1. Packages
  2. Zscaler Internet Access (ZIA)
  3. API Docs
  4. AdvancedSettings
Viewing docs for pulumi-resource-zia v1.3.8
published on Friday, Mar 13, 2026 by Zscaler
zia logo
Viewing docs for pulumi-resource-zia v1.3.8
published on Friday, Mar 13, 2026 by Zscaler

    The zia_advanced_settings resource manages advanced settings in the Zscaler Internet Access (ZIA) cloud service. This singleton resource controls a wide range of advanced proxy, authentication, DNS resolution, and security settings including domain fronting protection, HTTP tunnel tracking, surrogate IP enforcement, and session timeout configuration.

    For more information, see the ZIA Advanced Settings documentation.

    Example Usage

    Basic Advanced Settings

    Example coming soon!

    Example coming soon!

    Example coming soon!

    import * as zia from "@bdzscaler/pulumi-zia";
    
    const example = new zia.AdvancedSettings("example", {
        enableOffice365: true,
        logInternalIp: true,
        blockHttpTunnelOnNonHttpPorts: true,
        blockDomainFrontingOnHostHeader: true,
        authBypassUrls: [".example.com"],
    });
    
    import zscaler_pulumi_zia as zia
    
    example = zia.AdvancedSettings("example",
        enable_office365=True,
        log_internal_ip=True,
        block_http_tunnel_on_non_http_ports=True,
        block_domain_fronting_on_host_header=True,
        auth_bypass_urls=[".example.com"],
    )
    
    resources:
      example:
        type: zia:AdvancedSettings
        properties:
          enableOffice365: true
          logInternalIp: true
          blockHttpTunnelOnNonHttpPorts: true
          blockDomainFrontingOnHostHeader: true
          authBypassUrls:
            - .example.com
    

    Create AdvancedSettings Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new AdvancedSettings(name: string, args?: AdvancedSettingsArgs, opts?: CustomResourceOptions);
    @overload
    def AdvancedSettings(resource_name: str,
                         args: Optional[AdvancedSettingsArgs] = None,
                         opts: Optional[ResourceOptions] = None)
    
    @overload
    def AdvancedSettings(resource_name: str,
                         opts: Optional[ResourceOptions] = None,
                         auth_bypass_apps: Optional[Sequence[str]] = None,
                         auth_bypass_url_categories: Optional[Sequence[str]] = None,
                         auth_bypass_urls: Optional[Sequence[str]] = None,
                         basic_bypass_apps: Optional[Sequence[str]] = None,
                         basic_bypass_url_categories: Optional[Sequence[str]] = None,
                         block_connect_host_sni_mismatch: Optional[bool] = None,
                         block_domain_fronting_apps: Optional[Sequence[str]] = None,
                         block_domain_fronting_on_host_header: Optional[bool] = None,
                         block_http_tunnel_on_non_http_ports: Optional[bool] = None,
                         block_non_compliant_http_request_on_http_ports: Optional[bool] = None,
                         block_non_http_on_http_port_enabled: Optional[bool] = None,
                         cascade_url_filtering: Optional[bool] = None,
                         digest_auth_bypass_apps: Optional[Sequence[str]] = None,
                         digest_auth_bypass_url_categories: Optional[Sequence[str]] = None,
                         digest_auth_bypass_urls: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_apps: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_exempt_apps: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_exempt_url_categories: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_exempt_urls: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_ipv6_apps: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_ipv6_exempt_apps: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_ipv6_exempt_url_categories: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_ipv6_url_categories: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_url_categories: Optional[Sequence[str]] = None,
                         dns_resolution_on_transparent_proxy_urls: Optional[Sequence[str]] = None,
                         domain_fronting_bypass_url_categories: Optional[Sequence[str]] = None,
                         dynamic_user_risk_enabled: Optional[bool] = None,
                         ecs_for_all_enabled: Optional[bool] = None,
                         enable_admin_rank_access: Optional[bool] = None,
                         enable_dns_resolution_on_transparent_proxy: Optional[bool] = None,
                         enable_evaluate_policy_on_global_ssl_bypass: Optional[bool] = None,
                         enable_ipv6_dns_optimization_on_all_transparent_proxy: Optional[bool] = None,
                         enable_ipv6_dns_resolution_on_transparent_proxy: Optional[bool] = None,
                         enable_office365: Optional[bool] = None,
                         enable_policy_for_unauthenticated_traffic: Optional[bool] = None,
                         enforce_surrogate_ip_for_windows_app: Optional[bool] = None,
                         http2_nonbrowser_traffic_enabled: Optional[bool] = None,
                         http_range_header_remove_url_categories: Optional[Sequence[str]] = None,
                         kerberos_bypass_apps: Optional[Sequence[str]] = None,
                         kerberos_bypass_url_categories: Optional[Sequence[str]] = None,
                         kerberos_bypass_urls: Optional[Sequence[str]] = None,
                         log_internal_ip: Optional[bool] = None,
                         prefer_sni_over_conn_host: Optional[bool] = None,
                         prefer_sni_over_conn_host_apps: Optional[Sequence[str]] = None,
                         sipa_xff_header_enabled: Optional[bool] = None,
                         sni_dns_optimization_bypass_url_categories: Optional[Sequence[str]] = None,
                         track_http_tunnel_on_http_ports: Optional[bool] = None,
                         ui_session_timeout: Optional[int] = None,
                         zscaler_client_connector1_and_pac_road_warrior_in_firewall: Optional[bool] = None)
    func NewAdvancedSettings(ctx *Context, name string, args *AdvancedSettingsArgs, opts ...ResourceOption) (*AdvancedSettings, error)
    public AdvancedSettings(string name, AdvancedSettingsArgs? args = null, CustomResourceOptions? opts = null)
    public AdvancedSettings(String name, AdvancedSettingsArgs args)
    public AdvancedSettings(String name, AdvancedSettingsArgs args, CustomResourceOptions options)
    
