GSA coexistence guide

Global Secure Access + Zscaler

Zscaler secures your internet traffic; GSA takes over private access and identity. The most common coexistence pattern we see — and Microsoft documents four supported scenarios for it.

Zscaler · ZIA / ZPA

GSA owns

  • Private access to on-prem / legacy apps (Entra Private Access)
  • Microsoft 365 traffic
  • Identity + Conditional Access enforcement

Zscaler owns (during coexistence)

  • Internet and SaaS traffic via ZIA (SWG)
  • ZPA-published private apps you're not ready to move

01Decide the traffic split

Agree which workloads GSA owns and which Zscaler keeps. Typically: GSA for private + M365, Zscaler for internet/SaaS — or the inverse if you're rolling out Internet Access first.

02Align forwarding so they don't double-route

Configure Zscaler forwarding profiles (and PAC files where used) so traffic is steered to exactly one platform — no hairpinning or double inspection.

03Publish private apps through GSA

Deploy the Entra Private Network Connector and publish apps with Quick Access — Zscaler keeps the internet, GSA handles private, side by side.

04Cut over app by app

Migrate ZPA-published apps to GSA incrementally, then decommission the overlap when you're ready. No big-bang rip-and-replace.

When to use: you're invested in Zscaler for internet security but want Entra-native private access — or you're consolidating on Entra and want to retire ZPA gradually.