ZPA: Troubleshoot App Connector
Keywords
app connector, connector down, connector not enrolling, enrollment failure, connector upgrade, connector high cpu, connector memory, connector troubleshoot, connector status, connector group, provisioning key, broker connection, public service edge, connector health
Overview
Troubleshoot ZPA App Connector issues by combining MCP API inspection (connector groups, provisioning keys, server groups) with operational runbook knowledge. This skill covers the four major App Connector failure categories: enrollment failures, upgrade issues, Public Service Edge connectivity, and resource utilization.
Use this skill when: An administrator reports App Connector problems -- connector not appearing, enrollment failures, upgrade failures, high resource usage, or application unreachability traced to a connector issue.
Workflow
Step 1: Gather Issue Details
Collect from the administrator:
Required:
- Connector name or the App Connector Group it belongs to
- Symptom: not enrolling, showing disconnected, upgrade failed, high CPU/memory, applications unreachable
Helpful:
- When did the issue start?
- Was anything changed recently (provisioning key, network, firewall)?
- Is it one connector or multiple connectors in the group?
- Cloud name (e.g., prod.zpath.net, zpatwo.net)
Step 1.5: Config-Only Pre-Flight Checks (baseline alignment)
Before concluding a connector is broken, verify the deployment matches ZPA Baseline Recommendations v1.0 §App Connector Recommendations. These are configuration checks only — ZPA does not expose live connector telemetry (CPU, memory, throughput, bandwidth utilization), so we cannot prove a connector is currently overloaded; we can only verify the deployment shape.
Important — what we cannot check via API: per-connector CPU/memory/throughput, app probe results, bandwidth utilization, session counts. If the symptom is "connector is slow" and the config checks above pass, the next step is operational telemetry from outside ZPA (hypervisor / cloud-provider metrics, syslog from the connector VM). Flag this gap to the user so they don't expect the API to return runtime metrics.
Step 2: Inspect Connector and Connector Group Status via API
List individual app connectors to get their runtime status directly:


