ZPA
acronymcloudsecurity
Zscaler Private Access: per-application, per-session brokered access to private apps - user and App Connector both dial out, a Service Edge stitches the Microtunnels.
Access to applications, never to networks; nothing listens inbound.
ZPA is the inbound half, and it replaces the VPN rather than extending it. Instead of placing a remote user on a routable network segment and then trying to restrict what they can reach, it brokers a connection to one specific application and nothing else.
The mechanism is what makes it interesting. A lightweight App Connector sits beside your applications and makes only outbound connections to the Zscaler cloud; it never accepts inbound ones. The user's client also connects outbound. The cloud stitches the two halves together. Because both sides dial out, the application needs no inbound firewall rule and no public exposure at all, which removes it from internet scanning entirely.
The security argument follows directly. A compromised VPN session gives an attacker a network position to explore laterally; a compromised ZPA session gives them one application. That is a genuine reduction in blast radius rather than a marketing claim. The cost is that access becomes an inventory problem: every application must be defined, and anything nobody remembered to onboard simply does not work, which is exactly why migrations surface applications nobody knew were still running.