    type: zia:AdvancedSettings
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    

    Parameters

    name string
    The unique name of the resource.
    args AdvancedSettingsArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args AdvancedSettingsArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args AdvancedSettingsArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args AdvancedSettingsArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args AdvancedSettingsArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var advancedSettingsResource = new Zia.AdvancedSettings("advancedSettingsResource", new()
    {
        AuthBypassApps = new[]
        {
            "string",
        },
        AuthBypassUrlCategories = new[]
        {
            "string",
        },
        AuthBypassUrls = new[]
        {
            "string",
        },
        BasicBypassApps = new[]
        {
            "string",
        },
        BasicBypassUrlCategories = new[]
        {
            "string",
        },
        BlockConnectHostSniMismatch = false,
        BlockDomainFrontingApps = new[]
        {
            "string",
        },
        BlockDomainFrontingOnHostHeader = false,
        BlockHttpTunnelOnNonHttpPorts = false,
        BlockNonCompliantHttpRequestOnHttpPorts = false,
        BlockNonHttpOnHttpPortEnabled = false,
        CascadeUrlFiltering = false,
        DigestAuthBypassApps = new[]
        {
            "string",
        },
        DigestAuthBypassUrlCategories = new[]
        {
            "string",
        },
        DigestAuthBypassUrls = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyApps = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyExemptApps = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyExemptUrlCategories = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyExemptUrls = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyIpv6Apps = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyIpv6ExemptApps = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyIpv6ExemptUrlCategories = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyIpv6UrlCategories = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyUrlCategories = new[]
        {
            "string",
        },
        DnsResolutionOnTransparentProxyUrls = new[]
        {
            "string",
        },
        DomainFrontingBypassUrlCategories = new[]
        {
            "string",
        },
        DynamicUserRiskEnabled = false,
        EcsForAllEnabled = false,
        EnableAdminRankAccess = false,
        EnableDnsResolutionOnTransparentProxy = false,
        EnableEvaluatePolicyOnGlobalSslBypass = false,
        EnableIpv6DnsOptimizationOnAllTransparentProxy = false,
        EnableIpv6DnsResolutionOnTransparentProxy = false,
        EnableOffice365 = false,
        EnablePolicyForUnauthenticatedTraffic = false,
        EnforceSurrogateIpForWindowsApp = false,
        Http2NonbrowserTrafficEnabled = false,
        HttpRangeHeaderRemoveUrlCategories = new[]
        {
            "string",
        },
        KerberosBypassApps = new[]
        {
            "string",
        },
        KerberosBypassUrlCategories = new[]
        {
            "string",
        },
        KerberosBypassUrls = new[]
        {
            "string",
        },
        LogInternalIp = false,
        PreferSniOverConnHost = false,
        PreferSniOverConnHostApps = new[]
        {
            "string",
        },
        SipaXffHeaderEnabled = false,
        SniDnsOptimizationBypassUrlCategories = new[]
        {
            "string",
        },
        TrackHttpTunnelOnHttpPorts = false,
        UiSessionTimeout = 0,
        ZscalerClientConnector1AndPacRoadWarriorInFirewall = false,
    });
    
