Manage the Zscaler Zero Trust Exchange platform via 300+ tools across ZPA (private access), ZIA (internet access), ZDX (digital experience), ZCC (client connector), ZTW (workload segmentation), ZMS (microsegmentation), EASM (attack surface management), Z-Insights (security analytics), and ZIdentity (identity management). Create and manage policies, troubleshoot connectivity, audit security configurations, and investigate incidents — all from your AI assistant.
6.9K
302 Tools
Version 4.43 or later needs to be installed to add the server automatically
Tools
| Name | Description |
|---|---|
zscaler_check_connectivity | Check connectivity to the Zscaler API. |
zscaler_get_available_services | Get information about available services. |
zcc_list_devices | Retrieves ZCC device enrollment information from the Zscaler Client Connector Portal (read-only) |
zcc_list_forwarding_profiles | Returns the list of Forwarding Profiles By Company ID in the Client Connector Portal (read-only) |
zcc_list_trusted_networks | Returns the list of Trusted Networks By Company ID in the Client Connector Portal (read-only) |
zdx_delete_analysis | Stop a running ZDX score analysis (destructive operation) |
zdx_delete_deeptrace | Delete a ZDX deep trace session (destructive operation) |
zdx_get_alert | Get a specific ZDX alert by ID (read-only) |
zdx_get_analysis | Get status of a ZDX score analysis (read-only) |
zdx_get_application | Get ZDX application details (read-only) |
zdx_get_application_metric | Get ZDX metrics for a specified application (read-only) |
zdx_get_application_score_trend | Get ZDX application score trend (read-only) |
zdx_get_application_user | Get a specific ZDX application user (read-only) |
zdx_get_deeptrace_cloudpath | Get cloud path topology from a ZDX deep trace session (read-only) |
zdx_get_deeptrace_cloudpath_metrics | Get cloud path metrics from a ZDX deep trace session (read-only) |
zdx_get_deeptrace_events | Get events from a ZDX deep trace session (read-only) |
zdx_get_deeptrace_health_metrics | Get health metrics from a ZDX deep trace session (read-only) |
zdx_get_deeptrace_webprobe_metrics | Get web probe metrics from a ZDX deep trace session (read-only) |
zdx_get_device | Get a specific ZDX device by ID (read-only) |
zdx_get_device_deep_trace | Get a specific ZDX deep trace by ID (read-only) |
zdx_get_software_details | Get details for specific ZDX software (read-only) |
zdx_get_web_probes | Get web probes for an app on a device - returns web_probe_id needed for zdx_start_deeptrace (read-only) |
zdx_list_alert_affected_devices | List devices affected by a ZDX alert (read-only) |
zdx_list_alerts | List ZDX alerts (read-only) |
zdx_list_application_users | List users for a ZDX application (read-only) |
zdx_list_applications | List ZDX applications (read-only) |
zdx_list_cloudpath_probes | List cloud path probes for an app on a device - returns cloudpath_probe_id needed for zdx_start_deeptrace (read-only) |
zdx_list_deeptrace_top_processes | Get top processes from a ZDX deep trace session (read-only) |
zdx_list_departments | List ZDX departments (read-only) |
zdx_list_device_deep_traces | List ZDX deep traces for a device (read-only) |
zdx_list_devices | List ZDX devices with optional filtering (read-only) |
zdx_list_historical_alerts | List ZDX historical alerts (read-only) |
zdx_list_locations | List ZDX locations (read-only) |
zdx_list_software | List ZDX software inventory (read-only) |
zdx_start_analysis | Start a ZDX score analysis on a device (write operation) |
zdx_start_deeptrace | Start a deep trace for a ZDX device (write operation) |
get_zpa_app_protection_profile | Manage ZPA App Protection Profiles (Inspection Profiles) (read-only) |
get_zpa_app_segments_by_type | Manage ZPA application segments by type (read-only) |
get_zpa_enrollment_certificate | Manage ZPA Enrollment Certificates (read-only) |
get_zpa_isolation_profile | Manage ZPA Cloud Browser Isolation (CBI) profiles (read-only) |
get_zpa_posture_profile | Manage ZPA Posture Profiles (read-only) |
