THE NETWORK GUY | Mastering Zscaler:
Hands On
Module 01 — Lab 01 — ZIA Admin Portal
Orientation
Lab Guide | Saturday 6 June 2026
─────────────────────────────────────────────────────
───────────────────
Lab 01 orients you to the ZIA Admin Portal. You will log in, explore the key sections, check your ZIA cloud
subscription details, and verify the settings that matter for the rest of the course.
Estimated time: 30–40 minutes
────────────────────────────────────────────────────────────────────────────────
Prerequisites
ZIA Admin Portal URL from your trainer (e.g., [Link], [Link], or
[Link])
Admin username and password (provided by trainer or from your ZIA trial)
NOTE: ZIA trial accounts from Zscaler are available at [Link]/products/zscaler-internet-access. Request a
trial if you don't have portal access — setup takes 1 business day.
────────────────────────────────────────────────────────────────────────────────
Part 1: Log In and Explore the Admin Portal (10 min)
Step 1: Log in to ZIA Admin Portal
Open a browser and navigate to your ZIA Admin Portal URL.
Enter your admin credentials.
Expected: ZIA Admin Portal dashboard loads — you should see the navigation menu on the left.
Step 2: Identify your ZIA cloud
Look at the URL in your browser address bar — it shows which Zscaler cloud your tenant is on:
[Link] → Zscaler Public Cloud
[Link] → ZscalerOne Cloud
[Link] → ZscalerTwo Cloud
[Link] → ZscalerBeta
Note your cloud — this determines the API URL, ZCC provisioning URL, and PAC file domain you will use
in later labs.
Step 3: Explore the main navigation sections
Click through each main section in the left navigation:
Dashboard: overview cards — users, threats blocked, top categories
Policy: URL Filtering, SSL Inspection, Cloud Firewall, DLP, Sandbox
Analytics: Web Insights, Reports, DLP incidents
Administration: Users, Groups, Locations, Authentication, ZCC
Infrastructure: Locations, Sub-Locations, GRE/IPsec config
Don't change anything — just browse each section to understand where things live.
TIP: Bookmark the Admin Portal URL in your browser now. You will access it constantly throughout this
course.
────────────────────────────────────────────────────────────────────────────────
Part 2: Check Subscription and Licence (5 min)
Step 4: View your ZIA subscription
Administration > Company Profile (or Administration > Subscription)
Note:
Subscription type (trial / professional / business / transformation)
Expiry date
Enabled features (SSL Inspection, Sandbox, DLP — are they enabled in your trial?)
If features show as disabled: some ZIA capabilities require specific licence tiers. The trainer will advise
which features are available for labs.
────────────────────────────────────────────────────────────────────────────────
Part 3: Check Policy Activation Status (5 min)
Step 5: Check for pending changes
Look at the top of the Admin Portal — is there a yellow 'Pending Activation' banner?
If yes: click it and review what is pending. Click Activate to push pending changes.
If no: there are no pending changes (all current config is active).
Understand: every change you make in ZIA is staged until you click Activate. Changes do NOT take effect
immediately when you save them.
TIP: Activating changes in ZIA is like committing a git change. Saves are staged — Activate pushes them live.
Always activate after making changes, or they will have no effect.
────────────────────────────────────────────────────────────────────────────────
Part 4: Check URL Categorisation (10 min)
Step 6: Test URL categorisation
Policy > URL & Cloud App Control > Check URL Category
(This tool may be in different locations depending on your ZIA version — search for it if needed)
Test the following URLs and note the category assigned by ZIA:
[Link] → expected: Social Networking
[Link] → expected: News and Media
[Link] → expected: Malware
[Link] → expected: Social Networking
[Link] → expected: Microsoft Office 365 or Business Applications
Screenshot the results for at least 3 URLs.
Step 7: Check your company's default URL filtering policy
Policy > URL & Cloud App Control > Filtering Rules
Note: what rules already exist? Are there any default rules?
In a trial: there may be no rules (all traffic is allowed by default)
In a production tenant: there will be existing rules
Do NOT make any changes to existing rules.
Take note of the current number of rules — you will add rules in Lab 04.
────────────────────────────────────────────────────────────────────────────────
Part 5: Explore Analytics Dashboard (5 min)
Step 8: Open Web Insights
Analytics > Web Insights
If this is a fresh trial: dashboards may be empty (no traffic yet)
If traffic has been forwarded: you will see:
Top users by requests/bandwidth
Top URL categories
Top blocked categories
Threat events
For a fresh trial: the dashboards will populate once ZCC is installed and traffic is forwarding (Lab 02
onwards).
Step 9: Take note of the transaction log
Analytics > Web Insights > Transactions tab (if available)
This is the detailed log of every URL request.
In Lab 04 and 05, you will use this log extensively for troubleshooting.
Familiarise yourself with the columns: Timestamp, User, URL, Category, Action, Rule, Bytes.
────────────────────────────────────────────────────────────────────────────────
Lab 01 Completion Checklist
[] Logged in to ZIA Admin Portal successfully
[] Identified your ZIA cloud ([Link] / [Link] / [Link])
[] Explored all main navigation sections (Policy, Analytics, Administration)
[] Checked subscription and enabled features
[] Tested URL categorisation for at least 3 URLs — screenshot
[] Noted current URL filtering rules (or confirmed none exist in trial)
[] Explored Analytics > Web Insights (even if empty — understand the layout)
────────────────────────────────────────────────────────────────────────────────
What's Next?
Lab 02 (Module 02) will configure traffic forwarding — installing ZCC on an Azure VM to forward traffic
through ZIA. Once ZCC is installed and traffic is flowing, the Analytics dashboards in Lab 01 will start
populating with real data.