    example, err := zia.NewAdvancedSettings(ctx, "advancedSettingsResource", &zia.AdvancedSettingsArgs{
    	AuthBypassApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	AuthBypassUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	AuthBypassUrls: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	BasicBypassApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	BasicBypassUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	BlockConnectHostSniMismatch: pulumi.Bool(false),
    	BlockDomainFrontingApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	BlockDomainFrontingOnHostHeader:         pulumi.Bool(false),
    	BlockHttpTunnelOnNonHttpPorts:           pulumi.Bool(false),
    	BlockNonCompliantHttpRequestOnHttpPorts: pulumi.Bool(false),
    	BlockNonHttpOnHttpPortEnabled:           pulumi.Bool(false),
    	CascadeUrlFiltering:                     pulumi.Bool(false),
    	DigestAuthBypassApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DigestAuthBypassUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DigestAuthBypassUrls: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyExemptApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyExemptUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyExemptUrls: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyIpv6Apps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyIpv6ExemptApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyIpv6ExemptUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyIpv6UrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DnsResolutionOnTransparentProxyUrls: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DomainFrontingBypassUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	DynamicUserRiskEnabled:                         pulumi.Bool(false),
    	EcsForAllEnabled:                               pulumi.Bool(false),
    	EnableAdminRankAccess:                          pulumi.Bool(false),
    	EnableDnsResolutionOnTransparentProxy:          pulumi.Bool(false),
    	EnableEvaluatePolicyOnGlobalSslBypass:          pulumi.Bool(false),
    	EnableIpv6DnsOptimizationOnAllTransparentProxy: pulumi.Bool(false),
    	EnableIpv6DnsResolutionOnTransparentProxy:      pulumi.Bool(false),
    	EnableOffice365:                                pulumi.Bool(false),
    	EnablePolicyForUnauthenticatedTraffic:          pulumi.Bool(false),
    	EnforceSurrogateIpForWindowsApp:                pulumi.Bool(false),
    	Http2NonbrowserTrafficEnabled:                  pulumi.Bool(false),
    	HttpRangeHeaderRemoveUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	KerberosBypassApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	KerberosBypassUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	KerberosBypassUrls: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	LogInternalIp:         pulumi.Bool(false),
    	PreferSniOverConnHost: pulumi.Bool(false),
    	PreferSniOverConnHostApps: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	SipaXffHeaderEnabled: pulumi.Bool(false),
    	SniDnsOptimizationBypassUrlCategories: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	TrackHttpTunnelOnHttpPorts:                         pulumi.Bool(false),
    	UiSessionTimeout:                                   pulumi.Int(0),
    	ZscalerClientConnector1AndPacRoadWarriorInFirewall: pulumi.Bool(false),
    })
    
    var advancedSettingsResource = new AdvancedSettings("advancedSettingsResource", AdvancedSettingsArgs.builder()
        .authBypassApps("string")
        .authBypassUrlCategories("string")
        .authBypassUrls("string")
        .basicBypassApps("string")
        .basicBypassUrlCategories("string")
        .blockConnectHostSniMismatch(false)
        .blockDomainFrontingApps("string")
        .blockDomainFrontingOnHostHeader(false)
        .blockHttpTunnelOnNonHttpPorts(false)
        .blockNonCompliantHttpRequestOnHttpPorts(false)
        .blockNonHttpOnHttpPortEnabled(false)
        .cascadeUrlFiltering(false)
        .digestAuthBypassApps("string")
        .digestAuthBypassUrlCategories("string")
        .digestAuthBypassUrls("string")
        .dnsResolutionOnTransparentProxyApps("string")
        .dnsResolutionOnTransparentProxyExemptApps("string")
        .dnsResolutionOnTransparentProxyExemptUrlCategories("string")
        .dnsResolutionOnTransparentProxyExemptUrls("string")
        .dnsResolutionOnTransparentProxyIpv6Apps("string")
        .dnsResolutionOnTransparentProxyIpv6ExemptApps("string")
        .dnsResolutionOnTransparentProxyIpv6ExemptUrlCategories("string")
        .dnsResolutionOnTransparentProxyIpv6UrlCategories("string")
        .dnsResolutionOnTransparentProxyUrlCategories("string")
        .dnsResolutionOnTransparentProxyUrls("string")
        .domainFrontingBypassUrlCategories("string")
        .dynamicUserRiskEnabled(false)
        .ecsForAllEnabled(false)
        .enableAdminRankAccess(false)
        .enableDnsResolutionOnTransparentProxy(false)
        .enableEvaluatePolicyOnGlobalSslBypass(false)
        .enableIpv6DnsOptimizationOnAllTransparentProxy(false)
        .enableIpv6DnsResolutionOnTransparentProxy(false)
        .enableOffice365(false)
        .enablePolicyForUnauthenticatedTraffic(false)
        .enforceSurrogateIpForWindowsApp(false)
        .http2NonbrowserTrafficEnabled(false)
        .httpRangeHeaderRemoveUrlCategories("string")
        .kerberosBypassApps("string")
        .kerberosBypassUrlCategories("string")
        .kerberosBypassUrls("string")
        .logInternalIp(false)
        .preferSniOverConnHost(false)
        .preferSniOverConnHostApps("string")
        .sipaXffHeaderEnabled(false)
        .sniDnsOptimizationBypassUrlCategories("string")
        .trackHttpTunnelOnHttpPorts(false)
        .uiSessionTimeout(0)
        .zscalerClientConnector1AndPacRoadWarriorInFirewall(false)
        .build());
    
