| Check | Severity | Platforms | Where the setting lives |
|---|
| DNS Domains | High | Windows, macOS, Linux | Policy → ZCC App Profile → Forwarding Profile → Tunnel Settings |
| DNS IPs | High | Windows, macOS, Linux | Policy → ZCC App Profile → Forwarding Profile → Tunnel Settings |
| Fail-Close | High | Windows, macOS, Linux | Policy → ZCC App Profile → Service Status / Tunnel Configuration |
| ZIA Protection Passwords | High | All platforms | Policy → ZCC App Profile → ZIA → Authentication |
| Anti-Tampering | Medium | Windows | Policy → ZCC App Profile → Windows → Install Options |
| Reactivate ZIA | Medium | All platforms | Policy → ZCC App Profile → ZIA → Service Status |
| ZPA Auth Expiry | Medium | Windows, macOS | Policy → ZCC App Profile → ZPA → Authentication |
| Drop QUIC | Low | iOS, Android | Policy → ZCC App Profile → Mobile → Tunnel Configuration |
| Intercept All | Info | Windows | Policy → ZCC App Profile → Tunnel Configuration |
The pairing of ZIA Protection Passwords and Reactivate ZIA is the one to read together: a
password that stops users disabling ZIA is worth little once the password circulates, unless the
profile also re-enables the service automatically after a set interval.
Resilience
| Check | Severity | Platforms | Where the setting lives |
|---|
| Dynamic Service Edge | Medium | All platforms | Policy → ZCC Forwarding Profile → ZIA Action (per network state) |
| Subcloud PAC (App) | Medium | All platforms | Policy → ZIA → PAC Files (the PAC the App Profile references) |
| Subcloud PAC (Fwd) | Medium | All platforms | Policy → ZCC Forwarding Profile → ZIA Action → Custom PAC |
| ZIA DR | Medium | All platforms | Policy → ZCC App Profile → Disaster Recovery → ZIA |
| ZPA DR | Medium | All platforms | Policy → ZCC App Profile → Disaster Recovery → ZPA |
| Machine Token | Info | Windows, macOS | Policy → ZCC App Profile → Install Options → Machine Token |
Best practice and deployment quality
| Check | Severity | Platforms | Where the setting lives |
|---|
| PAC Syntax Errors | Critical | All platforms | Administration → PAC Files |
| Z-Tunnel 2.0 | High | Windows, macOS, Linux | Policy → ZCC Forwarding Profile → ZIA Actions (per network state) |
| PAC Broad Bypass | Medium | All platforms | Administration → PAC Files |
| Drop IPv6 Traffic | Medium | All platforms | Policy → ZCC Forwarding Profile → ZIA Action → IPv6 |
| Prioritize IPv4 | Medium | Windows | Policy → ZCC App Profile → Windows → Network |
| Redirect Web | Medium | Windows, macOS, Linux | Policy → ZCC Forwarding Profile → ZIA Action → Tunnel |
| SSL Cert | Medium | Windows, macOS, Linux, Android | Policy → ZCC App Profile → Install Options → SSL |
| PAC Configured | Info | Windows, macOS, Linux | Policy → ZCC App Profile → Forwarding Profile → PAC File |
| Custom IPs | Info | Windows, macOS, Linux | Policy → ZCC App Profile → Forwarding Profile → Tunnel Settings |
Checks that do not apply to a platform are reported as not applicable rather than as failures, so a
mobile profile is never penalised for a Windows-only flag.
Notes
- Severity is computed, not fixed. The values above are the baseline. A zombie connector down
for a week scores higher than one down for an hour.
- Coverage depends on your admin role and on OneAPI. Objects a restricted Zscaler role cannot
read cannot be analysed, and a few templates only run once OneAPI credentials are configured.
- This catalog grows. New templates ship with product releases; the
changelog records them.
Related pages