Network & Internet · For Staff, Faculty, Researchers, IT Administrators
Coming soon . Planned but not yet available.
Secure, identity-based access to protected departmental applications and services.
In 2025, UCSB began the implementation of a new Secure Service Access (SSA) solution using the Zscaler client connector. This replaces Ivanti VPN or other existing remote access tools. The SSA / Zscaler client connector is installed on devices, and prompts users to authenticate identity using their UCSB credentials before granting access to private resources.
Benefits:
- Providing a simple, convenient, and consistent experience to users. Our faculty, staff, and students will have access to the systems, data, and services they need to pursue their academic or research objectives—whether on different campus location or around the world.
- Users can choose to have the SSA / Zscaler client connector running in the background in order to seamlessly connect to protected UCSB applications instead of manually launching Ivanti VPN or other remote access tools every time they need access.
- The connector has the ability to continuously check the security posture of both users and devices attempting to connect to sensitive resources. This ensures sensitive data is not exposed to an unauthorized user, or a compromised device.
- Unlike VPN, which connects users to an entire network, SSA / Zscaler client connector only connects a user to the specific UCSB resource they need, eliminating the unnecessary exposure of other sensitive user information. This shrinks the attack surface and limits lateral movement between university business systems, visitors, and BYOD while enhancing user privacy.
- Only traffic associated with identified UCSB resources transits the connector. All other traffic remains private.
Functionality:
- Once the client connector is installed, users will be prompted with an authentication window.
- They must authenticate into the client connector with their UCSB SSO, or the window will persist.
- The client connector’s optimal functionality is to be both authenticated to, and turned on. This ensures proper network connectivity and security.
SSA / ZScaler deployment documentation:
- Client Connector General Use
- Client Installation and Initial Setup
- UCSB Networks & Firewall Requirements
- UCSB Device Posture Requirements for Resource Access
Note: SSO authentication required to access documentation
Frequently Asked Questions
Initially, ScreenConnect and VPN will be replaced, but in the future, SSA could provide additional capabilities to improve remote access to UCSB resources.
There will be a gradual replacement of some commonly used tools for remote access to UCSB systems or applications. Access to sensitive applications may be restricted to only specific users/groups, and may be subject to a device security posture check.
Security postures are a real-time check of a device’s security health. This information is used to decide whether the device can be trusted to access sensitive resources. For example:
- Is the device running a supported, up-to-date operating system?
- Does the device have an anti-virus solution enabled?
- Is full-disk encryption enabled on the device?
- Is a local firewall enabled on the device?
Private UCSB-hosted applications containing P3 / P4 data will require the user to have a device security posture check before access is granted. All applications currently requiring VPN will require the SSA connector.
Systems or applications generally accessible by the public, students or parents will not be behind SSA or require a security device posture check.
VPN provides full trust and access to an entire network, while SSA only connects the user to the specific systems or applications that they are authorized to access. This makes SSA a more secure alternative. Instead of manually opening the VPN client and connecting when needed, the ZPA connector used for SSA provides a more seamless user experience. The client runs in the background and will automatically initiate connections when you need access to protected UCSB applications or services. Users will need to re-authenticate every 7 days. It is security that is always on, and only acts if a user needs access to a secure UCSB resource.
In addition to improving our cybersecurity posture, there are other benefits of SSA:
- SSA is similar to a split-tunnel, which only routes traffic for specific applications through the connector, resulting in faster internet speeds, even when the client is running. This makes SSA a more stable access model that will not require frequent interaction or reconnections.
- The connector replaces VPN as the tool that devices must have installed to remotely access certain secure systems. It is lightweight and updates itself automatically. Unlike the current VPN (Ivanti) the connector does not require significant maintenance by users or IT support.
It is licensed to faculty, staff and student employees.
Deprecation will be iterative. ITS VPN profiles will be replaced first, followed by departmental VPN profiles. We expect to complete the transition by fall 2026.
VPN service may still be used in some capacity. More information to come.
- For remote connectivity, admins will use native tools, such as Remote Desktop Protocol (RDP) or Secure Shell (SSH).
- For remote support, we are currently assessing a handful of tools to replace ScreenConnect. More information to come.
Unlike VPN, which connects users to an entire network, SSA / Zscaler client connector only connects a user to the specific UCSB resource they need, eliminating the unnecessary exposure of other sensitive user information. This shrinks the attack surface and limits lateral movement between university business systems, visitors, and BYOD while enhancing user privacy. Only traffic associated with identified UCSB resources transits the connector. All other traffic remains private.