Configuring the Zscaler Client Connector (ZCC)

Technical Paper: Integrating Zscaler with Jamf Device Identity

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

The Zscaler Client Connector, which runs on Mac computers, communicates with Jamf Trust.

Requirements

A Zscaler account with administrator-level privileges

  1. In the Zscaler Client Connector portal, create a device posture configuration.
    1. Navigate to Administration > Device Posture.
    2. Add Device Posture.
    3. Deselect all operating systems, except for macOS.
    4. Under Define Posture Configuration, select Posture Type.
    5. Select JAMF Risk Level.
    6. Choose between Secure, Low, Medium, and High.
    7. Repeat steps 4 - 6 as necessary to define various risk levels for all device risk identities.
    8. Click Save.
  2. Modify the device posture configuration to include your ZIA posture profile.
    1. Navigate to Administration > ZIA Posture Profile
    2. Select macOS.
    3. Click Add ZIA Posture.
    4. Add a name for the posture profile.
    5. Under High Trust, select the device posture profile that aligns with a highly trusted device in the Expression > Any field.
    6. Under Medium Trust, select the device posture profile that aligns with a medially trusted device in the Expression > Any field.
    7. Under Low Trust, select the device posture profile that aligns with a lowly trusted device in the Expression > Any field.
  3. Enable the macOS policy and implement your ZIA posture profile.
    1. Navigate to App Profiles > macOS.
    2. Select Add macOS Policy.
    3. Add a name and enable the policy.
    4. Select Install Zscaler SSL Certificate.
    5. Select ZIA Posture Profile and select your ZIA posture profile.
  4. Allow the policy to be deployed by Jamf Pro or an alternate UEM.
    1. Navigate to Administration > Client Connector App Store.
    2. Select New Releases.
    3. Under Platform, select macOS.
    4. Select the Enable Build toggle and download the PKG file if you are using a UEM other than Jamf Pro.

You can now upload the Client Connector PKG file to Jamf Pro and push the PKG to your devices via a policy.