Administrator Documentation  |  Zscaler Platform Migration

Migrating to the
Experience Center

A complete guide for administrators transitioning from legacy Zscaler admin portals (admin.zscalerone.net) to the unified Experience Center console.

Document Version 1.0
New Console URL console.zscaler.com
Deprecation Date September 2026
Audience Zscaler Administrators
⚠️ Action Required: Legacy admin portals (admin.zscalerone.net and others) will be deprecated in September 2026. From April 2026, all new Zscaler features are only available in the Experience Center. Migration to ZIdentity and Experience Center should be completed by March 2026.

Contents

Section 01

Overview & Why This Change

Zscaler is replacing its multiple product-specific administration portals — including admin.zscalerone.net (ZIA), admin.private.zscaler.com (ZPA), and separate ZDX portals — with a single unified console called the Zscaler Experience Center, accessible at console.zscaler.com.

This is not simply a cosmetic rebrand. The Experience Center represents a fundamental architectural shift in how Zscaler delivers its administrative experience — consolidating siloed product portals into one integrated, outcome-driven platform with a shared identity layer.

The Problem with the Legacy Portals

Previously, administrators managing Zscaler services needed to work across multiple disconnected portals. An administrator responsible for both internet security (ZIA) and private access (ZPA) would regularly switch between admin.zscalerone.net and admin.private.zscaler.com, each with separate login credentials, separate dashboards, and separate policy frameworks. ZDX (Digital Experience Monitoring) was yet another separate interface.

ℹ️
Key Motivation

The Experience Center unifies administrative workflows for ZIA, ZPA, ZDX, Zero Trust Branch, and more into a single hub — reducing context-switching and providing cross-product analytics that were impossible with siloed portals.

Section 02

Migration Timeline

Zscaler has published a phased timeline for the migration. It is critical that all administrators understand the key dates and plan accordingly.

Aug 2024

Experience Center Launched Complete

Zscaler introduced the Experience Center as a unified console, initially covering ZIA, ZPA, ZDX, and Client Connector management. Available to all customers to explore.

Nov 2024

Zero Trust Networking Added Complete

Experience Center expanded to include Zero Trust Branch, Zero Trust Cloud, and IoT/OT segmentation capabilities — becoming the true unified SASE console.

Now – Mar 2026

Migration Window Action Required

Customers should complete migration to ZIdentity and the Experience Center. Engage your Zscaler account team for migration assistance. Both old and new portals remain accessible during this period.

April 2026

New Features Experience Center Only Important

From this date, all new Zscaler features and innovations will only be released within the Experience Center. Legacy portals will no longer receive new feature updates.

Sep 2026

Legacy Portals Deprecated Deadline

All legacy Zscaler administrative UIs (admin.zscalerone.net, admin.private.zscaler.com, etc.) will be officially deprecated and shut down. Migration must be complete before this date.

🚨
Do Not Wait Until September 2026

If you do not migrate before April 2026, you will miss access to new features. If you do not migrate before September 2026, you will lose access to your administrative console entirely. Begin planning now.

Section 03

Architecture Comparison

The most significant change is the shift from a fragmented, product-per-portal model to a single unified console with a shared identity layer.

Legacy Architecture — Multiple Siloed Portals
Portal 1
admin.zscalerone.net
ZIA — Internet & SaaS Security
Portal 2
admin.private.zscaler.com
ZPA — Private Access
Portal 3
ZDX Admin Portal
Digital Experience Monitoring
Separate Logins
Separate Logins
Separate Logins
Identity
ZIA Credentials
Identity
ZPA Credentials
Identity
ZDX Credentials
New Architecture — Unified Experience Center
Single Identity Layer
ZIdentity
Your enterprise IdP (Okta / Entra ID / Ping) · MFA by default · SCIM provisioning
Unified Admin Console
console.zscaler.com
Experience Center — One interface for all Zscaler products
ZIA
Internet & SaaS
ZPA
Private Access
ZDX
Digital Experience
Networking
Branch & Cloud
Section 04

Portal Comparison: At a Glance

The table below summarises the key differences administrators will encounter when moving from the legacy portals to the Experience Center.

