Zscaler Private Access (ZPA) applies the principles of least privilege to give users secure connectivity to private applications while eliminating unauthorized access and lateral movement. ZPA can be deployed in hours to replace legacy VPN and remote access tools with a holistic zero trust platform.
Zscaler Private Access enables businesses to achieve:
Peerless Security, beyond legacy VPNs and firewalls
Connect users directly to apps - not the network - minimizing the attack surface and eliminating lateral movement
Unrivaled Security against compromised app or users
First-of-its-kind app protection, with inline prevention, deception, and threat isolation, minimizes the risk of compromised users
Superior productivity for today's hybrid workforce
Lighting-fast access to private apps extends seamlessly across remote users, HQ, branch offices, and third party partners
Unified ZTNA platform for users, workloads & OT/IoT
Securely connect to private apps, services, and OT/IoT devices with the industry's most comprehensive ZTNA platform
Highlights
Minimize the attack surface - Make apps invisible, impossible to breach
Eliminate lateral movement - Enforce least-privileged access without putting users on the network
Stop compromised users and mitigate risk - Prevent app exploitation, find, active attackers and threats, and prevent data loss
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing dimension: the ZPA Transformation Edition. You buy it as a contract priced per user. The unit is Users, so your cost scales with the number of subscribed users you enroll. It delivers zero trust network access to private applications, connecting users directly to apps rather than to your network. There are no separate tiers or instance sizes to choose from on the Marketplace. You commit to a set user quantity for the contract term, and pricing follows that count.
Top-of-mind questions for buyers
What counts as one user for billing under the ZPA Transformation Edition?
A user is a subscribed individual you enroll for private application access. Your subscribed user count sets your cost. The listing has a minimum of 500 subscribed users. App connectors and service edges support that user base but are not billed as separate user units on this contract.
What happens to my cost if my user count grows during the contract?
Cost scales with the number of subscribed users you commit to. You enroll a set user quantity for the contract term, and pricing follows that count. Adding users beyond your commitment requires adjusting your subscription. Contact the vendor for changes to your committed user quantity mid-term.
What capabilities are included with the ZPA Transformation Edition per user?
You get zero trust access to private apps in cloud or data centers, with app segmentation, browser-based access, and app connectors. It brokers direct user-to-app connections instead of network access. Capabilities like AppProtection, browser isolation, and privileged remote access support securing private application traffic under this edition.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Zscaler global support is available around the clock, with dedicated customer support engineers providing personalized assistance to ensure that customers are getting the most value from our products. Our support engineers have significant experience in networking and security, working closely with operations, sales, and engineering teams to ensure rapid response and resolution. support.zscaler.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Applies least privilege principles to provide secure connectivity to private applications while eliminating unauthorized access and lateral movement through a zero trust architecture.
Application-Centric Access Control
Connects users directly to applications rather than the network, minimizing attack surface and preventing lateral movement across network infrastructure.
Inline Threat Prevention and Isolation
Implements inline prevention, deception techniques, and threat isolation mechanisms to protect against compromised users and prevent application exploitation.
Multi-Entity ZTNA Platform
Supports unified zero trust network access for users, workloads, and OT/IoT devices with comprehensive coverage across remote users, headquarters, branch offices, and third-party partners.
Application Invisibility and Protection
Makes applications invisible to unauthorized users and implements breach prevention mechanisms to reduce exposure to potential attackers.
VPN Protocol
Built on WireGuard protocol for secure connectivity
Network Architecture
Mesh networking architecture that eliminates single points of failure and replaces legacy hub-and-spoke models
Identity-Based Access Control
Identity-based network access control enabling user and group-based permissions independent of IP addresses
Hostname Resolution
MagicDNS feature enabling device access using memorable hostnames instead of IP addresses
Connection Persistence
Connection migration capability maintaining active connections when switching between different network types
Zero Trust Network Access
Enforces least-privilege access based on user identity with continuous checks on device identity, device security, and user location
Intrusion Detection and Prevention
Built-in IDS/IPS that automatically filters and blocks malicious traffic based on threat priority or category
DNS-Based Content Filtering
Customizable, pre-emptive DNS filtering to block websites from 43 undesirable or unsafe categories
Application Domain-Based Routing
Routes traffic to applications using application domain names instead of IP addresses, efficiently handling overlapping IP address ranges across distributed private networks
Global Distributed Network Infrastructure
Cloud-delivered service from 30+ worldwide points of presence with full-mesh topology providing fast, on-demand connectivity using IPsec and OpenVPN protocols
Admin Control and Custom Tunnel Routing That Just Works
Reviewed on Sep 16, 2026
Review provided by G2
What do you like best about the product?
