ZMS: Analyze Policy Rules & Segmentation Optimization
Keywords
policy rules, segmentation policies, microsegmentation rules, default policy, deny all, allow all, stale rules, unused rules, overly permissive, rule optimization, cross-zone, app zones, lateral movement, zero trust policy, rule priority, policy coverage
Overview
Perform a focused analysis of Zscaler Microsegmentation policy rules to identify optimization opportunities. This skill examines custom segmentation rules for staleness, breadth, and coverage gaps; evaluates default policy posture (deny vs allow); maps cross-zone communication patterns through app zones; and correlates policy rules with resource group structure to identify unprotected segments.
Policy rules are the enforcement backbone of microsegmentation. They define which resource groups can communicate with each other, over which ports and protocols, and in which direction. Poorly maintained rules lead to either excessive lateral movement risk (too permissive) or application breakage (too restrictive).
Rule evaluation order matters: Rules are evaluated by priority — higher priority rules are matched first. A misconfigured priority can cause a restrictive rule to shadow an intended allow rule, or vice versa.
Use this skill when: A security architect needs to audit policy rule hygiene, identify stale rules, tighten overly permissive rules, review default posture, or prepare for a compliance audit that requires demonstrating least-privilege segmentation.
Important:
- All ZMS tools require
ZSCALER_CUSTOMER_IDto be set as an environment variable. - All current MCP tools are read-only (Query operations).
- The ZMS API supports full CRUD for policy rules via mutations (
policyRuleCreate,policyRuleUpdate,policyRuleDelete,defaultPolicyRulesCreate/Update/Delete) but these are not yet exposed through MCP tools.
Workflow
Follow this 5-step process for a comprehensive policy rule analysis.
Step 1: Inventory All Policy Rules
Fetch all custom policy rules:


