Deploy Zscaler Client Connector via Intune | Guide
Zscaler Client Connector is a zero trust network access agent that routes user traffic through the Zscaler cloud. Deployment via Intune requires the MSI installer from your Zscaler admin portal, pre-configured with your cloud name and tenant URL so the agent connects to your environment automatically without user interaction.
Prerequisites
- A Zscaler Internet Access (ZIA) or Zscaler Private Access (ZPA) subscription
- Admin access to your Zscaler admin portal
- Your Zscaler cloud name (e.g. zscaler.net, zscalertwo.net, zscalerthree.net)
- Your tenant URL (e.g. yourcompany.zscaler.net)
Download from the Zscaler portal
Log in to your Zscaler admin portal and work through to:
Client Connector → Client Connector Portal → Downloads
Download the Windows MSI. Make sure you download the version matching your Zscaler cloud - the download page shows which cloud you are on.
Wrap with the Content Prep Tool
IntuneWinAppUtil.exe -c "C:\AppSource\Zscaler" -s "ZscalerClientConnectorSetup.msi" -o "C:\IntunePackages"
Add the app in Intune
- Upload the .intunewin file
- Name: Zscaler Client Connector
- Publisher: Zscaler, Inc.
Install and uninstall commands
Detection rule
Known gotchas
Users prompted to log in after install
If you have SSO configured via Entra ID (Azure AD), users will be auto-authenticated when they open Zscaler Client Connector. If SSO is not configured, users will see a login prompt. Ensure your Zscaler IdP authentication is set up in the admin portal before deploying at scale.
Split tunnel configuration
By default, Zscaler routes all traffic through the cloud. If you want to exclude certain apps or IP ranges, configure your tunnel profile in the Zscaler admin portal before deploying - these settings are pushed to the client automatically once it registers.
Frequently Asked Questions
Use: ZscalerClientConnectorSetup-
Log in to your Zscaler admin portal, go to Client Connector > Client Connector Portal > Downloads. Download the Windows MSI installer for your Zscaler cloud (zscaler.net, zscalertwo.net, etc.).
Pass CLOUDNAME, CLOUDURL, and USERDOMAIN as MSI properties in the install command. These connect the client to your specific Zscaler cloud and enable SSO auto-login for your domain users.
Use a file detection rule: check for ZSATunnel.exe in C:\Program Files\Zscaler\ZSATunnel. Alternatively check the registry under HKLM\SOFTWARE\Zscaler.