ZPA Authentication & MFA Concepts

Zscaler Private Access (ZPA) Zscaler portal — demo tenant (GUI)

مقصدObjectiveObjective

اس سبق میں آپ دیکھیں گے کہ ZPA Identity Provider سے کیسے جڑتا ہے، MFA کہاں fit ہوتا ہے، اور posture checks رسائی کے فیصلے میں کیا اضافہ کرتے ہیں۔Is lesson mein aap dekhenge ke ZPA Identity Provider se kaise jurta hai, MFA kahan fit hota hai, aur posture checks access decision mein kya izafa karte hain.In this lesson you will see how ZPA connects with an Identity Provider, where MFA fits in, and what posture checks add to access decisions.

آسان مثالSimple AnalogySimple Analogy

IdP نادرا آفس جیسا ہے: ZPA خود ID کارڈ نہیں بناتا — وہ نادرا کے کارڈ پر بھروسہ کرتا ہے۔ MFA دوسرا ثبوت ہے، جیسے کارڈ کے ساتھ فنگر پرنٹ۔IdP NADRA office jaisa hai: ZPA khud ID card nahi banata — woh NADRA ke card par bharosa karta hai. MFA doosra saboot hai, jaise card ke saath fingerprint.An IdP is like the NADRA office: ZPA doesn't make the ID card itself — it trusts NADRA's card. MFA is the second proof, like a fingerprint along with the card.

سیٹ اپLab SetupLab Setup

Zscaler پورٹل ڈیمو ٹیننٹ۔ Administration > IdP Configuration اور Policy > Access Policy کھول کر ساتھ چلیں۔ زیادہ تر تصوری، پورٹل views کے ساتھ۔Zscaler portal demo tenant. Administration > IdP Configuration aur Policy > Access Policy khol kar saath chalein. Zyada tar conceptual, portal views ke saath.Zscaler portal demo tenant. Open Administration > IdP Configuration and Policy > Access Policy to follow along. Mostly conceptual, with portal views.

اقداماتStepsSteps

Step 1

ZPA صارف کے پاس ورڈز خود نہیں رکھتا۔ یہ Identity Provider (Okta, Microsoft Entra ID, Google Workspace) سے جڑتا ہے اور پہچان کے لیے اس پر بھروسہ کرتا ہے۔ZPA user ke passwords khud nahi rakhta. Ye Identity Provider (Okta, Microsoft Entra ID, Google Workspace) se jurta hai aur identity ke liye us par bharosa karta hai.ZPA does not keep user passwords itself. It connects to an Identity Provider (Okta, Microsoft Entra ID, Google Workspace) and trusts it for identity.

Step 2

Administration > IdP Configuration میں admin SAML metadata سے IdP جوڑتا ہے۔ Users, groups اور SSO login اسی کنیکشن سے آتے ہیں۔Administration > IdP Configuration mein admin SAML metadata se IdP jorta hai. Users, groups aur SSO login isi connection se aate hain.In Administration > IdP Configuration the admin adds the IdP using SAML metadata. Users, groups, and SSO login all come from this connection.

🖱️ Administration > IdP Configuration > Add IdPAdministration > IdP Configuration > Add IdPAdministration > IdP Configuration > Add IdP

Step 3

MFA (multi-factor authentication) دوسرا ثبوت ہے: پاس ورڈ کے ساتھ فون کوڈ یا authenticator app۔ ZPA اسے IdP کی policy سے لاگو کرتا ہے۔MFA (multi-factor authentication) doosra saboot hai: password ke saath phone code ya authenticator app. ZPA ise IdP ki policy se laagu karta hai.MFA (multi-factor authentication) is the second proof: password plus a phone code or authenticator app. ZPA enforces it through the IdP's policy.

