THE NETWORK GUY | Mastering Zscaler:
Hands On
Module 04 — Lab 04 — ZIA Policy Configuration
Lab Guide | Saturday 27 June 2026
─────────────────────────────────────────────────────
───────────────────
This lab builds real policies in your ZIA Admin Portal and tests them from your Azure VM. You will configure
URL Filtering rules, an SSL Inspection bypass, a DLP rule, and review results in Analytics.
Estimated time: 60–70 minutes
────────────────────────────────────────────────────────────────────────────────
Prerequisites
ZIA Admin Portal access (from M01 lab setup)
Azure VM running Windows (from M02 lab — or create a new one in your free Azure subscription)
ZCC installed and enrolled on the Azure VM (from M02 lab)
ZCC showing 'Connected' status — verify via ZCC tray icon on the Azure VM
WARNING: All steps in this lab are performed in the ZIA Admin Portal. When a step says 'test from Azure VM,'
use Remote Desktop to connect to your Azure VM and run tests there — not on your local machine.
────────────────────────────────────────────────────────────────────────────────
Part 1: URL Filtering — Block & Exception (20 min)
1.1 Create a Test User Group
You will create a group called 'Lab04-Allowed' and add your test user to it. This group will be the exception to
the social media block.
Step 1: Open ZIA Admin Portal
Navigate to your ZIA Admin Portal URL (e.g., [Link] or [Link]). Log in with your
admin credentials.
Step 2: Navigate to User Groups
Go to Administration > User Management > Groups > click + Add Group.
Step 3: Create the group
Name: Lab04-Allowed
Description: Exception group for URL filtering lab
Click Save and Activate.
Step 4: Add a user to the group
Go to Administration > User Management > Users.
Find your test user (the one enrolled with ZCC on your Azure VM).
Click Edit > scroll to Groups > add Lab04-Allowed > Save and Activate.
TIP: Activating changes is required for every policy modification. Look for the yellow 'Pending Activation'
banner at the top of the portal and click Activate.
1.2 Create the Block Rule (Order 10)
Step 5: Navigate to URL Filtering
Go to Policy > URL & Cloud App Control > Filtering Rules > click + Add Rule.
Step 6: Configure the Block rule
Order: 10
Name: Block-Social-Media-All
Status: Enabled
URL Categories: Social Networking
Users: select 'All Users' (or leave blank for all)
Action: Block
Block Response: 'This site is blocked by company policy.'
Click Save (do NOT activate yet — you need to add the exception rule first).
WARNING: Do not activate yet. If you activate the Block rule before creating the Allow exception, ALL users
(including you) will be blocked from social media.
1.3 Create the Allow Exception Rule (Order 5)
Step 7: Add another URL Filtering rule
Policy > URL & Cloud App Control > Filtering Rules > + Add Rule.
Step 8: Configure the Allow rule
Order: 5
Name: Allow-Social-Media-Lab04
Status: Enabled
URL Categories: Social Networking
Users: click + Add > Groups > select Lab04-Allowed
Action: Allow
Click Save.
Step 9: Verify rule order
In the Filtering Rules list, confirm:
Order 5: Allow-Social-Media-Lab04 (Allow)
Order 10: Block-Social-Media-All (Block)
The Allow rule (5) must appear ABOVE the Block rule (10).
Step 10: Activate changes
Click the yellow 'Pending Activation' banner > Activate.
Changes take effect within 30–60 seconds.
1.4 Test the Rules
Step 11: Test Block rule (as non-exception user)
Remote Desktop to your Azure VM.
Open a browser and navigate to: [Link]
Expected: Zscaler block page stating the site is blocked.
Screenshot the block page — note the rule name shown (Block-Social-Media-All).
Step 12: Test Allow exception
The test user on the Azure VM should be in the Lab04-Allowed group (Step 4).
If the block page still shows, ZCC may be caching the old policy — right-click ZCC tray icon > Reconnect.
Navigate to [Link] again.
Expected: LinkedIn loads normally.
Screenshot the successfully loaded LinkedIn page.
TIP: If the exception is still not working after reconnecting ZCC, check: (1) the test user is actually in the Lab04-
Allowed group, (2) changes were activated, (3) the Allow rule order (5) is lower than the Block rule (10) in the
policy list.
────────────────────────────────────────────────────────────────────────────────
Part 2: SSL Inspection — Bypass for Financial Sites (15 min)
2.1 Observe Certificate Before Bypass
Step 13: Visit a financial site on Azure VM
On your Azure VM, navigate to: [Link] (or any banking site).
Click the padlock icon in the browser address bar > click 'Connection is secure' or 'Certificate'.
Note the 'Issued by' field — it should show something like 'Zscaler Root CA' or 'ZscalerTwo Root CA'.
Screenshot the certificate details.
If you see the Zscaler CA, this confirms SSL Inspection is active and decrypting HTTPS traffic to financial
sites.
2.2 Create SSL Bypass Rule
Step 14: Navigate to SSL Inspection
In ZIA Admin Portal: Policy > SSL Inspection > click + Add Bypass Rule (or 'Add Rule' depending on your
ZIA version).
Step 15: Configure the bypass rule
Name: Bypass-Financial-Sites
Order: 1 (highest priority)
URL Categories: select 'Finance' and 'Banking'
(Alternatively: check if 'Financial Services' is a single category in your ZIA)
Action: Do Not Inspect
Click Save and Activate.
TIP: Your IdP ([Link]) should also have an SSL bypass. Check if a bypass already exists for
Microsoft / Azure AD — if not, add one. Breaking SAML auth affects all users.
2.3 Test the Bypass
Step 16: Revisit the financial site
On your Azure VM, navigate again to [Link] (clear browser cache first:
Ctrl+Shift+Delete).
