Skip to content

ZIA Hero Guide

This section is about Zscaler Internet Access itself, not about ZHERO. It collects the patterns that come up repeatedly in real tenants: what a sound configuration looks like, what the common mistakes cost, and how to recognise them in your own estate.

The rest of this site documents the product. This section documents the platform.

What is here today

Two articles, both on the same theme: how URLs behave once they are in your configuration, and what makes an SSL exception safe or dangerous.

  • URL Patterns in SSL Exceptions: which URL patterns are safe in a do-not-inspect rule and which quietly exempt far more than intended, with the wildcard and CDN cases spelled out.
  • URL Inventory Management: keeping a URL estate maintainable as it grows, from naming through cleanup.

That is genuinely all there is for now. This section grows slowly and on purpose: an article lands here when it says something specific enough to change what somebody does, not to fill a category.

Where the rest of the answers are

If you came looking for something else, it is probably in one of these:

You wantGo to
To install or configure ZHEROSetup and OneAPI
To find out what is wrong with your ZIA configurationAnalysis Engine and the template catalog
To score and track your postureSecurity Posture Dashboard
To work out why a user cannot reach a siteTroubleshooting Engine
To clean up URLsURL Inventory and URL Management
To make changes safelyPending Changes

The analysis templates are, in effect, this guide in executable form: every check encodes a best practice, and running them on your tenant is faster than reading about the practice and then looking for it by hand.

Contributing

If you have a pattern worth writing up, from a migration, an incident or a tenant that taught you something, get in touch. Field notes from people who run these environments are the only source this section has.