Step 4

Posture checks ڈیوائس کو چیک کرتے ہیں: OS version, patch level, disk encryption, antivirus, jailbreak/root status۔ بیمار ڈیوائس کو block کیا جا سکتا ہے یا remediation segment میں بھیجا جا سکتا ہے۔Posture checks device ko check karte hain: OS version, patch level, disk encryption, antivirus, jailbreak/root status. Bemar device ko block kiya ja sakta hai ya remediation segment mein bheja ja sakta hai.Posture checks inspect the device: OS version, patch level, disk encryption, antivirus, and jailbreak/root status. An unhealthy device can be blocked or sent to a remediation segment.

Step 5

Policy > Access Policy میں تینوں جوڑ سکتے ہیں: user group کو ALLOW، MFA ضروری، اور compliant posture ضروری۔ Continuous verification ہی زیرو ٹرسٹ کا عمل ہے۔Policy > Access Policy mein teeno jor sakte hain: user group ko ALLOW, MFA zaroori, aur compliant posture zaroori. Continuous verification hi Zero Trust ka amal hai.In Policy > Access Policy you can combine all three: ALLOW a user group AND require MFA AND require compliant posture. Continuous verification is Zero Trust in action.

🖱️ Policy > Access Policy > Add Rule > ConditionsPolicy > Access Policy > Add Rule > ConditionsPolicy > Access Policy > Add Rule > Conditions

تصدیقVerifyVerify

ڈیمو user سے sign-in کریں، MFA prompt تصدیق کریں، پھر posture fail کر کے (جیسے jailbreak) policy کا block دیکھیں۔Demo user se sign-in karein, MFA prompt confirm karein, phir posture fail kar ke (jaise jailbreak) policy ka block dekhein.Sign in with a demo user, confirm MFA prompts appear, then deny posture (e.g. jailbreak) and watch the policy block access.

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ IdP login کامیاب ہونے کے بعد بھی users کو 'access denied' ملتا ہے۔IdP login kamyab hone ke baad bhi users ko 'access denied' milta hai.Users get 'access denied' even after successful IdP login.

✅ Login کامیاب تھا لیکن Access Policy نے block کیا۔ User کے IdP groups کو policy conditions سے ملائیں — عام طور پر group name کا فرق ہوتا ہے۔Login kamyab tha lekin Access Policy ne block kiya. User ke IdP groups ko policy conditions se milayein — aam tor par group name ka farq hota hai.Login succeeded but the Access Policy blocked them. Check the user's IdP groups against the policy conditions — usually a group name mismatch.

⚠️ MFA لاگو نہیں ہو رہا حالانکہ ضروری set ہے۔MFA laagu nahi ho raha halan ke zaroori set hai.MFA is not being enforced even though it is required.

✅ MFA IdP سے لاگو ہوتا ہے، ZPA خود سے نہیں۔ پہلے IdP کی MFA policy اور sign-in logs چیک کریں۔MFA IdP se laagu hota hai, ZPA khud se nahi. Pehle IdP ki MFA policy aur sign-in logs check karein.MFA is enforced by the IdP, not ZPA itself. Check the IdP's own MFA policy and sign-in logs first.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ IdP کیا ہے اور ZPA کو اس کی ضرورت کیوں ہے؟IdP kya hai aur ZPA ko is ki zaroorat kyun hai?What is an IdP and why does ZPA need one?

یہ وہ trusted identity store ہے (Okta, Entra ID, Google) جو ZPA login، groups اور SSO کے لیے استعمال کرتا ہے۔Ye woh trusted identity store hai (Okta, Entra ID, Google) jo ZPA login, groups aur SSO ke liye istemal karta hai.It is the trusted identity store (Okta, Entra ID, Google) that ZPA uses for login, groups, and SSO.

❓ ZPA میں posture checks کیا کرتی ہیں؟ZPA mein posture checks kya karti hain?What do posture checks do in ZPA?

Posture checks ڈیوائس کی صحت دیکھتی ہیں — OS version, disk encryption, AV, jailbreak — اور policy رسائی کے لیے صحت مند posture مانگ سکتی ہے۔Posture checks device ki sehat dekhti hain — OS version, disk encryption, AV, jailbreak — aur policy access ke liye sehatmand posture maang sakti hai.Posture checks look at the device's health — OS version, disk encryption, AV, jailbreak — and policy can require healthy posture for access.