Click the padlock icon > Certificate.
The 'Issued by' field should now show the real bank's CA (e.g., DigiCert, Sectigo) — NOT Zscaler.
Screenshot the new certificate details.
Step 17: Document the difference
You should now have two screenshots:
Before bypass: certificate shows Zscaler CA
After bypass: certificate shows the bank's real CA
This visually demonstrates how SSL bypass works.
────────────────────────────────────────────────────────────────────────────────
Part 3: DLP — Credit Card Detection (15 min)
3.1 Create DLP Rule
Step 18: Navigate to DLP
In ZIA Admin Portal: Policy > DLP > + Add Rule.
Step 19: Configure the DLP rule
Name: Detect-Credit-Cards-Lab04
Status: Enabled
Order: 1 (first to be evaluated)
DLP Engines: click + Add Engine > select 'Credit Card Numbers' (PCI-DSS built-in)
Content to inspect: HTTP/HTTPS Uploads (Web)
Users: All Users
Action: Allow & Log (monitor mode — does NOT block, just records)
Notification: None (for lab purposes)
Click Save and Activate.
TIP: Allow & Log is always the right starting point for DLP. This lets you observe what would be caught before
committing to blocking. Review incidents for 2–3 weeks, then switch to Block if the false positive rate is
acceptable.
3.2 Test the DLP Rule
Step 20: Use a DLP test form
On your Azure VM, open a browser and navigate to:
[Link]
(This is a safe, publicly available DLP testing site with dummy credit card numbers.)
Step 21: Submit a test form
On [Link], find the 'Test DLP (HTTP POST)' or similar form.
In the text field, paste the following dummy test CC numbers (these are not real cards):
4111111111111111 (Visa test number)
5500005555555559 (Mastercard test number)
Click Send / Submit.
The data is sent as an HTTP POST — ZIA should intercept and log it.
Step 22: Wait 2–3 minutes
ZIA analytics updates are not instant. Wait 2–3 minutes before checking the DLP report.
3.3 Check DLP Incidents
Step 23: Open DLP Report
In ZIA Admin Portal: Analytics > Reports > DLP Report.
Set time filter to 'Last 1 Hour'.
Look for your test user's entry — you should see:
User: your test user
Rule: Detect-Credit-Cards-Lab04
Content Type: HTTP Request Body
Engine: Credit Card Numbers
Action: Allowed (because we used Allow & Log)
Screenshot the DLP incident record.
WARNING: If no DLP incident appears after 5 minutes, check: (1) Is SSL Inspection enabled for the test site?
DLP cannot see HTTP POST content inside HTTPS without SSL inspection. (2) Is the DLP rule activated? (3) Is
[Link] categorised as HTTPS? Try disabling SSL bypass for 'Technology' or 'General' categories if needed.
────────────────────────────────────────────────────────────────────────────────
Part 4: Analytics Review (10 min)
4.1 Review Transaction Log
Step 24: Open Web Insights
Analytics > Web Insights > Transactions tab.
Set time filter: Last 1 Hour.
Filter by your test user (click Add Filter > User > enter username).
Step 25: Find all three test events
Scroll through transactions to find:
1. Blocked LinkedIn request — Action: Block, Rule: Block-Social-Media-All
2. Allowed LinkedIn request — Action: Allow, Rule: Allow-Social-Media-Lab04
3. SSL bypass — your financial site visit with 'SSL: Not Inspected' status
Screenshot the transaction list showing all three events.
Step 26: Explore transaction details
Click any transaction row to expand the full details:
URL, category, action, rule name, SSL inspection status, bytes transferred, response code
This is the primary troubleshooting view — every user complaint about blocked sites is investigated here.
4.2 Create a Scheduled Report (Bonus)
Step 27: Create scheduled email report
Analytics > Report Management > + Add Report.
Name: Weekly-Top-Blocked-Categories
Report Type: Summary
Content: Top Blocked URL Categories
Frequency: Weekly (every Monday at 09:00)
Recipients: enter your email address
Format: PDF
Click Save.
You will receive an automated weekly PDF report every Monday morning showing the top blocked URL
categories. This is the kind of report a CISO or security team would receive for oversight.
────────────────────────────────────────────────────────────────────────────────
Lab 04 Completion Checklist
[] Block rule created: Block-Social-Media-All (Order 10)
[] Allow exception created: Allow-Social-Media-Lab04 (Order 5, Group: Lab04-Allowed)
[] Both rules activated and tested — block page screenshot + allowed page screenshot
[] SSL bypass created for Financial/Banking categories
[] Certificate screenshots: before bypass (Zscaler CA) and after bypass (real bank CA)
[] DLP rule created: Detect-Credit-Cards-Lab04 (Allow & Log mode)
[] DLP incident visible in Analytics > DLP Report
[] Transaction log screenshot showing block, allow, and SSL bypass events
[] (Bonus) Scheduled email report created
────────────────────────────────────────────────────────────────────────────────
Troubleshooting Reference
Rule not applying: check ZCC is connected (tray icon), changes are activated, and the user is in the correct
group.
URL still blocked after adding exception: rule order is wrong — Allow must be above Block. Check order
numbers.
Certificate still shows Zscaler CA after bypass: clear browser cache (Ctrl+Shift+Delete) and force-reload.
Also confirm the bypass rule is activated and the URL category matches.
DLP incident not appearing: confirm SSL Inspection is active for the test site (check transaction log for SSL:
Inspected). DLP cannot see HTTPS POST content without SSL inspection.
LinkedIn loads even though ZCC is connected: check ZCC profile — the forwarding rule may exclude
certain categories or the user's device type. Also verify the enrolled user matches your test user account.