Diocese Zscaler Portal Administrator Documentation  |  CEnet organised Migration

Migrating to the
Experience centre

A guide for diocese administrators transitioning from legacy Zscaler admin portals (admin.zscalerone.net) to the unified Experience centre console.

New Console URL console.zscaler.com
Deprecation Date September 2026
Audience Diocese Zscaler Portal Administrators
⚠️ The current admin portals (admin.zscalerone.net and others) will be deprecated - September 2026.

Contents

Section 01

Overview / TLDR

ℹ️
Too long - didn't read...

In the coming weeks CEnet will reach out to each diocese to migrate all diocese zscaler administrators to the new ZSlogin / ZIdentity service. This introduces MFA to the administrator login flow. Diocese admins will still use the same Authenticator app they currently use and are used to.

Only accounts that are in IDP will be migrated.
Local accounts with credentials stored in the zscaler portal will not be migrated.


During the process a "break glass" account is created that CEnet will maintain.
In the event that diocese administrators find they do not have the access they expected, CEnet can grant extra permissions using this account.(This will require a support ticket to CEnet.)

Zscaler is replacing its multiple product-specific administration portals — including admin.zscalerone.net (ZIA), admin.private.zscaler.com (ZPA), and separate ZDX portals — with a single unified console called the Zscaler Experience centre, accessible at console.zscaler.com.

This is not simply a cosmetic rebrand. The Experience centre represents a fundamental architectural shift in how Zscaler delivers its administrative experience — consolidating siloed product portals into one integrated platform with a shared identity layer.

Eventual removal of the Legacy Portals

Previously, diocese administrators managing Zscaler services needed to work across multiple disconnected portals. A diocese administrator responsible for both internet security (ZIA) and private access (ZPA) would regularly switch between admin.zscalerone.net and admin.private.zscaler.com, each with separate login credentials, separate dashboards, and separate policy frameworks. ZDX (Digital Experience Monitoring) was yet another separate interface.

ℹ️
Key Motivation

As well as enabling a more seciure MFA process for diocese administratos, the Experience centre unifies administrative workflows for ZIA, ZPA, ZDX, Zero Trust Branch, and more into a single hub — reducing context-switching and providing cross-product analytics that were impossible with siloed portals.

Section 02

Migration Timeline

Zscaler has published a phased timeline for the migration.

Aug 2024

Experience centre Launched Complete

Zscaler introduced the Experience centre as a unified console, initially covering ZIA, ZPA, ZDX, and Client Connector management. Available to all customers to explore.

Nov 2024

Zero Trust Networking Added Complete

Experience centre expanded to include Zero Trust Branch, Zero Trust Cloud, and IoT/OT segmentation capabilities — becoming the true unified SASE console.

Now – Ongoing 2026

Migration Window in Progress

CEnet will contact each diocese seperately in the coming weeks to organise the migration. Both old and new portals remain accessible during this period.

1st Sep 2026

Legacy Portals Deprecated Deadline

All legacy Zscaler administrative UIs (admin.zscalerone.net, admin.private.zscaler.com, etc.) will be officially deprecated and shut down.

Section 03

Architecture Comparison

The most significant change is the shift from a fragmented, product-per-portal model to a single unified console with a shared identity layer.

Legacy Architecture — Multiple Siloed Portals
Portal 1
admin.zscalerone.net
ZIA — Internet & SaaS Security
Portal 2
admin.private.zscaler.com
ZPA — Private Access
Portal 3
ZDX Admin Portal
Digital Experience Monitoring
Separate Logins
Separate Logins
Separate Logins
Identity
ZIA Credentials
Identity
ZPA Credentials
Identity
ZDX Credentials
New Architecture — Unified Experience centre
Single Identity Layer
ZIdentity
Your enterprise IdP (Okta / Entra ID / Ping) · MFA by default · SCIM provisioning
Unified Admin Console
console.zscaler.com
Experience centre — One interface for all Zscaler products
ZIA
Internet & SaaS
ZPA
Private Access
ZDX
Digital Experience
Networking
Branch & Cloud
Section 04

Portal Comparison: At a Glance

The table below summarises the key differences administrators will encounter when moving from the legacy portals to the Experience centre.