That the user cannot logout or close it if I want as an admin and that it routes the data in tunnels using only the routes I define so I can disable the best effort route
What do you dislike about the product?
That it does not handle the disconnect and internet issues well so it only can reconnect if manually initiated or by unplugging the ethernet cable and plugging it back in although this is not an issue from only my side
What problems is the product solving and how is that benefiting you?
Accessing my clients' data from a single IP so I have the users logging in from other places and it masks that like a VPN solution plus the Zscaler lists for restricting websites access
Anonymous
Enhances Security but Needs Improved Admin Features
Reviewed on Sep 13, 2026
Review provided by G2
What do you like best about the product?
I like the one-to-one connection between the user and authorized applications with Zscaler Private Access and its deep integration with cloud security architecture. I find its approach to segmenting apps and services by user and group especially valuable, as it minimizes the attack surface while keeping services and apps available. It effectively limits access to specific users or groups and uses posture checks to prevent access by unauthorized users, protecting the environment from lateral movements in case of user compromise.
What do you dislike about the product?
I think for admins, Zscaler doesn't give the full benefit of PAM (Privilege Access Management) and although it segregates access to services and apps, it doesn't provide command control or session recording, which would be good to have.
What problems is the product solving and how is that benefiting you?
Zscaler Private Access reduces attack surfaces by allowing limited access based on user needs, not exposing the entire network. It segments app and service access to users and groups, which enhances security by preventing lateral movement in case of user compromise.
Luciana S.
Brilliant Zero Trust Secure Access That Replaces Traditional VPNs
Reviewed on May 26, 2026
Review provided by G2
What do you like best about the product?
Zscaler is brilliant, with zero trust on matters secure application access, which creates operational safety. The program eliminates the use for traditional VPN and it has multiple security advantages Zscaler supports remote and secure access, where no internal network exploitation or exposure The program is resourceful for distributed workforce and those that access systems on cloud Zscaler is helpful in user segmentation and this brings granular access control that maintains business privacy The app is cloud set, where it has centralized management, with moderate deployment standards The user experience on matters secure applications access is also a paramount feature from the software
What do you dislike about the product?
Zscaler demands policy configurations, a process that is complex and time sensitive The performance for Zscaler depends on regional connectivity and network routing, which is a primary problem
What problems is the product solving and how is that benefiting you?
Zscaler is resourceful in offering secure remote access, more so to private applications and no network exposure The software gives efficiency in operations, where it eliminates a risks that are associated with traditional VPNs Zscaler is brilliant, where it helps in implementing a strategy for zero trust in matters access security The management of secure access is done remotely and this favors all the users, both remotely and hybrid Zscaler eliminates chances of cyberattacks and this prevents companies from being compromised The program concentrates on identity based access, which guarantees security to all applications
Ben G.
Seamless Network Security Without VPN Hassles
Reviewed on Apr 21, 2026
Review provided by G2
What do you like best about the product?
I like that Zscaler Private Access runs quietly in the background, so I don't have to constantly log in to VPNs. It's better than a firewall and a VPN with no gaps, making the setup fairly seamless.
What do you dislike about the product?
N/A
What problems is the product solving and how is that benefiting you?
Zscaler Private Access is better than a firewall and VPN with no gaps. It runs quietly in the background, so I don't have to constantly log in to VPNs.
Kristina D.
Strong Data Security and Easy Auto-Connect
Reviewed on Apr 21, 2026
Review provided by G2
What do you like best about the product?
The product works well to secure data shared throughout the call center and in the corporate offices. The automatic connection when starting computers is a great ease of use tool.
What do you dislike about the product?
My connection to Zscaler often drops, which forces me to log in more frequently than necessary, especially when I’m on a call. As a phone agent operator, the line would constantly drop during program tech updates, creating frustration for both agents and customers in a high-stakes environment.
What problems is the product solving and how is that benefiting you?
Zscaler helps address the security risks that come with an unencrypted connection to the internet. In a world where hackers are constantly seeking financial gain, it’s vital to our company that customer information is protected. We safeguard sensitive data such as bank account details and personal identifying information, including a customer’s SSN, date of birth, and home address.