Feature / Aspect Legacy Portals (admin.zscalerone.net) Experience Center (console.zscaler.com)
Access URL admin.zscalerone.net, admin.private.zscaler.com, ZDX portal (separate) console.zscaler.com (single URL for all products)
Login Method Product-specific credentials per portal; separate logins required for ZIA, ZPA, and ZDX Single sign-on via ZIdentity; integrates with your enterprise IdP (Okta, Entra ID, Ping); MFA enforced by default
Product Scope One portal per product. Switching products requires navigating to a different URL All products managed from one console: ZIA, ZPA, ZDX, Zero Trust Branch, Risk360, and more
Dashboard / Analytics Product-isolated dashboards; no cross-product unified view Unified analytics across internet/SaaS, private access, and digital experience; consolidated traffic, threats, and user views
Policy Management Separate policy frameworks per product; internet and private access policies managed independently Common policy framework across access controls, cybersecurity, data protection, and digital experience management
Admin Role Management Roles and entitlements managed separately in each product portal Centralised entitlement management via ZIdentity; SCIM-based auto-provisioning from your IdP; unified RBAC
Location Management Managed separately per product; no single view of all locations Unified Locations: manage branches, cloud connectors, IPSec/GRE tunnels from a single workflow
AI & GenAI Features Not available in legacy portals GenAI-driven interactive guidance, AI-powered policy recommendations, Risk360 risk intelligence
Future Feature Access No new features from April 2026; fully deprecated September 2026 All new Zscaler features and innovations exclusively released here from April 2026 onwards
MFA Requirement Optional / product-specific MFA enforced by default via ZIdentity; strongly recommended to keep enabled
Legacy Portal Navigation
Dashboard ZIA only
Policy > URL Filtering ZIA only
Policy > Firewall ZIA only
Reports > Web Insights ZIA only
→ Switch to admin.private.zscaler.com for ZPA
→ Switch to ZDX portal for DEM
Experience Center Navigation
Overview Dashboard All products
Internet & SaaS (ZIA) All ZIA controls
Private Access (ZPA) All ZPA controls
Digital Experience (ZDX) DEM & insights
Zero Trust Networking Branch & Cloud
Risk360 & Analytics Unified risk view
Section 05

New Login Experience & ZIdentity

One of the most significant changes administrators will notice is the new login experience powered by ZIdentity — Zscaler's centralised identity service (formerly known as ZSLogin).

What is ZIdentity?

  • Zscaler's common identity service for the entire Zero Trust platform
  • Integrates with your existing enterprise IdP (Okta, Microsoft Entra ID, Ping Identity)
  • Provides a single set of credentials for all Zscaler admin portals
  • Supports SAML and OpenID Connect SSO
  • Includes built-in MFA (enabled by default)
  • Supports SCIM for automated admin provisioning

Benefits for Admins

  • No more managing separate passwords for ZIA, ZPA, and ZDX
  • Single login to access all Zscaler products
  • Admin accounts can be provisioned/deprovisioned automatically via SCIM
  • Centralised entitlement and role management
  • Step-up authentication for sensitive operations
  • Passwordless MFA options available

Migration Paths for Admin Accounts

How your organisation migrates to ZIdentity depends on your current identity provider configuration:

If you use an external SAML IdP for admin authentication:

Zscaler will provide a staging environment for you to test and validate the migration before going live. You will have the opportunity to verify the integration with your IdP before any change affects your production environment.

ℹ️
If you do not use an external SAML IdP:

Zscaler may automatically upgrade your admin accounts. You will receive communication from Zscaler ahead of any automated migration. Admin credentials will be migrated to ZIdentity hosted accounts with MFA enabled.

⚠️
MFA is Required

ZIdentity enforces MFA by default and Zscaler strongly recommends keeping it enabled. A compromised admin account without MFA could provide attackers with unrestricted access to your Zero Trust configuration. Do not disable MFA without a compelling reason.

Section 06

New Features in the Experience Center

The Experience Center is not just a consolidated interface — it introduces capabilities that were not possible with the siloed legacy portals. These features are only available in the Experience Center.

📊

Unified Analytics Dashboard

A single consolidated view across internet/SaaS traffic, private access, and digital experience. See users, cyber threats, data protection events, and network health in one place without switching portals.

🤖

GenAI-Driven Guidance

Interactive AI assistance within the console to guide administrators through complex configuration tasks, policy recommendations, and Zero Trust adoption — reducing reliance on documentation.

🛡️

Risk360

A comprehensive risk intelligence tool that surfaces and prioritises risks within your Zero Trust network, helping administrators understand and remediate their organisation's overall security posture.

💚

Health360

A proactive deployment health tool that measures and optimises the performance and configuration health of your Zscaler deployment — identifying gaps before they become incidents.

📍

Unified Location Management

Manage all locations — branches, cloud edges, data centres, OT/IoT factories, SD-WAN sites — from a single workflow. No more toggling between interfaces for site-by-site administration.

🔒

Step-Up Authentication

Require additional authentication challenges before sensitive administrative operations, reducing the blast radius of a compromised admin session without impacting day-to-day workflows.

