Network-centric security makes moving to Azure painful
Today 40% of enterprises are running apps in Azure to increase scalability and speed. This move has extended the perimeter to the internet. Yet, many enterprises still rely on remote access VPNs, which are network-centric, and not built to secure access to the internet. They also place users on the network, and require physical or virtual appliances that increase complexity and limit scalability.
Common pitfalls of network-centric approaches:
- Places users on-net to provide access to Azure
- Requires appliances, ACLs and FW policies
- Provides a poor end user experience
- Inbound connections create opportunity for DDoS attacks
- No ability to provide true application segmentation
- Lack visibility into app-related activity
Zscaler Private Access for Azure
Enabling user and application-centric security for Azure
Zscaler Private Access (ZPA) for Azure is a cloud service from Zscaler that provides zero-trust, secure remote access to internal applications running on Azure. With ZPA, applications are never exposed to the internet, making them completely invisible to unauthorized users. The service enables the applications to connect to users via inside-out connectivity versus extending the network to them. Users are never placed on the network. It provides a software-defined perimeter for Azure, that supports any device and any internal application.Read the Solution Brief
Zscaler Private Access for Azure benefits
Better remote user experience
Users have fast, direct-to-cloud access without having to login to remote access VPN client each time.
Less complexity for admins
Network admins can segment based on application from within the web UI. No need to segment by network. No IP address segmentation or access control lists required.
Secure remote access, w/o network access
Policy based access, with no access to network. Visibility into apps being accessed by users and ability to discover unsanctioned apps running within Azure.
Traffic remains private via internet network
Service uses dynamic, application specific TLS-based end to end encryption. All data remains private and enterprises can bring their own PKI.
No hardware appliances, lower costs
The cloud service requires no hardware. Enterprises can easily scale across multiple Azure and Zscaler data centers with no need to replicate gateways.
Scale elastically, reduce latency
The service uses the global Azure network to ramp up new users and route them to the app location nearest to them via internet-based networking.
Leverage the Power of the Azure Network
With Zscaler Private Access for Azure, Zscaler Enforcement Nodes (ZENs), which broker access between a remote user and an internal application, run within the Azure cloud. This enables networking admins to leverage the Azure network and its many data center locations. This reduces latency by minimizing hops and boosts user productivity.
Key Integrations Accelerate The Journey To Azure
We have developed integrations for Azure ecosystems. Integrations with Azure AD enables admins to use ZPA to set access policies for user groups based on their existing configurations. Additionally the Z-Connector is available on the Azure Marketplace. The connector front-ends apps on Azure, and send an inside-out connection to the Zscaler Security Cloud, where the brokered connection between authorized users and application takes place.
See how MAN Diesel & Turbo SE uses ZPA to provide zero-trust access to internal apps, at global scaleRead Case Study
Watch the ZPA for Azure webinar recordingWatch Webcast
Microsoft and Zscaler partner for successRead More