Zpa Create Access Policy Rule

by zscaler809f68d6c921No licenseListed Oct 8, 2026Updated Oct 8, 2026

Create ZPA access policy rules with v2 conditions. Supports all condition object types: APP, APP_GROUP, SAML, SCIM, SCIM_GROUP, PLATFORM, COUNTRY_CODE, POSTURE, TRUSTED_NETWORK, RISK_FACTOR_TYPE, CLIENT_TYPE, MACHINE_GRP, LOCATION, and CHROME_ENTERPRISE. Walks through: (1) gathering requirements, (2) looking up identity attributes (SAML/SCIM), (3) building the conditions payload, (4) creating the rule. Includes ready-to-use examples for common scenarios: SCIM group access, SAML attribute matching, platform restrictions, country-based access, posture checks, and combined conditions.

Instructions onlySecurityDevOps & Cloud
AI-generated overview

Guides creation of ZPA access policy rules with v2 conditions for identity, device, network and risk criteria.

What it does
This skill walks an administrator through creating ZPA access policy rules using the v2 condition format. It covers gathering requirements, looking up identity and posture identifiers, assembling the conditions payload, creating the rule, and verifying it. It documents condition object types, action types, rule ordering classes, and ready-to-use examples for common scenarios.
When to use it
Use it when an administrator wants to create a ZPA access policy rule that allows, denies, or requires approval for private application access based on user identity, device posture, platform, location, or risk factors. It is also useful for scoping rules to application segments or segment groups.
Requirements
Requires access to ZPA administration tooling and the referenced lookup and rule-creation tools, such as SCIM group, SAML attribute, SCIM attribute, posture profile, trusted network, and segment group lookups plus rule creation and retrieval. No scripts are included; the skill is instructions only.

ZPA: Create Access Policy Rule

Keywords

access policy, access rule, allow rule, deny rule, zpa policy, scim group policy, saml policy, platform restriction, country restriction, posture check, require approval, zero trust policy, conditional access

Overview

Create ZPA access policy rules that control who can access private applications. Access policies use the v2 condition format and support a rich set of condition types: identity-based (SAML/SCIM), device-based (platform, posture, Chrome Enterprise), network-based (trusted networks, country codes), and risk-based (ZIA risk factors).

Use this skill when: An administrator asks to create an access policy rule, grant or deny application access based on user identity, device posture, location, or any combination of conditions.


Condition Object Type Reference

Each condition block must contain a single object type. Multiple condition blocks are ANDed together. Within a condition block, multiple operands or entry_values are ORed.

Value-Based Object Types (use values)

Object TypeDescriptionValues
APPApplication segmentsApplication segment IDs
APP_GROUPSegment groupsSegment group IDs
CLIENT_TYPEClient connector typezpn_client_type_zapp, zpn_client_type_exporter, zpn_client_type_machine_tunnel, zpn_client_type_browser_isolation, zpn_client_type_ip_anchoring, zpn_client_type_edge_connector, zpn_client_type_branch_connector, zpn_client_type_zapp_partner
MACHINE_GRPMachine groupsMachine group IDs
LOCATIONLocationsLocation IDs
EDGE_CONNECTOR_GROUPEdge connector groupsEdge connector group IDs
BRANCH_CONNECTOR_GROUPBranch connector groupsBranch connector group IDs

Entry-Values Object Types (use entry_values with lhs/rhs)

Object TypeLHSRHS
SAMLSAML attribute IDAttribute value to match (email, group name, etc.)
SCIMSCIM attribute header IDAttribute value to match
SCIM_GROUPIdentity Provider IDSCIM group ID
PLATFORMlinux, android, ios, mac, windows"true" or "false"
COUNTRY_CODEISO 3166 Alpha-2 code (US, CA, GB)"true" or "false"
POSTUREPosture profile posture_udid"true" or "false"
TRUSTED_NETWORKTrusted network network_id"true" or "false"
RISK_FACTOR_TYPEZIAUNKNOWN, LOW, MEDIUM, HIGH, CRITICAL
CHROME_ENTERPRISEmanaged"true" or "false"

Action Types

ActionDescription
ALLOWPermit access
DENYBlock access
REQUIRE_APPROVALRequire explicit approval before access

Workflow

Step 0: Identify the Rule Class (baseline alignment)

Reference: ZPA Baseline Recommendations v1.0 §Access Policy Construction (A–H). Before building conditions, identify which rule class this fits — that determines where the rule belongs in the policy order and which conditions are mandatory.

OrderClassActionMandatory criteriaNotes
1A. Deception (if licensed)ALLOWPredefined criteriaTenant feature — auto-provisioned. Do not modify the default rule.
2B. Machine Tunnel allowALLOWCLIENT_TYPE = zpn_client_type_machine_tunnel + APP (specific) + minimum POSTUREFor AD DCs, SCCM, patch services.
3B'. Machine Tunnel block-restDENYCLIENT_TYPE = zpn_client_type_machine_tunnelStops machine traffic from inheriting user rules.
4C. Contractor allowALLOWSCIM_GROUP (Contractors) + APP + CLIENT_TYPE + POSTURETightly scoped to approved apps only.
5C'. Contractor block-restDENYSCIM_GROUP (Contractors)Prevents contractor inheritance of employee rules.
6D. Posture remediation allowALLOWAPP (remediation segment) + CLIENT_TYPELets non-compliant devices reach the remediation app only.
7 + ND'. Posture block per-OSDENYPOSTURE (failed) + PLATFORM (Windows / macOS / iOS / Android / Linux)One rule per OS — see "Per-OS posture gotcha" below.
MidE. Critical app allowALLOWSCIM_GROUP + APP (crown-jewel) + CLIENT_TYPE (ZCC only) + POSTUREApply optional extra posture checks (cert, registry).
MidE'. Critical app block-restDENYAPP (crown-jewel) onlyDefense-in-depth even though E only allows approved users.
After EF. Standard internal appsALLOWSCIM_GROUP (employees) + APP + CLIENT_TYPEBaseline access for non-sensitive apps.
Near bottomG. Discovery wildcard catch-allALLOWAPP (wildcard discovery segment) + SCIM_GROUPDiscovery only — never above critical apps.
BottomH. Block-All explicitDENYNone — match allImproves logging and audit clarity beyond ZPA's implicit deny.
Per-OS posture gotcha

Defining a posture-block rule for only Windows leaves macOS, iOS, Android, and Linux implicitly allowed even when their device posture has failed. The doc is explicit about this on page 30: create one block rule per OS in use, each with its own POSTURE and PLATFORM criteria. This is the #1 posture-enforcement mistake.

When NOT to use this skill
  • Building a baseline policy from scratch (multiple classes at once) — defer to a future bulk-build skill, or chain calls to this skill once per class.
  • Auditing policy alignment — use the audit-baseline-compliance skill.

Step 1: Gather Requirements

Ask the administrator:

Required:

  • Rule name
  • Action: ALLOW, DENY, or REQUIRE_APPROVAL
  • What conditions determine access (identity, platform, location, etc.)

Optional:

  • Description
  • Which application segments or segment groups to scope to
  • App connector group IDs or server group IDs

Step 2: Look Up Identity Attributes

If the rule uses identity-based conditions (SAML, SCIM, SCIM_GROUP), look up the required IDs first.

For SCIM groups:

text
get_zpa_scim_group(search="<group_name>")```text
Note both the SCIM group ID (used as `rhs`) and the Identity Provider ID (used as `lhs`).
**For SAML attributes:**
```textget_zpa_saml_attribute(search="<attribute_name>")```text
Note the SAML attribute ID (used as `lhs`). The `rhs` is the value to match (e.g., an email address or group name string).
**For SCIM attributes:**
```textget_zpa_scim_attribute(search="<attribute_name>")```text
**For segment groups (APP_GROUP):**
```textzpa_list_segment_groups()```text
**For posture profiles:**
```textget_zpa_posture_profile(search="<profile_name>")```text
Note the `posture_udid` value (used as `lhs`).
**For trusted networks:**
```textget_zpa_trusted_network(search="<network_name>")```text
Note the `network_id` value (used as `lhs`).
---
### Step 3: Build the Conditions Payload
Conditions use a list of dictionaries. Each dictionary represents one condition block with an `operator` and `operands`. **Separate condition blocks for each object type.**
**Format:**
```json[  {    "operator": "OR",    "operands": [      {        "object_type": "<OBJECT_TYPE>",        "values": ["<id1>", "<id2>"]      }    ]  },  {    "operator": "OR",    "operands": [      {        "object_type": "<OBJECT_TYPE>",        "entry_values": [          {"lhs": "<lhs_value>", "rhs": "<rhs_value>"}        ]      }    ]  }]```text
**Rules:**
- Each condition block contains **one object type only**- Multiple condition blocks are **ANDed** together (all must match)- Within a block, multiple `entry_values` or multiple `values` are **ORed** (any can match)- Value-based types (`APP`, `APP_GROUP`, `CLIENT_TYPE`, etc.) use `values`- Entry-based types (`SAML`, `SCIM_GROUP`, `PLATFORM`, etc.) use `entry_values`
---
### Step 4: Create the Rule
```textzpa_create_access_policy_rule(  name="<rule_name>",  action_type="ALLOW",  description="<description>",  conditions=<conditions_payload>,  app_connector_group_ids=["<optional_connector_group_ids>"],  app_server_group_ids=["<optional_server_group_ids>"])```text
---
### Step 5: Verify
```textzpa_get_access_policy_rule(rule_id="<returned_rule_id>")```text
---
## Ready-to-Use Examples
### Example 1: Allow SCIM Groups to Access a Segment Group
Allow members of "Engineering" or "DevOps" SCIM groups to access an application segment group.
**Step 1: Look up IDs**
```textget_zpa_scim_group(search="Engineering")get_zpa_scim_group(search="DevOps")zpa_list_segment_groups()```text
**Step 2: Create rule**
```textzpa_create_access_policy_rule(  name="Allow Engineering and DevOps",  action_type="ALLOW",  description="Grants Engineering and DevOps teams access to internal apps",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<segment_group_id>"]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "SCIM_GROUP",          "entry_values": [            {"lhs": "<idp_id>", "rhs": "<engineering_scim_group_id>"},            {"lhs": "<idp_id>", "rhs": "<devops_scim_group_id>"}          ]        }      ]    }  ])```text
**Logic:** User must be in the segment group's apps AND be a member of Engineering OR DevOps.
---
### Example 2: Allow SAML Users with Platform Restriction
Allow specific SAML-identified users, but only from macOS and Windows devices.
**Step 1: Look up SAML attribute**
```textget_zpa_saml_attribute(search="Email_Users")```text
**Step 2: Create rule**
```textzpa_create_access_policy_rule(  name="Allow Specific Users on Mac/Windows",  action_type="ALLOW",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "SAML",          "entry_values": [            {"lhs": "<saml_email_attribute_id>", "rhs": "[email protected]"},            {"lhs": "<saml_email_attribute_id>", "rhs": "[email protected]"}          ]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "PLATFORM",          "entry_values": [            {"lhs": "mac", "rhs": "true"},            {"lhs": "windows", "rhs": "true"}          ]        }      ]    }  ])```text
**Logic:** User must match a SAML email AND be on macOS OR Windows.
---
### Example 3: Country-Based Access Restriction
Allow access only from the United States and Canada.
```textzpa_create_access_policy_rule(  name="US and Canada Only",  action_type="ALLOW",  description="Restrict access to US and Canadian locations",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<segment_group_id>"]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "COUNTRY_CODE",          "entry_values": [            {"lhs": "US", "rhs": "true"},            {"lhs": "CA", "rhs": "true"}          ]        }      ]    }  ])```text
---
### Example 4: Posture-Based Access with Risk Factor
Allow access only from devices that pass a posture check and have a ZIA risk score of LOW or below.
**Step 1: Look up posture profile**
```textget_zpa_posture_profile(search="CrowdStrike_ZTA")```text
**Step 2: Create rule**
```textzpa_create_access_policy_rule(  name="Posture and Risk Check",  action_type="ALLOW",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "POSTURE",          "entry_values": [            {"lhs": "<posture_udid>", "rhs": "true"}          ]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "RISK_FACTOR_TYPE",          "entry_values": [            {"lhs": "ZIA", "rhs": "UNKNOWN"},            {"lhs": "ZIA", "rhs": "LOW"}          ]        }      ]    }  ])```text
**Logic:** Device must pass posture check AND have a ZIA risk score of UNKNOWN or LOW.
---
### Example 5: Combined SCIM + SAML + Platform + Country
A comprehensive rule combining identity, device, and location conditions.
```textzpa_create_access_policy_rule(  name="Comprehensive Access Rule",  action_type="ALLOW",  description="Engineering team, Mac/Linux only, from US/CA",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<segment_group_id>"]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "SCIM_GROUP",          "entry_values": [            {"lhs": "<idp_id>", "rhs": "<engineering_group_id>"}          ]        },        {          "object_type": "SAML",          "entry_values": [            {"lhs": "<saml_email_attr_id>", "rhs": "[email protected]"}          ]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "PLATFORM",          "entry_values": [            {"lhs": "mac", "rhs": "true"},            {"lhs": "linux", "rhs": "true"}          ]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "COUNTRY_CODE",          "entry_values": [            {"lhs": "US", "rhs": "true"},            {"lhs": "CA", "rhs": "true"}          ]        }      ]    }  ])```text
**Logic:** Must access apps in the segment group AND (be in Engineering SCIM group OR be <[email protected]>) AND (be on macOS OR Linux) AND (be in US OR Canada).
---
### Example 6: Deny Rule
Block access from specific platforms.
```textzpa_create_access_policy_rule(  name="Deny Android and iOS",  action_type="DENY",  description="Block mobile device access to sensitive applications",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<sensitive_apps_segment_group_id>"]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "PLATFORM",          "entry_values": [            {"lhs": "android", "rhs": "true"},            {"lhs": "ios", "rhs": "true"}          ]        }      ]    }  ])```text
---
## Edge Cases
### No Conditions (Global Rule)
A rule with no conditions applies to all users and all applications:
```textzpa_create_access_policy_rule(  name="Default Allow All",  action_type="ALLOW",  conditions=[])```text
### Mixing SAML and SCIM in the Same Condition Block
SAML and SCIM_GROUP operands can share a condition block since they are identity types. They are ORed within the block:
```json{  "operator": "OR",  "operands": [    {      "object_type": "SAML",      "entry_values": [{"lhs": "<saml_attr_id>", "rhs": "[email protected]"}]    },    {      "object_type": "SCIM_GROUP",      "entry_values": [{"lhs": "<idp_id>", "rhs": "<scim_group_id>"}]    }  ]}```text
### Trusted Network Condition
```json{  "operator": "OR",  "operands": [    {      "object_type": "TRUSTED_NETWORK",      "entry_values": [{"lhs": "<network_id>", "rhs": "true"}]    }  ]}```text
---
## Quick Reference
**Tools used:**
- `get_zpa_scim_group(search)` -- look up SCIM group IDs- `get_zpa_saml_attribute(search)` -- look up SAML attribute IDs- `get_zpa_scim_attribute(search)` -- look up SCIM attribute IDs- `get_zpa_posture_profile(search)` -- look up posture profile UDIDs- `get_zpa_trusted_network(search)` -- look up trusted network IDs- `zpa_list_segment_groups()` -- look up segment group IDs- `zpa_create_access_policy_rule(name, action_type, conditions, ...)` -- create the rule- `zpa_get_access_policy_rule(rule_id)` -- verify the rule
**Condition logic:**
- Multiple condition blocks = AND (all must match)- Multiple entry_values within a block = OR (any can match)- Separate condition blocks per object type
**Actions:** `ALLOW`, `DENY`, `REQUIRE_APPROVAL`