Feature / Aspect Legacy Portals (admin.zscalerone.net) Experience centre (console.zscaler.com)
Access URL admin.zscalerone.net, admin.private.zscaler.com, ZDX portal (separate) console.zscaler.com (single URL for all products)
Login Method Product-specific credentials per portal; separate logins required for ZIA, ZPA, and ZDX Single sign-on via ZIdentity; integrates with your enterprise IdP (Okta, Entra ID, Ping); MFA enforced by default
Product Scope One portal per product. Switching products requires navigating to a different URL All products managed from one console: ZIA, ZPA, ZDX, Zero Trust Branch, Risk360, and more
Dashboard / Analytics Product-isolated dashboards; no cross-product unified view Unified analytics across internet/SaaS, private access, and digital experience; consolidated traffic, threats, and user views
Policy Management Separate policy frameworks per product; internet and private access policies managed independently Common policy framework across access controls, cybersecurity, data protection, and digital experience management
Admin Role Management Roles and entitlements managed separately in each product portal Centralised entitlement management via ZIdentity; SCIM-based auto-provisioning from your IdP; unified RBAC
Location Management Managed separately per product; no single view of all locations Unified Locations: manage branches, cloud connectors, IPSec/GRE tunnels from a single workflow
Future Feature Access No new features from April 2026; fully deprecated September 2026 All new Zscaler features and innovations exclusively released here from April 2026 onwards
MFA Requirement Optional / product-specific MFA enforced by default via ZIdentity
Legacy Portal Navigation
Dashboard ZIA only
Policy > URL Filtering ZIA only
Policy > Firewall ZIA only
Reports > Web Insights ZIA only
→ Switch to admin.private.zscaler.com for ZPA
→ Switch to ZDX portal for DEM
Experience centre Navigation
Overview Dashboard All products
Internet & SaaS (ZIA) All ZIA controls
Private Access (ZPA) All ZPA controls
Digital Experience (ZDX) DEM & insights
Section 05

New Login Experience & ZIdentity

One of the most significant changes administrators will notice is the new login experience powered by ZIdentity — Zscaler's centralised identity service (formerly known as ZSLogin).

What is ZIdentity?

  • Zscaler's common identity service for the entire Zero Trust platform
  • Integrates with your existing enterprise IdP (Okta, Microsoft Entra ID, Ping Identity)
  • Provides a single set of credentials for all Zscaler admin portals
  • Supports SAML and OpenID Connect SSO
  • Includes built-in MFA (enabled by default)
  • Supports SCIM for automated admin provisioning

Benefits for Admins

  • No more managing separate passwords for ZIA, ZPA, and ZDX
  • Single login to access all Zscaler products
  • Admin accounts can be provisioned/deprovisioned automatically via SCIM
  • Centralised entitlement and role management
  • Step-up authentication for sensitive operations
  • Passwordless MFA options available

Migration Paths for Admin Accounts

How your organisation migrates to ZIdentity depends on your current identity provider configuration:

If you use SAML IdP for admin authentication:

CEnet has already implemeted a staging environment for all diocese. In the coming weeks CEnet will reach out to your teams to orgnise the full migration. Only accounts currently in IdP will be provisioned. Local Admin accounts will cease to function.

⚠️
MFA is Required

Once migrated, MFA is on by default and diocese portal administrators will be prompted to enroll for MFA.

Section 06

New Features in the Experience centre

The Experience centre is not just a consolidated interface — it introduces capabilities that were not possible with the siloed legacy portals. These features are only available in the Experience centre.

📊

Unified Analytics Dashboard

A single consolidated view across internet/SaaS traffic, private access, and digital experience. See users, cyber threats, data protection events, and network health in one place without switching portals.

🤖

Context based Guidance

Interactive context based assistance within the console to guide administrators through complex configuration tasks, policy recommendations.

📍

Unified Location Management

Manage all locations — branches, cloud edges, data centres, OT/IoT factories, SD-WAN sites — from a single workflow. No more toggling between interfaces for site-by-site administration.

🔒

Step-Up Authentication

Require additional authentication challenges before sensitive administrative operations, reducing the blast radius of a compromised admin session without impacting day-to-day workflows.

Section 07

What Changes for Administrators

✅ - MFA will be enabled for Portal administrators.

Upon first login to the new console / experience centre, administrators will be requested to enrol in MFA using your preferred Authenticator app.

