Deploy Posture-Gated Certificate Control Across Zscaler Gateways

SecureW2 extends certificate-based trust into your Zscaler environment, delivering phishing-resistant passwordless access backed by a proven PKI foundation. Deploy Certificate Distribution for SSL Inspection to manage encrypted traffic, maintain complete network visibility, and enforce identity policies across every managed and BYOD device, without disruption.

Overview

Certificate-Backed Passwordless Authentication for Zscaler, Without the EAP-TLS Wait

SecureW2 provides PKI and RADIUS for Zscaler, issuing device-bound, phishing-resistant certificates via JoinNow. It bridges Zscaler’s lack of EAP-TLS over RADIUS by integrating with Zscaler’s certificate authority or running JoinNow Cloud RADIUS, which evaluates identity and device posture and layers Entra MFA via SAML. Managing the full certificate lifecycle, it revokes certificates instantly if devices are flagged as risky. Once Zscaler adds native support, your PKI setup is prepared.

Use Cases
NPS / On-Premises RADIUS Replacement
Dynamic VLAN Assignment from Identity Attributes
Video Overview

See the Integration in Action

Want to See More Demos, Click Here

How It Works

Two Paths to Trusted Identity on Zscaler

ZTNA Authentication Flow with Real-Time Identity Lookup

The device presents its certificate to the Zscaler, which forwards the request to Cloud RADIUS using RADIUS. Cloud RADIUS validates the certificate and performs a live identity provider lookup to confirm the user’s status and group membership. It returns a RADIUS Accept to the gateway, which establishes the encrypted tunnel. A deprovisioned user is blocked on subsequent connection attempts without certificate revocation.

Certificate Distribution for SSL Inspection (SSLI)

JoinNow automates SSL inspection certificate distribution across Windows, macOS, iOS, Android, and ChromeOS through self-service onboarding. Devices receive and trust the Zscaler inspection certificate automatically, eliminating browser warnings and manual installation across managed and BYOD fleets.

Use Cases

Deployment & Architecture Detail

On-Premises RADIUS Replacement

Organizations deploying Zscaler often rely on legacy on-premises NPS servers and Active Directory Certificate Services (AD CS) to authenticate devices. SecureW2 eliminates that infrastructure dependency. SecureW2 Cloud PKI authenticates endpoints directly against your configured identity provider with no NPS, domain controllers, or AD CS required in the path. During enrollment, the Policy Engine validates user identity before issuing a device certificate. At connection time, SecureW2 performs a live lookup with the identity provider to verify user status and group membership, returning active trust signals to Zscaler.

 

The entire path runs through the cloud PKI and your identity provider, allowing on-premises NPS and AD CS to be safely decommissioned without affecting user access. Remote users and branch locations authenticate the same way. Because the authentication flow runs through the cloud, there is no dependency on domain controller reachability, legacy VPN tunnels, or Active Directory replication health.

Dynamic VLAN Assignment from Identity Attributes

Cloud RADIUS reads identity provider group membership at authentication time and maps group values to RADIUS policy attributes, including VLAN assignments. Each rule specifies a group condition and the RADIUS attributes to return when that condition is met.

 

Group-to-VLAN rules are defined once in Cloud RADIUS. Identity provider group management automatically drives network access. When a user moves between groups, the change takes effect at the next authentication event, no manual RADIUS policy changes required.

Frequently Asked Questions

Zscaler Integration — Common Questions

How long does it take to set up the SecureW2 and Zscaler Integration?

Most organizations can configure the integration in a single session by following our setup guide and working with our knowledgeable engineers. Once complete, users begin authenticating with certificates instead of passwords without requiring major changes to existing Zscaler configurations.

Which authentication protocols are supported?

Zscaler connects endpoints through modern SASE and ZTNA protocols rather than legacy RADIUS access control. SecureW2 integrates directly with Zscaler by leveraging cloud-native PKI and Identity Provider (IdP) connections. Organizations can establish direct certificate trust by importing SecureW2 root/intermediate CAs into Zscaler, or by validating device certificates during initial enrollment via JoinNow. Both methods enforce phishing-resistant, passwordless authentication by binding Zscaler access directly to verified user identities and compliant device posture.

How does passwordless ZTNA / Remote Access authentication look from the end-user perspective?

From the user’s perspective, connecting to Zscaler with SecureW2 is no different from opening the Client Connector client and clicking “connect.” The difference is behind the scenes: instead of typing a username or password, the session is authenticated automatically with a certificate issued to their device. This creates a frictionless login experience where users connect instantly and securely, without having to remember or reset passwords.

How does certificate revocation work if a device is lost, stolen, or flagged by an EDR?

SecureW2 manages the full lifecycle of client certificates across your Zscaler environment. If an endpoint is reported lost, stolen, or flagged by an EDR platform such as CrowdStrike or SentinelOne, SecureW2’s cloud-native PKI automatically revokes or suspends its certificate in real time. IT administrators can temporarily suspend access during security investigations or issue an immediate revocation, instantly invalidating the device identity and cutting off Zscaler Private Access (ZPA) to prevent lateral threat movement.

Does Zscaler support certificate-based RADIUS authentication?

SecureW2 provisions device X.509 client certificates that Zscaler uses directly for mTLS application access and SAML IdP re-authentication, alongside enterprise Wi-Fi 802.1X. SecureW2 provides two integration paths: using Cloud RADIUS with MFA to secure ZTNA logins with an identity‑bound, MFA‑protected credential, or deploying Managed PKI to establish a certificate trust chain within Zscaler firewalls. Both methods provide strong security today and ensure that when Zscaler adds EAP‑TLS support in the future, your organization will already have the full PKI infrastructure in place.

Ready to Connect Zscaler to SecureW2?

Connect with our integration specialists to implement this solution in your environment and transform your security posture.