    advanced_settings_resource = zia.AdvancedSettings("advancedSettingsResource",
        auth_bypass_apps=["string"],
        auth_bypass_url_categories=["string"],
        auth_bypass_urls=["string"],
        basic_bypass_apps=["string"],
        basic_bypass_url_categories=["string"],
        block_connect_host_sni_mismatch=False,
        block_domain_fronting_apps=["string"],
        block_domain_fronting_on_host_header=False,
        block_http_tunnel_on_non_http_ports=False,
        block_non_compliant_http_request_on_http_ports=False,
        block_non_http_on_http_port_enabled=False,
        cascade_url_filtering=False,
        digest_auth_bypass_apps=["string"],
        digest_auth_bypass_url_categories=["string"],
        digest_auth_bypass_urls=["string"],
        dns_resolution_on_transparent_proxy_apps=["string"],
        dns_resolution_on_transparent_proxy_exempt_apps=["string"],
        dns_resolution_on_transparent_proxy_exempt_url_categories=["string"],
        dns_resolution_on_transparent_proxy_exempt_urls=["string"],
        dns_resolution_on_transparent_proxy_ipv6_apps=["string"],
        dns_resolution_on_transparent_proxy_ipv6_exempt_apps=["string"],
        dns_resolution_on_transparent_proxy_ipv6_exempt_url_categories=["string"],
        dns_resolution_on_transparent_proxy_ipv6_url_categories=["string"],
        dns_resolution_on_transparent_proxy_url_categories=["string"],
        dns_resolution_on_transparent_proxy_urls=["string"],
        domain_fronting_bypass_url_categories=["string"],
        dynamic_user_risk_enabled=False,
        ecs_for_all_enabled=False,
        enable_admin_rank_access=False,
        enable_dns_resolution_on_transparent_proxy=False,
        enable_evaluate_policy_on_global_ssl_bypass=False,
        enable_ipv6_dns_optimization_on_all_transparent_proxy=False,
        enable_ipv6_dns_resolution_on_transparent_proxy=False,
        enable_office365=False,
        enable_policy_for_unauthenticated_traffic=False,
        enforce_surrogate_ip_for_windows_app=False,
        http2_nonbrowser_traffic_enabled=False,
        http_range_header_remove_url_categories=["string"],
        kerberos_bypass_apps=["string"],
        kerberos_bypass_url_categories=["string"],
        kerberos_bypass_urls=["string"],
        log_internal_ip=False,
        prefer_sni_over_conn_host=False,
        prefer_sni_over_conn_host_apps=["string"],
        sipa_xff_header_enabled=False,
        sni_dns_optimization_bypass_url_categories=["string"],
        track_http_tunnel_on_http_ports=False,
        ui_session_timeout=0,
        zscaler_client_connector1_and_pac_road_warrior_in_firewall=False)
    
    const advancedSettingsResource = new zia.AdvancedSettings("advancedSettingsResource", {
        authBypassApps: ["string"],
        authBypassUrlCategories: ["string"],
        authBypassUrls: ["string"],
        basicBypassApps: ["string"],
        basicBypassUrlCategories: ["string"],
        blockConnectHostSniMismatch: false,
        blockDomainFrontingApps: ["string"],
        blockDomainFrontingOnHostHeader: false,
        blockHttpTunnelOnNonHttpPorts: false,
        blockNonCompliantHttpRequestOnHttpPorts: false,
        blockNonHttpOnHttpPortEnabled: false,
        cascadeUrlFiltering: false,
        digestAuthBypassApps: ["string"],
        digestAuthBypassUrlCategories: ["string"],
        digestAuthBypassUrls: ["string"],
        dnsResolutionOnTransparentProxyApps: ["string"],
        dnsResolutionOnTransparentProxyExemptApps: ["string"],
        dnsResolutionOnTransparentProxyExemptUrlCategories: ["string"],
        dnsResolutionOnTransparentProxyExemptUrls: ["string"],
        dnsResolutionOnTransparentProxyIpv6Apps: ["string"],
        dnsResolutionOnTransparentProxyIpv6ExemptApps: ["string"],
        dnsResolutionOnTransparentProxyIpv6ExemptUrlCategories: ["string"],
        dnsResolutionOnTransparentProxyIpv6UrlCategories: ["string"],
        dnsResolutionOnTransparentProxyUrlCategories: ["string"],
        dnsResolutionOnTransparentProxyUrls: ["string"],
        domainFrontingBypassUrlCategories: ["string"],
        dynamicUserRiskEnabled: false,
        ecsForAllEnabled: false,
        enableAdminRankAccess: false,
        enableDnsResolutionOnTransparentProxy: false,
        enableEvaluatePolicyOnGlobalSslBypass: false,
        enableIpv6DnsOptimizationOnAllTransparentProxy: false,
        enableIpv6DnsResolutionOnTransparentProxy: false,
        enableOffice365: false,
        enablePolicyForUnauthenticatedTraffic: false,
        enforceSurrogateIpForWindowsApp: false,
        http2NonbrowserTrafficEnabled: false,
        httpRangeHeaderRemoveUrlCategories: ["string"],
        kerberosBypassApps: ["string"],
        kerberosBypassUrlCategories: ["string"],
        kerberosBypassUrls: ["string"],
        logInternalIp: false,
        preferSniOverConnHost: false,
        preferSniOverConnHostApps: ["string"],
        sipaXffHeaderEnabled: false,
        sniDnsOptimizationBypassUrlCategories: ["string"],
        trackHttpTunnelOnHttpPorts: false,
        uiSessionTimeout: 0,
        zscalerClientConnector1AndPacRoadWarriorInFirewall: false,
    });
    
    type: zia:AdvancedSettings
    properties:
        authBypassApps:
            - string
        authBypassUrlCategories:
            - string
        authBypassUrls:
            - string
        basicBypassApps:
            - string
        basicBypassUrlCategories:
            - string
        blockConnectHostSniMismatch: false
        blockDomainFrontingApps:
            - string
        blockDomainFrontingOnHostHeader: false
        blockHttpTunnelOnNonHttpPorts: false
        blockNonCompliantHttpRequestOnHttpPorts: false
        blockNonHttpOnHttpPortEnabled: false
        cascadeUrlFiltering: false
        digestAuthBypassApps:
            - string
        digestAuthBypassUrlCategories:
            - string
        digestAuthBypassUrls:
            - string
        dnsResolutionOnTransparentProxyApps:
            - string
        dnsResolutionOnTransparentProxyExemptApps:
            - string
        dnsResolutionOnTransparentProxyExemptUrlCategories:
            - string
        dnsResolutionOnTransparentProxyExemptUrls:
            - string
        dnsResolutionOnTransparentProxyIpv6Apps:
            - string
        dnsResolutionOnTransparentProxyIpv6ExemptApps:
            - string
        dnsResolutionOnTransparentProxyIpv6ExemptUrlCategories:
            - string
        dnsResolutionOnTransparentProxyIpv6UrlCategories:
            - string
        dnsResolutionOnTransparentProxyUrlCategories:
            - string
        dnsResolutionOnTransparentProxyUrls:
            - string
        domainFrontingBypassUrlCategories:
            - string
        dynamicUserRiskEnabled: false
        ecsForAllEnabled: false
        enableAdminRankAccess: false
        enableDnsResolutionOnTransparentProxy: false
        enableEvaluatePolicyOnGlobalSslBypass: false
        enableIpv6DnsOptimizationOnAllTransparentProxy: false
        enableIpv6DnsResolutionOnTransparentProxy: false
        enableOffice365: false
        enablePolicyForUnauthenticatedTraffic: false
        enforceSurrogateIpForWindowsApp: false
        http2NonbrowserTrafficEnabled: false
        httpRangeHeaderRemoveUrlCategories:
            - string
        kerberosBypassApps:
            - string
        kerberosBypassUrlCategories:
            - string
        kerberosBypassUrls:
            - string
        logInternalIp: false
        preferSniOverConnHost: false
        preferSniOverConnHostApps:
            - string
        sipaXffHeaderEnabled: false
        sniDnsOptimizationBypassUrlCategories:
            - string
        trackHttpTunnelOnHttpPorts: false
        uiSessionTimeout: 0
        zscalerClientConnector1AndPacRoadWarriorInFirewall: false
    

    AdvancedSettings Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The AdvancedSettings resource accepts the following input properties:

    AuthBypassApps List<string>
    Cloud applications that bypass authentication.
    AuthBypassUrlCategories List<string>
    URL categories that bypass authentication.
    AuthBypassUrls List<string>
    URLs that bypass authentication.
    BasicBypassApps List<string>
    Cloud applications that bypass basic authentication.
    BasicBypassUrlCategories List<string>
    URL categories that bypass basic authentication.
    BlockConnectHostSniMismatch bool
    Block connections where CONNECT host and SNI mismatch.
    BlockDomainFrontingApps List<string>
    Cloud applications for which domain fronting is blocked.
    BlockDomainFrontingOnHostHeader bool
    Block domain fronting when the host header mismatches the SNI.
    BlockHttpTunnelOnNonHttpPorts bool
    Block HTTP tunnels on non-HTTP ports.
    BlockNonCompliantHttpRequestOnHttpPorts bool
    Block non-compliant HTTP requests on HTTP ports.
    BlockNonHttpOnHttpPortEnabled bool
    Block non-HTTP traffic on HTTP ports.
    CascadeUrlFiltering bool
    Enable cascading URL filtering.
    DigestAuthBypassApps List<string>
    Cloud applications that bypass digest authentication.
    DigestAuthBypassUrlCategories List<string>
    URL categories that bypass digest authentication.
    DigestAuthBypassUrls List<string>
    URLs that bypass digest authentication.
    DnsResolutionOnTransparentProxyApps List<string>
    Cloud applications with DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyExemptApps List<string>
    Cloud applications exempt from DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyExemptUrlCategories List<string>
    URL categories exempt from DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyExemptUrls List<string>
    URLs exempt from DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyIpv6Apps List<string>
    Cloud applications with IPv6 DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyIpv6ExemptApps List<string>
    Cloud applications exempt from IPv6 DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyIpv6ExemptUrlCategories List<string>
    URL categories exempt from IPv6 DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyIpv6UrlCategories List<string>
    URL categories with IPv6 DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyUrlCategories List<string>
    URL categories with DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyUrls List<string>
    URLs with DNS resolution on transparent proxy enabled.
    DomainFrontingBypassUrlCategories List<string>
    URL categories that bypass domain fronting detection.
    DynamicUserRiskEnabled bool
    Enable dynamic user risk scoring.
    EcsForAllEnabled bool
    Enable EDNS Client Subnet (ECS) for all DNS queries.
    EnableAdminRankAccess bool
    Enable admin rank-based access control.
    EnableDnsResolutionOnTransparentProxy bool
    Enable DNS resolution on transparent proxy.
    EnableEvaluatePolicyOnGlobalSslBypass bool
    Enable policy evaluation on global SSL bypass.
    EnableIpv6DnsOptimizationOnAllTransparentProxy bool
    Enable IPv6 DNS optimization on all transparent proxy connections.
    EnableIpv6DnsResolutionOnTransparentProxy bool
    Enable IPv6 DNS resolution on transparent proxy.
    EnableOffice365 bool
    Enable Office 365 one-click configuration.
    EnablePolicyForUnauthenticatedTraffic bool
    Enable policy evaluation for unauthenticated traffic.
    EnforceSurrogateIpForWindowsApp bool
    Enforce surrogate IP for Windows applications.
    Http2NonbrowserTrafficEnabled bool
    Enable HTTP/2 for non-browser traffic.
    HttpRangeHeaderRemoveUrlCategories List<string>
    URL categories for which HTTP range headers are removed.
    KerberosBypassApps List<string>
    Cloud applications that bypass Kerberos authentication.
    KerberosBypassUrlCategories List<string>
    URL categories that bypass Kerberos authentication.
    KerberosBypassUrls List<string>
    URLs that bypass Kerberos authentication.
    LogInternalIp bool
    Enable logging of internal IP addresses.
    PreferSniOverConnHost bool
    Prefer SNI over CONNECT host header for policy evaluation.
    PreferSniOverConnHostApps List<string>
    Cloud applications that prefer SNI over CONNECT host header.
    SipaXffHeaderEnabled bool
    Enable X-Forwarded-For header for SIPA traffic.
    SniDnsOptimizationBypassUrlCategories List<string>
    URL categories that bypass SNI/DNS optimization.
    TrackHttpTunnelOnHttpPorts bool
    Track HTTP tunnels on HTTP ports.
    UiSessionTimeout int
    UI session timeout in minutes.
    ZscalerClientConnector1AndPacRoadWarriorInFirewall bool
    Include Zscaler Client Connector and PAC road warrior traffic in firewall policy.
    AuthBypassApps []string
    Cloud applications that bypass authentication.
    AuthBypassUrlCategories []string
    URL categories that bypass authentication.
    AuthBypassUrls []string
    URLs that bypass authentication.
    BasicBypassApps []string
    Cloud applications that bypass basic authentication.
    BasicBypassUrlCategories []string
    URL categories that bypass basic authentication.
    BlockConnectHostSniMismatch bool
    Block connections where CONNECT host and SNI mismatch.
    BlockDomainFrontingApps []string
    Cloud applications for which domain fronting is blocked.
    BlockDomainFrontingOnHostHeader bool
    Block domain fronting when the host header mismatches the SNI.
    BlockHttpTunnelOnNonHttpPorts bool
    Block HTTP tunnels on non-HTTP ports.
    BlockNonCompliantHttpRequestOnHttpPorts bool
    Block non-compliant HTTP requests on HTTP ports.
    BlockNonHttpOnHttpPortEnabled bool
    Block non-HTTP traffic on HTTP ports.
    CascadeUrlFiltering bool
    Enable cascading URL filtering.
    DigestAuthBypassApps []string
    Cloud applications that bypass digest authentication.
    DigestAuthBypassUrlCategories []string
    URL categories that bypass digest authentication.
    DigestAuthBypassUrls []string
    URLs that bypass digest authentication.
    DnsResolutionOnTransparentProxyApps []string
    Cloud applications with DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyExemptApps []string
    Cloud applications exempt from DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyExemptUrlCategories []string
    URL categories exempt from DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyExemptUrls []string
    URLs exempt from DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyIpv6Apps []string
    Cloud applications with IPv6 DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyIpv6ExemptApps []string
    Cloud applications exempt from IPv6 DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyIpv6ExemptUrlCategories []string
    URL categories exempt from IPv6 DNS resolution on transparent proxy.
    DnsResolutionOnTransparentProxyIpv6UrlCategories []string
    URL categories with IPv6 DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyUrlCategories []string
    URL categories with DNS resolution on transparent proxy enabled.
    DnsResolutionOnTransparentProxyUrls []string
    URLs with DNS resolution on transparent proxy enabled.
    DomainFrontingBypassUrlCategories []string
    URL categories that bypass domain fronting detection.
    DynamicUserRiskEnabled bool
    Enable dynamic user risk scoring.
    EcsForAllEnabled bool
    Enable EDNS Client Subnet (ECS) for all DNS queries.
    EnableAdminRankAccess bool
    Enable admin rank-based access control.
    EnableDnsResolutionOnTransparentProxy bool
    Enable DNS resolution on transparent proxy.
    EnableEvaluatePolicyOnGlobalSslBypass bool
    Enable policy evaluation on global SSL bypass.
    EnableIpv6DnsOptimizationOnAllTransparentProxy bool
    Enable IPv6 DNS optimization on all transparent proxy connections.
    EnableIpv6DnsResolutionOnTransparentProxy bool
    Enable IPv6 DNS resolution on transparent proxy.
    EnableOffice365 bool
    Enable Office 365 one-click configuration.
    EnablePolicyForUnauthenticatedTraffic bool
    Enable policy evaluation for unauthenticated traffic.
    EnforceSurrogateIpForWindowsApp bool
    Enforce surrogate IP for Windows applications.
    Http2NonbrowserTrafficEnabled bool
    Enable HTTP/2 for non-browser traffic.
    HttpRangeHeaderRemoveUrlCategories []string
    URL categories for which HTTP range headers are removed.
    KerberosBypassApps []string
    Cloud applications that bypass Kerberos authentication.
    KerberosBypassUrlCategories []string
    URL categories that bypass Kerberos authentication.
    KerberosBypassUrls []string
    URLs that bypass Kerberos authentication.
    LogInternalIp bool
    Enable logging of internal IP addresses.
    PreferSniOverConnHost bool
    Prefer SNI over CONNECT host header for policy evaluation.
    PreferSniOverConnHostApps []string
    Cloud applications that prefer SNI over CONNECT host header.
    SipaXffHeaderEnabled bool
    Enable X-Forwarded-For header for SIPA traffic.
    SniDnsOptimizationBypassUrlCategories []string
    URL categories that bypass SNI/DNS optimization.
    TrackHttpTunnelOnHttpPorts bool
    Track HTTP tunnels on HTTP ports.
    UiSessionTimeout int
    UI session timeout in minutes.
    ZscalerClientConnector1AndPacRoadWarriorInFirewall bool
    Include Zscaler Client Connector and PAC road warrior traffic in firewall policy.
    authBypassApps List<String>
    Cloud applications that bypass authentication.
    authBypassUrlCategories List<String>
    URL categories that bypass authentication.
    authBypassUrls List<String>
    URLs that bypass authentication.
    basicBypassApps List<String>
    Cloud applications that bypass basic authentication.
    basicBypassUrlCategories List<String>
    URL categories that bypass basic authentication.
    blockConnectHostSniMismatch Boolean
    Block connections where CONNECT host and SNI mismatch.
    blockDomainFrontingApps List<String>
    Cloud applications for which domain fronting is blocked.
    blockDomainFrontingOnHostHeader Boolean
    Block domain fronting when the host header mismatches the SNI.
    blockHttpTunnelOnNonHttpPorts Boolean
    Block HTTP tunnels on non-HTTP ports.
    blockNonCompliantHttpRequestOnHttpPorts Boolean
    Block non-compliant HTTP requests on HTTP ports.
    blockNonHttpOnHttpPortEnabled Boolean
    Block non-HTTP traffic on HTTP ports.
    cascadeUrlFiltering Boolean
    Enable cascading URL filtering.
    digestAuthBypassApps List<String>
    Cloud applications that bypass digest authentication.
    digestAuthBypassUrlCategories List<String>
    URL categories that bypass digest authentication.
    digestAuthBypassUrls List<String>
    URLs that bypass digest authentication.
    dnsResolutionOnTransparentProxyApps List<String>
    Cloud applications with DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyExemptApps List<String>
    Cloud applications exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyExemptUrlCategories List<String>
    URL categories exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyExemptUrls List<String>
    URLs exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6Apps List<String>
    Cloud applications with IPv6 DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyIpv6ExemptApps List<String>
    Cloud applications exempt from IPv6 DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6ExemptUrlCategories List<String>
    URL categories exempt from IPv6 DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6UrlCategories List<String>
    URL categories with IPv6 DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyUrlCategories List<String>
    URL categories with DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyUrls List<String>
    URLs with DNS resolution on transparent proxy enabled.
    domainFrontingBypassUrlCategories List<String>
    URL categories that bypass domain fronting detection.
    dynamicUserRiskEnabled Boolean
    Enable dynamic user risk scoring.
    ecsForAllEnabled Boolean
