Skip to content

Cloud App Sanctioned Toggle

Deciding that a SaaS application is sanctioned, or that it no longer is, should take one click from wherever you found it. It does.

This is for the shadow-IT loop: discovery surfaces an application, you make a call, and the call is staged for review like any other change.

When to use it

  • After a shadow-IT discovery, when URL intelligence or a cloud app export surfaces services nobody approved.
  • During a SaaS review, marking the applications that passed and the ones that did not.
  • When an approved tool is retired and should stop counting as sanctioned.

Where to find it in the UI

Open a cloud application anywhere ZHERO renders one: an entity card, a hover card, the drill-down drawer, or a policy that references it. The card shows the sanctioned state as a tag, Yes in green or No in red.

Step by step

  1. Open the cloud app card and find the Sanctioned line.
  2. Click the state. A confirmation asks whether to change it to the opposite state, naming which one.
  3. Confirm. The change is staged in Pending Changes, not written to the tenant.
  4. Review and execute in the pending drawer, on its own or batched with the rest of a review.

What to watch

  • The state is a classification, not an enforcement. Marking an application unsanctioned records the decision; blocking it is a job for the Cloud App Control rules, and the export is how you check whether the rules match the classification.
  • Review a batch together. Flipping eight applications during a SaaS review and executing them in one batch gives the team one diff to read instead of eight notifications.
  • The reverse trip is identical. An application marked unsanctioned by mistake is one confirmed click and one execution away from being back.

Limits and notes

  • The toggle applies to ZIA cloud applications.
  • It stages, it does not write. Nothing changes in the tenant until the pending change is executed, which also means it is covered by the conflict guard if somebody changes the same application in the console meanwhile.
  • Executing pending changes requires the full version.
  • The classification is Zscaler’s own sanctioned state, so it is visible to everything else that reads it, including the console and your Cloud App Control rules.

FAQ

Does marking an app unsanctioned block it? No. It changes the classification. Blocking is a policy decision you implement in Cloud App Control rules, and the classification is what makes the gap between intent and enforcement visible.

Can I change many at once? Flip them one at a time from their cards and execute the staged changes as a batch. The bulk selection path in the Entities Table covers the fields listed under Mass Edit, which does not currently include this one.

Where do I find the applications nobody approved? Start from the cloud app discovery in the URL inventory, or the Cloud App Control rule export in the export catalog.

Next steps

  1. Run a cloud app discovery and list what is in use
  2. Compare it with what is actually marked sanctioned
  3. Flip the ones that need it and execute them as one reviewed batch
  4. Check the Cloud App Control rules match the classification you just set