ZPA: Create Server Group
Keywords
create server group, new server group, zpa server group, add server group, connector group dependency, server group setup, zpa infrastructure
Overview
Create a ZPA server group by first ensuring its required dependency -- an app connector group -- exists. Server groups are fundamental building blocks in ZPA that define which application connectors serve traffic for specific applications.
Use this skill when: An administrator asks to create a new server group, set up ZPA infrastructure, or needs help understanding server group dependencies.
Workflow
Follow this 5-step process to create a server group with its dependencies.
Step 1: Gather Requirements
Ask the administrator for the following information:
Required:
- Server group name
- Whether to use an existing app connector group or create a new one
Optional:
- Server group description
- Whether IP anchoring is needed (
ip_anchored) - Whether dynamic discovery should be enabled (
dynamic_discovery) - Specific application server IDs to associate (
server_ids) - Microtenant ID (for multi-tenant environments)
Step 1.5: Pick the Server Group Pattern (baseline alignment)
Reference: ZPA Baseline Recommendations v1.0 §Server Group Definition. Pick one of the five patterns before you choose app_connector_group_ids:
Once you've picked the pattern, the AC group selection in Step 2 / 3 is determined.
Dynamic Discovery — when to disable it
The baseline doc recommends dynamic_discovery=True for almost all server groups. Disable it only when:
- Strict per-server segmentation is required (specific server IDs must be served by specific connectors).
- You need destination NAT for overlapping networks across multi-DC / multi-cloud or partner environments served by ZPA Extranet.
Important — dynamic discovery ≠ application health checks. Dynamic discovery only learns server reachability from connector lookups. Application health (TCP probes, HTTP checks, port polling) is configured separately on the application segment via the health_reporting field. See the application_segment-onboard skill for health_reporting defaults.
Step 2: Check for Existing App Connector Groups
Before creating anything, list existing app connector groups to avoid duplicates.


