The deployment insights report provides a cumulative score and detailed checks for your organization configurations, including a breakdown by domain and severity.
Secure Access assesses your organization's configurations to identify security risks, errors, or configuration gaps. Assessments can be run manually by an administrator. Secure Access assesses only the configuration domains and checks that apply to your organization based on your enabled services, subscriptions, and available configuration data. Checks for services that are not licensed or enabled do not affect your assessment score.
The platform assigns severity labels—Critical, High, Medium, or Low—to checks needing action, which contribute to the cumulative posture score.
Secure Access monitors the following applicable configuration domains:
-
Certificates: Identifies expiring RAVPN, SAML SP, and custom CA certificates before they cause authentication, VPN, or private access disruptions.
-
Client Profiles: Checks ZTNA client profile safeguards, including auto-enrollment for roaming users and trusted-network definitions that could accidentally bypass enforcement.
-
Network Connectivity: Validates tunnel presence, tunnel health, split-tunnel steering, region or IP pool consistency, and cipher strength to reduce outage and routing-risk conditions.
-
Data Loss Prevention: Ensures DLP rules are enabled, cover sensitive data such as PII, use blocking actions where required, and apply broadly across identities.
-
Security Controls: Identifies overly broad access rules, missing threat-category blocks, weak default internet policy, and missing posture checks for sensitive private resources.
After reviewing the assessment checks, you can take direct action to modify your configuration settings and resolve identified security gaps.
Before you begin
You must have a full admin user role to access the deployment insights report. For more information, see Manage Accounts.