🌿

Zero Trust Branch (SD-WAN)

Manage Zero Trust SD-WAN, branch connectors, and IoT/OT device segmentation directly from the Experience Center. Zero-touch provisioning for branch appliances via templates.

👥

Persona-Driven Workflows

The Experience Center adapts its interface to the administrator's role — security engineers, network administrators, and executives all see relevant views tailored to their responsibilities.

Section 07

What Changes for Administrators

This section walks through the specific changes administrators will experience when they begin using the Experience Center.

Day-to-Day Administration

Your existing Zscaler configuration — policies, rules, users, locations, app segments — will carry over to the Experience Center. You are not reconfiguring Zscaler from scratch. What changes is how you access and manage that configuration.

Your Configuration Is Preserved

All existing ZIA policies, ZPA application segments, forwarding profiles, user/group configurations, and location settings migrate automatically. The Experience Center is a new interface to the same underlying platform.

Navigation Changes

The navigation structure in the Experience Center is reorganised around outcomes and use cases rather than individual products. Administrators who are accustomed to the ZIA or ZPA portal menu structure will find their settings in different menu locations. Here is a guide to the major navigation changes:

Task Legacy Portal Location Experience Center Location
URL Filtering Policies ZIA Portal → Policy → URL & Cloud App Control Internet & SaaS → Cyberthreat Protection → URL Filtering
Firewall Rules ZIA Portal → Policy → Firewall Control Internet & SaaS → Firewall
DLP Policies ZIA Portal → Policy → DLP Data Security → Web & Email DLP
App Segment Management ZPA Portal → Applications Private Access → Application Segments
Access Policies (ZPA) ZPA Portal → Policy → Access Policy Private Access → Policies → Access Policies
ZPA App Connectors ZPA Portal → Infrastructure → App Connectors Private Access → Infrastructure → App Connectors
Digital Experience Monitoring Separate ZDX portal Digital Experience → Dashboard / Apps / Devices
Locations ZIA Portal → Administration → Locations Infrastructure → Locations (unified view)
Admin Management ZIA Portal → Administration → Administrators Administration → ZIdentity → Admin Accounts
Activity Logs ZIA Portal → Analytics → Web Insights Analytics → Logs (unified across ZIA & ZPA)

Bookmarks & Saved URLs

⚠️
Update Bookmarks Before Deprecation

Any browser bookmarks or documentation referencing admin.zscalerone.net, admin.private.zscaler.com, or other legacy portal URLs will need to be updated to console.zscaler.com. Deep-link URLs to specific settings pages will also change. Plan to update any internal runbooks, SOPs, or documentation that contain legacy portal URLs.

API & Automation Changes

The Experience Center introduces OneAPI — a unified API layer that replaces the separate product-specific APIs. If your organisation uses Zscaler APIs for automation (Terraform, scripts, SIEM integrations, etc.), you will need to review and update your API integrations as part of the migration planning process. Consult your Zscaler account team for the OneAPI migration guide specific to your integrations.

Section 08

Migration Steps

Follow these steps to complete your migration to ZIdentity and the Experience Center. Engage your Zscaler account team early — they can provide hands-on migration assistance.

1

Engage Your Zscaler Account Team Now

Contact your Zscaler account team to discuss your migration timeline, review any specific considerations for your environment, and request access to migration resources. Zscaler can also schedule onsite or virtual migration assistance sessions.

2

Review Your IdP Configuration

Determine whether your admin accounts currently authenticate via an external SAML IdP or use native Zscaler credentials. This determines your migration path. If you use Okta, Microsoft Entra ID, or Ping Identity for admin SSO, prepare to configure ZIdentity to federate with your IdP.

3

Access the Experience Center Try Now

Navigate to console.zscaler.com and explore the new interface. The Experience Center is available now and your existing configuration is visible within it. Familiarise yourself with the new navigation structure before the mandatory cutover date.

4

Migrate Admin Accounts to ZIdentity

Follow the ZIdentity migration wizard or work with your account team to migrate administrator accounts to ZIdentity. Validate that all admins can successfully authenticate via ZIdentity before cutting over. Test MFA flows and verify RBAC roles carry over correctly.

5

Train Administrators

Conduct orientation sessions for all Zscaler administrators on the new Experience Center navigation. Focus on the most common day-to-day tasks: policy changes, log review, user lookups, and incident response workflows. Zscaler's Customer Success Center and Zenith Community have training resources available.

6

Update Internal Documentation & Runbooks

Update any internal SOPs, runbooks, incident response playbooks, or training materials that reference legacy portal URLs or navigation paths. Replace admin.zscalerone.net references with console.zscaler.com and update any step-by-step navigation instructions.