Source and attribution

Source:zscaler/zscaler-mcp-serverinskills/zpa/create-access-policy-ruleat commit809f68d

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from zscaler/zscaler-mcp-server

Zpa Troubleshoot App Connector

zscaler

Troubleshoot ZPA App Connector issues including enrollment failures, upgrade problems, Public Service Edge connectivity, and high CPU/memory/disk utilization. Uses MCP tools to inspect connector groups, provisioning keys, server groups, and application segments, then provides runbook-guided remediation steps. Use when an administrator reports 'connector is down', 'connector not enrolling', 'connector upgrade failed', or 'connector high CPU.'

Awaiting classificationOct 8, 2026

Zpa Create Timeout Policy Rule

zscaler

Create ZPA timeout policy rules that control session re-authentication and idle timeout behavior. Configures how long a user session remains active (reauth_timeout) and how long an idle session persists (reauth_idle_timeout) before requiring re-authentication. Supports conditions: APP, APP_GROUP, CLIENT_TYPE, SAML, SCIM, SCIM_GROUP, PLATFORM, and POSTURE. Use when an administrator asks: 'Set session timeout', 'Configure idle timeout', 'Require re-authentication after X hours', or 'Set different timeouts per app or user group.'

Awaiting classificationOct 8, 2026

Zpa Create Session Duration Rule

zscaler

Create a ZPA Timeout Policy rule that enforces session duration — i.e. forces re-authentication after N minutes/hours/days, optionally with an idle-timeout. Use this skill when an admin asks for 'session duration', 'auto-revoke', 're-authentication interval', 'force re-auth after X hours', or 'session must expire after a workday' for ZPA. Scopes by SCIM group, SAML attribute, application segment, platform, and posture. ZPA Timeout Policy is a separate resource type from Access Policy; this skill creates timeout rules only and does not modify or pair with access rules.

Awaiting classificationOct 8, 2026

Zpa Create Server Group

zscaler

Create a ZPA server group with all required dependencies. Server groups require app connector groups to exist first. This skill walks through the dependency chain: (1) Check for existing app connector groups, (2) Create an app connector group if none exist, (3) Create the server group referencing the connector group IDs, (4) Verify the server group was created correctly. Use when an administrator needs to set up a new server group for application access.

Awaiting classificationOct 8, 2026

Zpa Create Forwarding Policy Rule

zscaler

Creates ZPA client forwarding policy rules that control how Zscaler Client Connector traffic is routed.

DevOps & CloudOct 8, 2026

Zpa Create Conditional Access Rule

zscaler

Builds a ZPA conditional access policy rule combining identity, posture, platform, country and risk checks.

SecurityOct 8, 2026