Skip to main content
Zscaler is a zero trust security platform for internet and private application access. Connect your Zscaler tenant to Oleria to bring user, group, and role access into your identity and access graph, without a dedicated Zscaler-specific integration.

What Oleria discovers

  • User accounts and profile attributes synced from Zscaler’s directory.
  • Groups and their memberships.
  • Roles assigned to each user.
  • Identity posture signals, such as administrative role assignment.
Oleria uses this data for dormant account detection and access reviews, refreshed on Zscaler’s standard sync schedule.

Prerequisites

  • Admin access in Zscaler with permission to generate an API key.
  • Admin access on the Oleria platform to add a new integration.
The exact location of these settings can change over time. If the steps below don’t match what you see, refer to Zscaler’s own API documentation.

Get your SCIM credentials from Zscaler

1

Generate an API key in Zscaler Admin

Sign in to Zscaler Admin, go to Administration → API Key Management, and generate an API key.
2

Copy your SCIM Base URL and Authentication token

Copy both values before you leave the page - you’ll paste them into Oleria in the next section:
  • SCIM Base URL - the HTTPS API endpoint for your Zscaler cloud.
  • Authentication token - the API key you generated.
Copy the key now. Many applications display it only once. Store it securely and rotate it per your organization’s security policy.

Connect Zscaler to Oleria

1

Open the integration

Go to your Oleria workspace, select Integrations, then select the Zscaler tile.
2

Complete the connection form

Select Continue and fill in the connection form:
3

Save the integration

Select Connect to validate the credentials and save the integration.

Verify the integration

Confirm the new instance appears in your Oleria workspace under Connected Integrations with a status of Healthy. Oleria syncs users, groups, and roles from Zscaler on the standard SCIM provisioning schedule once the initial sync completes.
If Zscaler rotates your API key, update the Authentication token in Oleria by editing the integration.

Governance actions

Oleria can also invoke lifecycle actions in Zscaler when the key you provide has write access:
  • Enable or disable a user account
  • Add or remove a user from a group
  • Create a new user or group
Many teams start with a read-only key for visibility, then grant write access once they’re ready to automate remediation in Zscaler.

Contact us

For questions about this integration, contact us at support@oleria.com.