Day-to-Day Administration

Your existing Zscaler configuration — policies, rules, users, locations, app segments — will carry over to the Experience Centre. You are not reconfiguring Zscaler from scratch. What changes is how you access and manage that configuration.

🔗
Your Configuration Is Preserved

All existing ZIA policies, ZPA application segments, forwarding profiles, user/group configurations, and location settings migrate automatically. The Experience Centre is a new interface to the same underlying platform.

Navigation Changes

The navigation structure in the Experience Centre is reorganised around outcomes and use cases rather than individual products. Administrators who are accustomed to the ZIA or ZPA portal menu structure will find their settings in different menu locations. Here is a brief guide to the major navigation changes:

Task Legacy Portal Location Experience Centre Location
URL Filtering Policies ZIA Portal → Policy → URL & Cloud App Control Internet & SaaS → Cyberthreat Protection → URL Filtering
Firewall Rules ZIA Portal → Policy → Firewall Control Internet & SaaS → Firewall
DLP Policies ZIA Portal → Policy → DLP Data Security → Web & Email DLP
App Segment Management ZPA Portal → Applications Private Access → Application Segments
Access Policies (ZPA) ZPA Portal → Policy → Access Policy Private Access → Policies → Access Policies
ZPA App Connectors ZPA Portal → Infrastructure → App Connectors Private Access → Infrastructure → App Connectors
Digital Experience Monitoring Separate ZDX portal Digital Experience → Dashboard / Apps / Devices
Locations ZIA Portal → Administration → Locations Infrastructure → Locations (unified view)
Admin Management ZIA Portal → Administration → Administrators Administration → ZIdentity → Admin Accounts
Activity Logs ZIA Portal → Analytics → Web Insights Analytics → Logs (unified across ZIA & ZPA)

Bookmarks & Saved URLs

⚠️
Update Bookmarks Before Deprecation

Any browser bookmarks or documentation referencing admin.zscalerone.net, admin.private.zscaler.com, or other legacy portal URLs will need to be updated to console.zscaler.com. Deep-link URLs to specific settings pages will also change. Plan to update any internal documentation that contain legacy portal URLs.

Section 08

Migration Steps

CEnet is handling the migration. Contact will be made with each diocese in the coming weeks.

1

CEnet managing the migration process Now

CEnet has already created staging areas for the current diocse Zscaler admins - If you currently use local admins that are not part of IdP this can be discussed when your portal is prepared for migration.

2

CEnet will review you IdP Configuration

As mentioned, local (portal defined) admins will not come across in the migration, only IDP based credentials will be migrated.

3

Access the Experience centre Try Now

Navigate to console.zscaler.com and explore the new interface. The Experience centre is available now and your existing configuration is visible within it.

Section 09

Frequently Asked Questions

Will my existing Zscaler configuration (policies, rules, users) be lost during migration?
No. Your existing configuration is preserved. The Experience centre is a new interface to the same underlying Zscaler platform. All policies, app segments, user/group configurations, and locations that exist in your current portals will be accessible in the Experience centre without any reconfiguration.
Can I still use admin.zscalerone.net while transitioning to the Experience centre?
Yes. Both the legacy portals and the Experience centre are available simultaneously during the migration window. You can use both in parallel until September 2026 when the legacy portals are deprecated. However, note that from April 2026, new features will only appear in the Experience centre, so legacy portal users will have a progressively diminishing experience.
Where can I find help if I get lost in the new interface?
Log a support ticket to CEnet to request any assistance.

The Experience centre alsoincludes built-in GenAI-powered guidance to assist administrators. Additionally, Zscaler's Help Portal contains updated documentation for the Experience centre. The Zenith Community is also a valuable resource for peer support and Zscaler expert advice.
Section 10

Support & Resources

🆘

CEnet

Your first point of contact.

Call the CEnet service desk or log a ticket.

📚

Zscaler Help Portal

Comprehensive technical documentation at help.zscaler.com, including dedicated sections for the Experience centre, ZIdentity migration guides, and the new unified admin documentation.

🎓

Zscaler Cyber Academy

Free and paid training courses on the Experience centre and ZIdentity administration, including hands-on labs in a live Zscaler environment.

🔗

ZIdentity Migration Guide

Zscaler's dedicated migration landing page at provides step-by-step migration instructions and resources specifically for the ZIdentity transition.

📎