Zscaler Runbook & Troubleshooting Guide
Overview
This runbook covers common Zscaler Internet Access (ZIA) and Zscaler Private Access (ZPA) issues, diagnostic steps, and resolution paths for support/NOC teams.
1. Quick Reference
| Component | Purpose | Client Check |
|---|---|---|
| ZIA | Secure internet/SaaS traffic | Zscaler Client Connector → Internet Security: ON |
| ZPA | Secure private app access | Zscaler Client Connector → Private Access: ON |
| ZCC | Zscaler Client Connector (endpoint agent) | System tray icon status |
| ZDX | Digital Experience monitoring | ZDX app / portal |
Key URLs to check status:
- https://trust.zscaler.com (service status by cloud)
- Admin portal: https://admin.<cloud>.net (e.g., zscaler.net, zscloud.net)
2. Initial Triage Checklist
- Identify scope — Single user, group, site, or global?
- Identify service — ZIA, ZPA, or both affected?
- Check Zscaler Trust Portal for active incidents on the customer's cloud.
- Confirm ZCC status on affected endpoint(s):
- Is the app running?
- Is it connected (green icon) or disconnected/error (red/yellow)?
- Check policy assignment — is the user in the correct policy group/location?
- Reproduce issue — browser test, curl test, or app-specific test.
3. Common Issues & Fixes
3.1 ZCC Won't Connect / Shows "Disconnected"
- Restart ZCC service (
Zscaler Client Connector→ Exit → relaunch, or restart theZSAService/ZSATunnelservice). - Check local firewall/AV isn't blocking Zscaler processes (
ZSAService.exe,ZSATunnel.exe,ZSATray.exe). - Verify DNS resolution to Zscaler cloud endpoints.
- Check for VPN conflicts (split tunneling issues, other VPN clients running simultaneously).
- Re-enroll device if certificate/auth token is stale: