Zscaler Private Access (ZPA) applies the principles of least privilege to give users secure connectivity to private applications while eliminating unauthorized access and lateral movement. ZPA can be deployed in hours to replace legacy VPN and remote access tools with a holistic zero trust platform.
Zscaler Private Access enables businesses to achieve:
Peerless Security, beyond legacy VPNs and firewalls
Connect users directly to apps - not the network - minimizing the attack surface and eliminating lateral movement
Unrivaled Security against compromised app or users
First-of-its-kind app protection, with inline prevention, deception, and threat isolation, minimizes the risk of compromised users
Superior productivity for today's hybrid workforce
Lighting-fast access to private apps extends seamlessly across remote users, HQ, branch offices, and third party partners
Unified ZTNA platform for users, workloads & OT/IoT
Securely connect to private apps, services, and OT/IoT devices with the industry's most comprehensive ZTNA platform
Highlights
Minimize the attack surface - Make apps invisible, impossible to breach
Eliminate lateral movement - Enforce least-privileged access without putting users on the network
Stop compromised users and mitigate risk - Prevent app exploitation, find, active attackers and threats, and prevent data loss
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing dimension: the ZPA Transformation Edition. You buy it as a contract priced per user. The unit is Users, so your cost scales with the number of subscribed users you enroll. It delivers zero trust network access to private applications, connecting users directly to apps rather than to your network. There are no separate tiers or instance sizes to choose from on the Marketplace. You commit to a set user quantity for the contract term, and pricing follows that count.
Top-of-mind questions for buyers
What counts as one user for billing under the ZPA Transformation Edition?
A user is a subscribed individual you enroll for private application access. Your subscribed user count sets your cost. The listing has a minimum of 500 subscribed users. App connectors and service edges support that user base but are not billed as separate user units on this contract.
What happens to my cost if my user count grows during the contract?
Cost scales with the number of subscribed users you commit to. You enroll a set user quantity for the contract term, and pricing follows that count. Adding users beyond your commitment requires adjusting your subscription. Contact the vendor for changes to your committed user quantity mid-term.
What capabilities are included with the ZPA Transformation Edition per user?
You get zero trust access to private apps in cloud or data centers, with app segmentation, browser-based access, and app connectors. It brokers direct user-to-app connections instead of network access. Capabilities like AppProtection, browser isolation, and privileged remote access support securing private application traffic under this edition.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Zscaler global support is available around the clock, with dedicated customer support engineers providing personalized assistance to ensure that customers are getting the most value from our products. Our support engineers have significant experience in networking and security, working closely with operations, sales, and engineering teams to ensure rapid response and resolution. support.zscaler.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Applies least privilege principles to provide secure connectivity to private applications while eliminating unauthorized access and lateral movement through a zero trust architecture.
Application-Centric Access Control
Connects users directly to applications rather than the network, minimizing attack surface and preventing lateral movement across network infrastructure.
Inline Threat Prevention and Isolation
Implements inline prevention, deception techniques, and threat isolation mechanisms to protect against compromised users and prevent application exploitation.
Multi-Entity ZTNA Platform
Supports unified zero trust network access for users, workloads, and OT/IoT devices with comprehensive coverage across remote users, headquarters, branch offices, and third-party partners.
Application Invisibility and Protection
Makes applications invisible to unauthorized users and implements breach prevention mechanisms to reduce exposure to potential attackers.
VPN Protocol
Built on WireGuard protocol for secure connectivity
Network Architecture
Mesh networking architecture that eliminates single points of failure and replaces legacy hub-and-spoke models
Identity-Based Access Control
Identity-based network access control enabling user and group-based permissions independent of IP addresses
Hostname Resolution
MagicDNS feature enabling device access using memorable hostnames instead of IP addresses
Connection Persistence
Connection migration capability maintaining active connections when switching between different network types
Zero Trust Network Access
Enforces least-privilege access based on user identity with continuous checks on device identity, device security, and user location
Intrusion Detection and Prevention
Built-in IDS/IPS that automatically filters and blocks malicious traffic based on threat priority or category
DNS-Based Content Filtering
Customizable, pre-emptive DNS filtering to block websites from 43 undesirable or unsafe categories
Application Domain-Based Routing
Routes traffic to applications using application domain names instead of IP addresses, efficiently handling overlapping IP address ranges across distributed private networks
Global Distributed Network Infrastructure
Cloud-delivered service from 30+ worldwide points of presence with full-mesh topology providing fast, on-demand connectivity using IPsec and OpenVPN protocols
I love the ease of use of Zscaler Private Access and the excellent interface. Also, the excellent features make the experience good. The application greatly helps me in my organization and makes network access easy and uncomplicated. Additionally, the setup experience was very excellent and simple with easy steps.
What do you dislike about the product?
Details about the subscription could be clearer regarding the subscription aspect.
What problems is the product solving and how is that benefiting you?
I use Zscaler Private Access for troubleshooting and providing good network visibility. It helps secure private networks and ensures easy access without complications.
Anonymous
Secure Access, Complex Setup
Reviewed on Sep 24, 2026
Review provided by G2
What do you like best about the product?
I appreciate that Zscaler Private Access provides me with secure, application-specific access without putting users directly on the corporate network, solving the security and complexity problems of traditional VPNs.
What do you dislike about the product?
The initial setup of Zscaler Private Access is moderately complex and requires careful planning rather than a simple plug-and-play installation.
What problems is the product solving and how is that benefiting you?
Zscaler Private Access solves security and complexity issues of traditional VPNs by offering secure, application-specific access without directly connecting users to our network.
Josue A.
User-Friendly UI and Helpful Built-In AI for Safer Public Use
Reviewed on Sep 23, 2026
Review provided by G2
What do you like best about the product?
It’s better than a VPM and feels more cautious in public spaces. The UI is very user-friendly, even for people who aren’t very tech-savvy. The built-in AI also helps you navigate.
What do you dislike about the product?
The price is high; if you can’t afford it, you might as well go with other options. I also experience stuttering from time to time, along with occasional disconnection issues.
What problems is the product solving and how is that benefiting you?
The network connection, with its approach of not trusting everyone, helps you get the best out of all your connections, while also helping the team navigate the web safely.
Outsourcing/Offshoring
Admin Control and Custom Tunnel Routing That Just Works
Reviewed on Sep 16, 2026
Review provided by G2
What do you like best about the product?
That the user cannot logout or close it if I want as an admin and that it routes the data in tunnels using only the routes I define so I can disable the best effort route
What do you dislike about the product?
That it does not handle the disconnect and internet issues well so it only can reconnect if manually initiated or by unplugging the ethernet cable and plugging it back in although this is not an issue from only my side
What problems is the product solving and how is that benefiting you?
Accessing my clients' data from a single IP so I have the users logging in from other places and it masks that like a VPN solution plus the Zscaler lists for restricting websites access
Anonymous
Enhances Security but Needs Improved Admin Features
Reviewed on Sep 13, 2026
Review provided by G2
What do you like best about the product?
I like the one-to-one connection between the user and authorized applications with Zscaler Private Access and its deep integration with cloud security architecture. I find its approach to segmenting apps and services by user and group especially valuable, as it minimizes the attack surface while keeping services and apps available. It effectively limits access to specific users or groups and uses posture checks to prevent access by unauthorized users, protecting the environment from lateral movements in case of user compromise.
What do you dislike about the product?
I think for admins, Zscaler doesn't give the full benefit of PAM (Privilege Access Management) and although it segregates access to services and apps, it doesn't provide command control or session recording, which would be good to have.
What problems is the product solving and how is that benefiting you?
Zscaler Private Access reduces attack surfaces by allowing limited access based on user needs, not exposing the entire network. It segments app and service access to users and groups, which enhances security by preventing lateral movement in case of user compromise.