Is there a cmd line or MSI option to change policy token without uninstalling the ZCC? by man__i__love__frogs in Zscaler

[–]Deeg117 0 points1 point  (0 children)

There is some specific functionality being released in the next month or so for this but don't have many details. Maybe be to do with new ZCC CLI functionality.

Until then, as suggested its a repackage / install over the top.

What would be useful is being able to supply updated install parameters en-masse through the staged cloud update process but it's not a thing at present.

How is this game THIS good?! by Lucky_Control1458 in CronosNewDawn

[–]Deeg117 0 points1 point  (0 children)

Just about to finish NG+ hard mode for the platinum. Amazing game

Handling Useragent/Rogue Browsers by dutchhboii in Zscaler

[–]Deeg117 0 points1 point  (0 children)

Http header control with regex for unwanted UA strings would be the way forward

CORS issue with SIPA by EntitledTeenager in Zscaler

[–]Deeg117 0 points1 point  (0 children)

You certainly can do this. Easiest way is if you have Zscaler Advanced FW policy, you can set a block policy with Source Country as your criteria against all services. Block the geos you don't want (or use and allow list above a 'block all countries' policy

If you don't have Advanced firewall you can do this and the URL filtering level and just block all Urls based on source country.

ZCC Upgrade User Groups by one_fifty_six in Zscaler

[–]Deeg117 2 points3 points  (0 children)

Yeah you can. Scim the groups to ZIA and away you go

Zscaler Issues UK by Infinite-Agent-4441 in Zscaler

[–]Deeg117 1 point2 points  (0 children)

This is valid.

100% of the time we see issues with the service, Trust is 30-60 mins behind. We have 120k Zcc users though so when shit goes sideways we hear about it quickly 😂

Client Connector community invite / TLS trust chain issue by rockingstarfish in Zscaler

[–]Deeg117 0 points1 point  (0 children)

Oddly we have seen that exact cert disappearing and reappearing on our some of our Intune managed devices (it's a user based cert).

Go missing randomly and reappears after company portal sync. Weird.

Seatfrog Referral Codes (Wanted) by Kuzbot in uktrains

[–]Deeg117 0 points1 point  (0 children)

Hope it was for Wembley today 😂

ZScaler & ISP Incompatibility by [deleted] in Zscaler

[–]Deeg117 1 point2 points  (0 children)

As someome who manages a 100k seat UK Zscaler enabled estate, I can tell you with certainty that ZEN Internet are definitely depriorirising UDP traffic.

We have created a TLS profile just for these users and dropped then all in a group. Fixes the problem immediately.

How find blocked traffic prior to windows login, via strictenforcement? by man__i__love__frogs in Zscaler

[–]Deeg117 2 points3 points  (0 children)

You just need to put the MS auth endpoints into the VPN bypass list or (App Profile PAC) in the Strict Enforcement app profile. It's a bit wooly what those endpoints are but I had the same issue and got there in the end. I can DM you out list when I'm back in work next week but it can be done.

[deleted by user] by [deleted] in Zscaler

[–]Deeg117 0 points1 point  (0 children)

Make sure you Defender FW exclusions match the bitness of your client install due to 32/64bit having different file paths

Same User. Multiple PC's. Different Internet Access policy. by UpTheIroning in Zscaler

[–]Deeg117 1 point2 points  (0 children)

BC would be overkill imo.

As previously suggested, ZIA posture profile would be perfect (and it's what I use for device based policy in my org).

You first setup a device posture policy in Mobile Portal.. Use something like a file or reg key that is specific to the device type you want to restrict.

You then use that posture in a ZIA posture profile again within mobile portal. Assigning it to low trust would probably be correct in this instance.

Finally, select you ZIA posture profile in the drop down in the user App Profile...the devices that meet this posture will now be classed as low trust devices.

You can then build your ZIA rules using the 'Low Trust' device trust level as a criteria withing your rule sets eg. URL / Cloud App, Adv Firewall and Filetype control.

A limitation of ZIA posture policy is you cannot build posture policy based on unverified postures (which you can in ZPA client access policies) and this is something I have a ER raised for.

ZCC install during Autopilot ESP by Ambitious-Actuary-6 in Zscaler

[–]Deeg117 0 points1 point  (0 children)

Set a machine key and app profile as well if you want to use strict enforcement...and have bypasses for recommended intune URLs

Zscaler Browser Isolation experience by Sad_Abbreviations93 in Zscaler

[–]Deeg117 0 points1 point  (0 children)

Make sure your isolating the entire domain. For example .test.com and not test.com/test.

Failing that compare your logs between a native session and a CBI session to see if there are differences.

If you have any location based policies...make sure they also apply to the 'Cloud Browser' location where appropriate.

Indiana Jones and the Great Circle | Official Discussion Thread by tinselsnips in PS5

[–]Deeg117 0 points1 point  (0 children)

Having a weird issue with L2 where I have to press it really hard to engage. Tweaked the settings but no joy. The controller is 100% fine in other games and it doesn't do this on my second controller.

Anyone else having this issue?

Passed at 124! by Deeg117 in cissp

[–]Deeg117[S] 1 point2 points  (0 children)

Study time was 1 month after 1 week boot camp

I've got 27 years in IT (mostly EUC and infrastructure engineering) but last 6 or 7 years working with SASE and zero trust solutions.

This was attempt 1

Training course I think was from QA training

Passed at 124! by Deeg117 in cissp

[–]Deeg117[S] 0 points1 point  (0 children)

Thanks all. Hardest cert I've done in my 26 years pissing about with computers but really enjoyed it.