get_zpa_saml_attribute | Manage ZPA SAML Attributes (read-only) |
get_zpa_scim_attribute | Manage ZPA SCIM Attributes (read-only) |
get_zpa_scim_group | Manage ZPA SCIM Groups (read-only) |
get_zpa_trusted_network | Manage ZPA Trusted Networks (read-only) |
zpa_bulk_delete_app_connectors | Bulk delete multiple ZPA app connectors (destructive operation) |
zpa_create_access_policy_rule | Create a new ZPA access policy rule (write operation) |
zpa_create_app_connector_group | Create a new ZPA app connector group (write operation) |
zpa_create_app_protection_rule | Create a new ZPA app protection rule (write operation) |
zpa_create_application_segment | Create a new ZPA application segment (write operation) |
zpa_create_application_server | Create a new ZPA application server (write operation) |
zpa_create_ba_certificate | Create a new ZPA browser access certificate (write operation) |
zpa_create_forwarding_policy_rule | Create a new ZPA forwarding policy rule (write operation) |
zpa_create_isolation_policy_rule | Create a new ZPA isolation policy rule (write operation) |
zpa_create_pra_credential | Create a new ZPA PRA credential (write operation) |
zpa_create_pra_portal | Create a new ZPA PRA portal (write operation) |
zpa_create_provisioning_key | Create a new ZPA provisioning key (write operation) |
zpa_create_segment_group | Create a new ZPA segment group (write operation) |
zpa_create_server_group | Create a new ZPA server group (write operation) |
zpa_create_service_edge_group | Create a new ZPA service edge group (write operation) |
zpa_create_timeout_policy_rule | Create a new ZPA timeout policy rule (write operation) |
zpa_delete_access_policy_rule | Delete a ZPA access policy rule (destructive operation) |
zpa_delete_app_connector | Delete a ZPA app connector (destructive operation) |
zpa_delete_app_connector_group | Delete a ZPA app connector group (destructive operation) |
zpa_delete_app_protection_rule | Delete a ZPA app protection rule (destructive operation) |
zpa_delete_application_segment | Delete a ZPA application segment (destructive operation) |
zpa_delete_application_server | Delete a ZPA application server (destructive operation) |
zpa_delete_ba_certificate | Delete a ZPA browser access certificate (destructive operation) |
zpa_delete_forwarding_policy_rule | Delete a ZPA forwarding policy rule (destructive operation) |
zpa_delete_isolation_policy_rule | Delete a ZPA isolation policy rule (destructive operation) |
zpa_delete_pra_credential | Delete a ZPA PRA credential (destructive operation) |
zpa_delete_pra_portal | Delete a ZPA PRA portal (destructive operation) |
zpa_delete_provisioning_key | Delete a ZPA provisioning key (destructive operation) |
zpa_delete_segment_group | Delete a ZPA segment group (destructive operation) |
zpa_delete_server_group | Delete a ZPA server group (destructive operation) |
zpa_delete_service_edge_group | Delete a ZPA service edge group (destructive operation) |
zpa_delete_timeout_policy_rule | Delete a ZPA timeout policy rule (destructive operation) |
zpa_get_access_policy_rule | Get a specific ZPA access policy rule by ID (read-only) |
zpa_get_app_connector | Get a specific ZPA app connector by ID with runtime status and control connection state (read-only) |
zpa_get_app_connector_group | Get a specific ZPA app connector group by ID (read-only) |
zpa_get_app_protection_rule | Get a specific ZPA app protection rule by ID (read-only) |
zpa_get_application_segment | Get a specific ZPA application segment by ID (read-only) |
zpa_get_application_server | Get a specific ZPA application server by ID (read-only) |
zpa_get_ba_certificate | Get a specific ZPA browser access certificate by ID (read-only) |
zpa_get_forwarding_policy_rule | Get a specific ZPA forwarding policy rule by ID (read-only) |
zpa_get_isolation_policy_rule | Get a specific ZPA isolation policy rule by ID (read-only) |
zpa_get_pra_credential | Get a specific ZPA PRA credential by ID (read-only) |
zpa_get_pra_portal | Get a specific ZPA PRA portal by ID (read-only) |
zpa_get_provisioning_key | Get a specific ZPA provisioning key by ID (read-only) |
zpa_get_segment_group | Get a specific ZPA segment group by ID (read-only) |
zpa_get_server_group | Get a specific ZPA server group by ID (read-only) |
zpa_get_service_edge_group | Get a specific ZPA service edge group by ID (read-only) |
zpa_get_timeout_policy_rule | Get a specific ZPA timeout policy rule by ID (read-only) |
zpa_list_access_policy_rules | List ZPA access policy rules (read-only) |
zpa_list_app_connector_groups | List ZPA app connector groups (read-only) |
zpa_list_app_connectors | List ZPA app connectors with status, version, and health information (read-only) |
zpa_list_app_protection_rules | List ZPA app protection rules (read-only) |
zpa_list_application_segments | List ZPA application segments with optional filtering (read-only) |
zpa_list_application_servers | List ZPA application servers (read-only) |
zpa_list_ba_certificates | List ZPA browser access certificates (read-only) |
zpa_list_forwarding_policy_rules | List ZPA forwarding policy rules (read-only) |
zpa_list_isolation_policy_rules | List ZPA isolation policy rules (read-only) |
zpa_list_pra_credentials | List ZPA PRA credentials (read-only) |
zpa_list_pra_portals | List ZPA PRA portals (read-only) |
zpa_list_provisioning_keys | List ZPA provisioning keys (read-only) |
zpa_list_segment_groups | List ZPA segment groups (read-only) |
zpa_list_server_groups | List ZPA server groups (read-only) |
zpa_list_service_edge_groups | List ZPA service edge groups (read-only) |
zpa_list_timeout_policy_rules | List ZPA timeout policy rules (read-only) |
zpa_update_access_policy_rule | Update an existing ZPA access policy rule (write operation) |
zpa_update_app_connector | Update a ZPA app connector (enable/disable, rename) (write operation) |
zpa_update_app_connector_group | Update an existing ZPA app connector group (write operation) |
zpa_update_app_protection_rule | Update an existing ZPA app protection rule (write operation) |
zpa_update_application_segment | Update an existing ZPA application segment (write operation) |
zpa_update_application_server | Update an existing ZPA application server (write operation) |
zpa_update_forwarding_policy_rule | Update an existing ZPA forwarding policy rule (write operation) |
zpa_update_isolation_policy_rule | Update an existing ZPA isolation policy rule (write operation) |
zpa_update_pra_credential | Update an existing ZPA PRA credential (write operation) |
zpa_update_pra_portal | Update an existing ZPA PRA portal (write operation) |
zpa_update_provisioning_key | Update an existing ZPA provisioning key (write operation) |
zpa_update_segment_group | Update an existing ZPA segment group (write operation) |
zpa_update_server_group | Update an existing ZPA server group (write operation) |
zpa_update_service_edge_group | Update an existing ZPA service edge group (write operation) |
zpa_update_timeout_policy_rule | Update an existing ZPA timeout policy rule (write operation) |
get_zia_dlp_dictionaries | Manage ZIA DLP dictionaries for data loss prevention pattern and phrase matching (read-only) |
get_zia_dlp_engines | Manage ZIA DLP engines for data loss prevention rule processing (read-only) |
get_zia_user_departments | Manage ZIA user departments for organizational structure (read-only) |
get_zia_user_groups | Manage ZIA user groups for access control and policy assignment (read-only) |
get_zia_users | Manage ZIA users for authentication and access control (read-only) |
zia_activate_configuration | Activate ZIA configuration changes (write operation) |
zia_add_atp_malicious_urls | Add URLs to ZIA ATP malicious URL list (write operation) |
zia_add_auth_exempt_urls | Add URLs to ZIA authentication exempt list (write operation) |
zia_add_urls_to_category | Add URLs to a ZIA URL category (write operation) |
zia_bulk_update_cloud_applications | Bulk update ZIA cloud applications (write operation) |
zia_create_cloud_firewall_rule | Create a new ZIA cloud firewall rule (write operation) |
zia_create_gre_tunnel | Create a new ZIA GRE tunnel (write operation) |
zia_create_ip_destination_group | Create a new ZIA IP destination group (write operation) |
zia_create_ip_source_group | Create a new ZIA IP source group (write operation) |
zia_create_location | Create a new ZIA location (write operation) |
zia_create_network_app_group | Create a new ZIA network application group (write operation) |
zia_create_network_service | Create a new ZIA network service with custom TCP/UDP ports (write operation) |
zia_create_network_svc_group | Create a new ZIA network service group (write operation) |
zia_create_rule_label | Create a new ZIA rule label (write operation) |
zia_create_ssl_inspection_rule | Create a new ZIA SSL inspection rule (write operation) |
zia_create_static_ip | Create a new ZIA static IP (write operation) |
zia_create_url_category | Create a new ZIA URL category (write operation) |
zia_create_url_filtering_rule | Create a new ZIA URL filtering rule (write operation) |
zia_create_vpn_credential | Create a new ZIA VPN credential (write operation) |
zia_create_web_dlp_rule | Create a new ZIA web DLP rule (write operation) |
zia_delete_atp_malicious_urls | Delete URLs from ZIA ATP malicious URL list (destructive operation) |
zia_delete_auth_exempt_urls | Delete URLs from ZIA authentication exempt list (destructive operation) |
zia_delete_cloud_firewall_rule | Delete a ZIA cloud firewall rule (destructive operation) |
zia_delete_gre_tunnel | Delete a ZIA GRE tunnel (destructive operation) |
zia_delete_ip_destination_group | Delete a ZIA IP destination group (destructive operation) |
zia_delete_ip_source_group | Delete a ZIA IP source group (destructive operation) |
zia_delete_location | Delete a ZIA location (destructive operation) |
zia_delete_network_app_group | Delete a ZIA network application group (destructive operation) |
zia_delete_network_service | Delete a ZIA network service (destructive operation) |
zia_delete_network_svc_group | Delete a ZIA network service group (destructive operation) |
zia_delete_rule_label | Delete a ZIA rule label (destructive operation) |
zia_delete_ssl_inspection_rule | Delete a ZIA SSL inspection rule (destructive operation) |
zia_delete_static_ip | Delete a ZIA static IP (destructive operation) |
zia_delete_url_category | Delete a ZIA URL category (destructive operation) |
zia_delete_url_filtering_rule | Delete a ZIA URL filtering rule (destructive operation) |
zia_delete_vpn_credential | Delete a ZIA VPN credential (destructive operation) |
zia_delete_web_dlp_rule | Delete a ZIA web DLP rule (destructive operation) |
zia_geo_search | Perform ZIA geographic lookups (coordinates, IP, or city prefix) (read-only) |
zia_get_activation_status | Get ZIA configuration activation status (read-only) |
zia_get_cloud_firewall_rule | Get a specific ZIA cloud firewall rule by ID (read-only) |
zia_get_gre_tunnel | Get a specific ZIA GRE tunnel by ID (read-only) |
zia_get_ip_destination_group | Get a specific ZIA IP destination group by ID (read-only) |
zia_get_ip_source_group | Get a specific ZIA IP source group by ID (read-only) |
zia_get_location | Get a specific ZIA location by ID (read-only) |
zia_get_network_app | Get a specific ZIA network application by ID (read-only) |
zia_get_network_app_group | Get a specific ZIA network application group by ID (read-only) |
zia_get_network_service | Get a specific ZIA network service by ID (read-only) |
zia_get_network_svc_group | Get a specific ZIA network service group by ID (read-only) |
zia_get_rule_label | Get a specific ZIA rule label by ID (read-only) |
zia_get_sandbox_behavioral_analysis | Retrieve sandbox behavioral analysis hash list (read-only) |
zia_get_sandbox_file_hash_count | Retrieve sandbox file hash usage counts (read-only) |
zia_get_sandbox_quota | Retrieve current ZIA sandbox quota information (read-only) |
zia_get_sandbox_report | Retrieve sandbox analysis report for a specific MD5 hash (read-only) |
zia_get_ssl_inspection_rule | Get a specific ZIA SSL inspection rule by ID (read-only) |
zia_get_static_ip | Get a specific ZIA static IP by ID (read-only) |
zia_get_url_category | Get a specific ZIA URL category by ID (read-only) |
zia_get_url_filtering_rule | Get a specific ZIA URL filtering rule by ID (read-only) |
zia_get_vpn_credential | Get a specific ZIA VPN credential by ID (read-only) |
zia_get_web_dlp_rule | Get a specific ZIA web DLP rule by ID (read-only) |
zia_list_atp_malicious_urls | List ZIA ATP malicious URLs (read-only) |
zia_list_auth_exempt_urls | List ZIA authentication exempt URLs (read-only) |
zia_list_cloud_app_control_actions | List granular actions supported for a Cloud App Control rule type (read-only) |
zia_list_cloud_application_custom_tags | List ZIA cloud application custom tags (read-only) |
zia_list_cloud_applications | List ZIA cloud applications (read-only) |
zia_list_cloud_firewall_rules | List ZIA cloud firewall rules with optional filtering (read-only) |
zia_list_device_groups | List ZIA device groups with optional device info and pseudo group filtering (read-only) |
zia_list_devices | List ZIA devices with filtering by name, user, pagination support (read-only) |
zia_list_devices_lite | List ZIA devices in lightweight format (ID, name, owner only) (read-only) |
zia_list_gre_ranges | List available ZIA GRE IP ranges (read-only) |
zia_list_gre_tunnels | List ZIA GRE tunnels (read-only) |
zia_list_ip_destination_groups | List ZIA IP destination groups (read-only) |
zia_list_ip_source_groups | List ZIA IP source groups (read-only) |
zia_list_locations | List ZIA locations (read-only) |
zia_list_network_app_groups | List ZIA network application groups (read-only) |
zia_list_network_apps | List ZIA network applications with optional filtering by search or locale (read-only) |
zia_list_network_services | List ZIA network services with optional filtering by protocol or search (read-only) |
zia_list_network_svc_groups | List ZIA network service groups with optional filtering (read-only) |
zia_list_rule_labels | List ZIA rule labels (read-only) |
zia_list_ssl_inspection_rules | List ZIA SSL inspection rules (read-only) |
zia_list_static_ips | List ZIA static IPs (read-only) |
zia_list_url_categories | List ZIA URL categories (read-only) |
zia_list_url_filtering_rules | List ZIA URL filtering rules (read-only) |
zia_list_vpn_credentials | List ZIA VPN credentials (read-only) |
zia_list_web_dlp_rules | List ZIA web DLP rules (read-only) |
zia_list_web_dlp_rules_lite | List ZIA web DLP rules in lite format (read-only) |
zia_remove_urls_from_category | Remove URLs from a ZIA URL category (write operation) |
zia_update_cloud_firewall_rule | Update an existing ZIA cloud firewall rule (write operation) |
zia_update_ip_destination_group | Update an existing ZIA IP destination group (write operation) |
zia_update_ip_source_group | Update an existing ZIA IP source group (write operation) |
zia_update_location | Update an existing ZIA location (write operation) |
zia_update_network_app_group | Update an existing ZIA network application group (write operation) |
zia_update_network_service | Update an existing ZIA network service (write operation) |
zia_update_network_svc_group | Update an existing ZIA network service group (write operation) |
zia_update_rule_label | Update an existing ZIA rule label (write operation) |
zia_update_ssl_inspection_rule | Update an existing ZIA SSL inspection rule (write operation) |
zia_update_static_ip | Update an existing ZIA static IP (write operation) |
zia_update_url_category | Update an existing ZIA URL category (write operation) |
zia_update_url_filtering_rule | Update an existing ZIA URL filtering rule (write operation) |
zia_update_vpn_credential | Update an existing ZIA VPN credential (write operation) |
zia_update_web_dlp_rule | Update an existing ZIA web DLP rule (write operation) |
zia_url_lookup | Look up URL category for given URLs (read-only) |
ztw_create_ip_destination_group | Create a new ZTW IP destination group (write operation) |
ztw_create_ip_group | Create a new ZTW IP group (write operation) |