7

Review & Update API Integrations If applicable

If you use Zscaler APIs for automation, SIEM integration, or Terraform, assess the impact of the OneAPI migration. Work with your account team to plan API integration updates and test them in a non-production environment before cutting over.

8

Complete Migration Before March 2026 Deadline

Ensure all administrators are fully using the Experience Center and ZIdentity for all administrative tasks. Verify no critical workflows still depend on legacy portal access before the April 2026 feature freeze date.

Pre-Migration Checklist

Section 09

Frequently Asked Questions

Will my existing Zscaler configuration (policies, rules, users) be lost during migration?
No. Your existing configuration is preserved. The Experience Center is a new interface to the same underlying Zscaler platform. All policies, app segments, user/group configurations, and locations that exist in your current portals will be accessible in the Experience Center without any reconfiguration.
Can I still use admin.zscalerone.net while transitioning to the Experience Center?
Yes. Both the legacy portals and the Experience Center are available simultaneously during the migration window. You can use both in parallel until September 2026 when the legacy portals are deprecated. However, note that from April 2026, new features will only appear in the Experience Center, so legacy portal users will have a progressively diminishing experience.
Do we need to reconfigure MFA for admin accounts?
ZIdentity includes built-in MFA and it is enabled by default. If you currently use an external IdP with MFA for admin logins, your IdP's MFA will continue to be used. If admins currently authenticate with native Zscaler credentials without MFA, they will need to enrol in ZIdentity MFA as part of the migration. Zscaler strongly recommends keeping MFA enabled.
Will our Terraform / API scripts still work after the migration?
Existing Zscaler API integrations may be impacted by the OneAPI changes introduced with the Experience Center. Zscaler is providing migration guidance for API consumers. You should conduct an audit of all API-dependent workflows and work with your account team to understand the specific impact and migration path for your integrations before the deprecation date.
How long will the migration to ZIdentity and Experience Center take?
The technical migration itself (migrating admin accounts to ZIdentity) can be relatively quick — potentially completed in a single change window with Zscaler's assistance. The larger effort involves training administrators, updating documentation, and auditing API integrations. Organisations should plan for 2–4 weeks of change management activity, depending on complexity.
What happens to admins who have different roles in ZIA vs ZPA?
ZIdentity's centralised entitlement management allows administrators to have different roles across Zscaler products from a single account. If an admin currently has a read-only role in ZIA but full admin in ZPA, that differentiated entitlement model is supported in ZIdentity. Role assignments should be reviewed and validated during the ZIdentity migration.
Is the Experience Center available in all Zscaler cloud environments (ZscalerOne, ZscalerTwo, etc.)?
The Experience Center is being rolled out across Zscaler's cloud environments. Your account team can confirm the availability timeline for your specific cloud environment and guide you through the correct console.zscaler.com tenant URL for your organisation.
Where can I find help if I get lost in the new interface?
The Experience Center includes built-in GenAI-powered guidance to assist administrators. Additionally, Zscaler's Help Portal (help.zscaler.com) contains updated documentation for the Experience Center. The Zenith Community (community.zscaler.com) is also a valuable resource for peer support and Zscaler expert advice.
Section 10

Support & Resources

Zscaler provides extensive support resources to assist with the migration. The following are the primary channels available to your team.

🧑‍💼

Your Zscaler Account Team

Your first point of contact. Account teams can schedule migration workshops, provide environment-specific guidance, and coordinate with Zscaler's technical teams to support your transition.

📚

Zscaler Help Portal

Comprehensive technical documentation at help.zscaler.com, including dedicated sections for the Experience Center, ZIdentity migration guides, and the new unified admin documentation.

🏘️

Zenith Community

Peer community at community.zscaler.com where you can connect with other Zscaler admins who have completed the migration, share experiences, and get answers from Zscaler experts.

🎓

Zscaler Cyber Academy

Free and paid training courses on the Experience Center and ZIdentity administration, including hands-on labs in a live Zscaler environment. Available at the Zscaler Customer Success Center.

🆘

Zscaler Support

For technical issues encountered during or after migration, open a support case via the Zscaler Help Portal or contact your regional support team. Phone support contacts are listed at help.zscaler.com/phone-support.

🔗

ZIdentity Migration Guide

Zscaler's dedicated migration landing page at info.zscaler.com/begin-your-zidentity-migration provides step-by-step migration instructions and resources specifically for the ZIdentity transition.

📎
Key URLs to Bookmark

New Admin Console: https://console.zscaler.com
Help Portal: https://help.zscaler.com
ZIdentity Docs: https://help.zscaler.com/zidentity
Migration Guide: https://info.zscaler.com/begin-your-zidentity-migration
Zenith Community: https://community.zscaler.com