ZIA Hero Guide
This section is about Zscaler Internet Access itself, not about ZHERO. It collects the patterns that come up repeatedly in real tenants: what a sound configuration looks like, what the common mistakes cost, and how to recognise them in your own estate.
The rest of this site documents the product. This section documents the platform.
What is here today
Two articles, both on the same theme: how URLs behave once they are in your configuration, and what makes an SSL exception safe or dangerous.
- URL Patterns in SSL Exceptions: which URL patterns are safe in a do-not-inspect rule and which quietly exempt far more than intended, with the wildcard and CDN cases spelled out.
- URL Inventory Management: keeping a URL estate maintainable as it grows, from naming through cleanup.
That is genuinely all there is for now. This section grows slowly and on purpose: an article lands here when it says something specific enough to change what somebody does, not to fill a category.
Where the rest of the answers are
If you came looking for something else, it is probably in one of these:
| You want | Go to |
|---|---|
| To install or configure ZHERO | Setup and OneAPI |
| To find out what is wrong with your ZIA configuration | Analysis Engine and the template catalog |
| To score and track your posture | Security Posture Dashboard |
| To work out why a user cannot reach a site | Troubleshooting Engine |
| To clean up URLs | URL Inventory and URL Management |
| To make changes safely | Pending Changes |
The analysis templates are, in effect, this guide in executable form: every check encodes a best practice, and running them on your tenant is faster than reading about the practice and then looking for it by hand.
Contributing
If you have a pattern worth writing up, from a migration, an incident or a tenant that taught you something, get in touch. Field notes from people who run these environments are the only source this section has.