ztw_create_ip_source_group | Create a new ZTW IP source group (write operation) |
ztw_delete_ip_destination_group | Delete a ZTW IP destination group (destructive operation) |
ztw_delete_ip_group | Delete a ZTW IP group (destructive operation) |
ztw_delete_ip_source_group | Delete a ZTW IP source group (destructive operation) |
ztw_get_discovery_settings | Get ZTW workload discovery service settings (read-only) |
ztw_list_admins | List all existing admin users in ZTW (read-only) |
ztw_list_ip_destination_groups | List ZTW IP destination groups (read-only) |
ztw_list_ip_destination_groups_lite | List ZTW IP destination groups in lite format (read-only) |
ztw_list_ip_groups | List ZTW IP groups (read-only) |
ztw_list_ip_groups_lite | List ZTW IP groups in lite format (read-only) |
ztw_list_ip_source_groups | List ZTW IP source groups (read-only) |
ztw_list_ip_source_groups_lite | List ZTW IP source groups in lite format (read-only) |
ztw_list_network_service_groups | List ZTW network service groups (read-only) |
ztw_list_network_services | List ZTW network services (read-only) |
ztw_list_public_account_details | List detailed ZTW public cloud account information (read-only) |
ztw_list_public_cloud_info | List ZTW public cloud accounts with metadata (read-only) |
ztw_list_roles | List all existing admin roles in ZTW (read-only) |
zid_get_group | Get a specific ZIdentity group by ID (read-only) |
zid_get_group_users | Get users in a ZIdentity group (read-only) |
zid_get_group_users_by_name | Get users in a ZIdentity group by group name (read-only) |
zid_get_user | Get a specific ZIdentity user by ID (read-only) |
zid_get_user_groups | Get groups for a ZIdentity user (read-only) |
zid_get_user_groups_by_name | Get groups for a ZIdentity user by username (read-only) |
zid_list_groups | List ZIdentity groups (read-only) |
zid_list_users | List ZIdentity users (read-only) |
zid_search_groups | Search ZIdentity groups (read-only) |
zid_search_users | Search ZIdentity users (read-only) |
zeasm_get_finding_details | Get details for a specific EASM finding (read-only) |
zeasm_get_finding_evidence | Get scan evidence for a specific EASM finding (read-only) |
zeasm_get_finding_scan_output | Get complete scan output for a specific EASM finding (read-only) |
zeasm_get_lookalike_domain | Get details for a specific lookalike domain (read-only) |
zeasm_list_findings | List all EASM findings for an organization (read-only) |
zeasm_list_lookalike_domains | List all lookalike domains detected for an organization (read-only) |
zeasm_list_organizations | List all EASM organizations configured for the tenant (read-only) |
zins_get_casb_app_report | Provides CASB SaaS application usage analytics, including cloud app usage and cloud service adoption metrics. |
zins_get_cyber_incidents | Provides cybersecurity incidents grouped by category, including security events, cyber attacks, and incident breakdowns. |
zins_get_cyber_incidents_by_location | Provides cybersecurity incidents grouped by location, showing incident distribution across offices and sites. |
zins_get_cyber_incidents_by_threat_and_app | Provides cybersecurity incidents correlated by threat type and application, showing which apps are targeted and threat-application relationships. |
zins_get_cyber_incidents_daily | Provides daily cybersecurity incident trends, showing incident patterns and security statistics over time. |
zins_get_firewall_by_action | Provides Zero Trust Firewall traffic analytics by action (allow/block), including blocked traffic volume and firewall policy effectiveness. |
zins_get_firewall_by_location | Provides Zero Trust Firewall traffic analytics grouped by location, including firewall activity by office and branch. |
zins_get_firewall_network_services | Provides firewall network service usage analytics, including port usage, protocol activity, and service breakdowns. |
zins_get_iot_device_stats | Provides IoT device statistics and classifications, including device inventory, connected device types, and unmanaged devices. |
