Zscaler rollout for 65,000 users
Zero trust access for a multinational workforce of 65,000, built on Zscaler with ZPA for private application access and ZDX for experience monitoring.
What we walked into.
Sixty five thousand people, thousands of internal applications and an access model that still assumed everyone sat behind a corporate perimeter.
The hard part of zero trust is never the technology. It is knowing which application belongs to whom, and proving that the new path is faster than the old one before you switch anyone over.
Zero trust is an application discovery project wearing a security badge.
The approach.
- Step 1
Application discovery first, then segmentation. ZPA connectors placed close to the workloads, access policies written per application group rather than per network range.
- Step 2
ZDX rolled out ahead of the migration so every user journey had a baseline. When someone said the new setup felt slower, we had the numbers instead of an argument.
- Step 3
Wave-based migration by business unit, with a rollback path at every wave and a support model briefed before each go-live.

Stack and disciplines.
What it delivered.
Private applications reachable without a traditional VPN, with access decided per identity and per application.
Digital experience visible end to end, from device to application, so the service desk stops guessing where a problem sits.
More about Enterprise InfrastructureLessons that travel.
Baselines end arguments. With ZDX data in hand, every performance complaint became a measurement instead of a debate.
Access policy written per application group stays readable. Policy written per network range never does.
Support teams briefed before a wave save more time than any automation in it.
Got something like this?
Tell us what you are building. We will be direct about whether Redwind is the right team for it.
Start a project