Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Zscaler ZDTE Exam - Topic 6 Question 9 Discussion

Actual exam question for Zscaler's ZDTE exam
Question #: 9
Topic #: 6
[All ZDTE Questions]

How does Zscaler apply Tenant Restriction policies to cloud applications?

Show Suggested Answer Hide Answer
Suggested Answer: C

In the ZDTE material under Advanced Access Control Services, Tenant Restrictions (often discussed with ''personal vs. corporate'' SaaS use) are described as a way to ensure users can only authenticate to sanctioned organization tenants for apps like Microsoft 365, Google Workspace, or other major SaaS platforms.

Zscaler does this by acting as an inline Zero Trust proxy and modifying the authentication flow, not by bluntly blocking all external SaaS access. The docs explain that, for supported SaaS applications, Zscaler injects specific identity or tenant identifiers (for example, the allowed tenant ID or corresponding claim) into the HTTP(S) requests during sign-in. These injected headers or parameters signal to the SaaS provider which tenant is permitted so that logins to personal or unsanctioned tenants can be transparently blocked or challenged while corporate tenant access is allowed.

Because this enforcement is done at the HTTP/S layer using header/parameter insertion tied to identity and policy, users retain seamless access to approved corporate tenants while attempts to use personal or shadow-IT tenants are controlled according to policy---exactly what Option C describes.


Contribute your Thoughts:

0/2000 characters
Roslyn
6 days ago
I think Zscaler uses headers during authentication, but I'm not entirely sure if that's the only method they use.
upvoted 0 times
...

Save Cancel