Global Secure Access + Zscaler
Zscaler secures your internet traffic; GSA takes over private access and identity. The most common coexistence pattern we see — and Microsoft documents four supported scenarios for it.
GSA owns
- Private access to on-prem / legacy apps (Entra Private Access)
- Microsoft 365 traffic
- Identity + Conditional Access enforcement
Zscaler owns (during coexistence)
- Internet and SaaS traffic via ZIA (SWG)
- ZPA-published private apps you're not ready to move
01Decide the traffic split
Agree which workloads GSA owns and which Zscaler keeps. Typically: GSA for private + M365, Zscaler for internet/SaaS — or the inverse if you're rolling out Internet Access first.
02Align forwarding so they don't double-route
Configure Zscaler forwarding profiles (and PAC files where used) so traffic is steered to exactly one platform — no hairpinning or double inspection.
03Publish private apps through GSA
Deploy the Entra Private Network Connector and publish apps with Quick Access — Zscaler keeps the internet, GSA handles private, side by side.
04Cut over app by app
Migrate ZPA-published apps to GSA incrementally, then decommission the overlap when you're ready. No big-bang rip-and-replace.
Full configuration: Microsoft Learn — GSA + Zscaler coexistence