zins_get_shadow_it_apps | Provides discovered shadow IT applications with risk scores, including unsanctioned and unauthorized application detection. |
zins_get_shadow_it_summary | Provides shadow IT summary statistics, including total shadow apps, app categories, and risk distribution overview. |
zins_get_threat_class | Provides detailed threat classification analytics including virus, trojan, ransomware, and other malware type breakdowns. |
zins_get_threat_super_categories | Provides threat super-category analytics including malware, phishing, spyware, and other threat types detected across the tenant. |
zins_get_web_protocols | Provides web protocol distribution analytics (HTTP, HTTPS, SSL), including protocol usage and HTTPS adoption metrics. |
zins_get_web_traffic_by_location | Provides web traffic analytics grouped by location, including traffic volume, bandwidth usage, and office traffic comparisons. |
zins_get_web_traffic_no_grouping | Provides total web traffic volume metrics without grouping, including aggregate bandwidth and overall web usage statistics. |
zms_get_agent_connection_status_statistics | Get aggregated connection status statistics for ZMS agents. Returns connected/disconnected counts and percentages. |
zms_get_agent_group_totp_secrets | Get TOTP secrets for a specific ZMS agent group. Returns TOTP secret, QR code, and generation timestamp for agent enrollment. |
zms_get_agent_version_statistics | Get aggregated version statistics for ZMS agents. Returns software version distribution across the agent fleet. |
zms_get_metadata | Get event metadata for ZMS resources. Returns metadata about available resource events. |
zms_get_nonce | Get a specific ZMS nonce (provisioning key) by eyez ID. Returns detailed key information including usage counts. |
zms_get_resource_group_members | Get members of a specific ZMS resource group. Returns workloads in the group with resource type, status, cloud info, and OS. |
zms_get_resource_group_protection_status | Get protection status summary for ZMS resource groups. Returns protected/unprotected group counts and coverage percentage. |
zms_get_resource_protection_status | Get protection status summary for ZMS resources. Returns protected/unprotected counts and protection coverage percentage. |
zms_list_agent_groups | List ZMS agent groups with pagination and search. Returns group name, type, agent count, policy status, and upgrade settings. |
zms_list_agents | List Zscaler Microsegmentation agents with pagination and search. Returns agent name, connection status, OS, version, IPs, and group membership. |
zms_list_app_catalog | List ZMS application catalog entries with pagination. Returns discovered apps with name, category, port/protocol specs, and processes. |
zms_list_app_zones | List ZMS app zones with pagination. Returns zone name, description, member count, and VPC/subnet settings. |
zms_list_default_policy_rules | List default microsegmentation policy rules. Returns system-defined baseline rules with action, direction, and scope type. |
zms_list_nonces | List ZMS nonces (provisioning keys) with pagination and search. Returns key name, value, max usage, current usage, and agent group association. |
zms_list_policy_rules | List ZMS microsegmentation policy rules with pagination. Returns rule name, action, priority, source/destination targets, and port/protocol specs. |
zms_list_resource_groups | List ZMS resource groups with pagination. Returns managed and unmanaged groups with member counts, CIDRs, and FQDNs. |
zms_list_resources | List ZMS resources (workloads) with pagination. Returns resource type, status, cloud provider, region, hostname, OS, IPs, and app zones. |
zms_list_tag_keys | List tag keys within a ZMS tag namespace. Returns tag key name and description. |
zms_list_tag_namespaces | List ZMS tag namespaces with pagination. Returns namespace name, description, and origin (CUSTOM, EXTERNAL, ML). |
zms_list_tag_values | List tag values for a specific ZMS tag key. Returns available values for filtering resources. |