    Enable EDNS Client Subnet (ECS) for all DNS queries.
    enableAdminRankAccess Boolean
    Enable admin rank-based access control.
    enableDnsResolutionOnTransparentProxy Boolean
    Enable DNS resolution on transparent proxy.
    enableEvaluatePolicyOnGlobalSslBypass Boolean
    Enable policy evaluation on global SSL bypass.
    enableIpv6DnsOptimizationOnAllTransparentProxy Boolean
    Enable IPv6 DNS optimization on all transparent proxy connections.
    enableIpv6DnsResolutionOnTransparentProxy Boolean
    Enable IPv6 DNS resolution on transparent proxy.
    enableOffice365 Boolean
    Enable Office 365 one-click configuration.
    enablePolicyForUnauthenticatedTraffic Boolean
    Enable policy evaluation for unauthenticated traffic.
    enforceSurrogateIpForWindowsApp Boolean
    Enforce surrogate IP for Windows applications.
    http2NonbrowserTrafficEnabled Boolean
    Enable HTTP/2 for non-browser traffic.
    httpRangeHeaderRemoveUrlCategories List<String>
    URL categories for which HTTP range headers are removed.
    kerberosBypassApps List<String>
    Cloud applications that bypass Kerberos authentication.
    kerberosBypassUrlCategories List<String>
    URL categories that bypass Kerberos authentication.
    kerberosBypassUrls List<String>
    URLs that bypass Kerberos authentication.
    logInternalIp Boolean
    Enable logging of internal IP addresses.
    preferSniOverConnHost Boolean
    Prefer SNI over CONNECT host header for policy evaluation.
    preferSniOverConnHostApps List<String>
    Cloud applications that prefer SNI over CONNECT host header.
    sipaXffHeaderEnabled Boolean
    Enable X-Forwarded-For header for SIPA traffic.
    sniDnsOptimizationBypassUrlCategories List<String>
    URL categories that bypass SNI/DNS optimization.
    trackHttpTunnelOnHttpPorts Boolean
    Track HTTP tunnels on HTTP ports.
    uiSessionTimeout Integer
    UI session timeout in minutes.
    zscalerClientConnector1AndPacRoadWarriorInFirewall Boolean
    Include Zscaler Client Connector and PAC road warrior traffic in firewall policy.
    authBypassApps string[]
    Cloud applications that bypass authentication.
    authBypassUrlCategories string[]
    URL categories that bypass authentication.
    authBypassUrls string[]
    URLs that bypass authentication.
    basicBypassApps string[]
    Cloud applications that bypass basic authentication.
    basicBypassUrlCategories string[]
    URL categories that bypass basic authentication.
    blockConnectHostSniMismatch boolean
    Block connections where CONNECT host and SNI mismatch.
    blockDomainFrontingApps string[]
    Cloud applications for which domain fronting is blocked.
    blockDomainFrontingOnHostHeader boolean
    Block domain fronting when the host header mismatches the SNI.
    blockHttpTunnelOnNonHttpPorts boolean
    Block HTTP tunnels on non-HTTP ports.
    blockNonCompliantHttpRequestOnHttpPorts boolean
    Block non-compliant HTTP requests on HTTP ports.
    blockNonHttpOnHttpPortEnabled boolean
    Block non-HTTP traffic on HTTP ports.
    cascadeUrlFiltering boolean
    Enable cascading URL filtering.
    digestAuthBypassApps string[]
    Cloud applications that bypass digest authentication.
    digestAuthBypassUrlCategories string[]
    URL categories that bypass digest authentication.
    digestAuthBypassUrls string[]
    URLs that bypass digest authentication.
    dnsResolutionOnTransparentProxyApps string[]
    Cloud applications with DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyExemptApps string[]
    Cloud applications exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyExemptUrlCategories string[]
    URL categories exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyExemptUrls string[]
    URLs exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6Apps string[]
    Cloud applications with IPv6 DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyIpv6ExemptApps string[]
    Cloud applications exempt from IPv6 DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6ExemptUrlCategories string[]
    URL categories exempt from IPv6 DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6UrlCategories string[]
    URL categories with IPv6 DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyUrlCategories string[]
    URL categories with DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyUrls string[]
    URLs with DNS resolution on transparent proxy enabled.
    domainFrontingBypassUrlCategories string[]
    URL categories that bypass domain fronting detection.
    dynamicUserRiskEnabled boolean
    Enable dynamic user risk scoring.
    ecsForAllEnabled boolean
    Enable EDNS Client Subnet (ECS) for all DNS queries.
    enableAdminRankAccess boolean
    Enable admin rank-based access control.
    enableDnsResolutionOnTransparentProxy boolean
    Enable DNS resolution on transparent proxy.
    enableEvaluatePolicyOnGlobalSslBypass boolean
    Enable policy evaluation on global SSL bypass.
    enableIpv6DnsOptimizationOnAllTransparentProxy boolean
    Enable IPv6 DNS optimization on all transparent proxy connections.
    enableIpv6DnsResolutionOnTransparentProxy boolean
    Enable IPv6 DNS resolution on transparent proxy.
    enableOffice365 boolean
    Enable Office 365 one-click configuration.
    enablePolicyForUnauthenticatedTraffic boolean
    Enable policy evaluation for unauthenticated traffic.
    enforceSurrogateIpForWindowsApp boolean
    Enforce surrogate IP for Windows applications.
    http2NonbrowserTrafficEnabled boolean
    Enable HTTP/2 for non-browser traffic.
    httpRangeHeaderRemoveUrlCategories string[]
    URL categories for which HTTP range headers are removed.
    kerberosBypassApps string[]
    Cloud applications that bypass Kerberos authentication.
    kerberosBypassUrlCategories string[]
    URL categories that bypass Kerberos authentication.
    kerberosBypassUrls string[]
    URLs that bypass Kerberos authentication.
    logInternalIp boolean
    Enable logging of internal IP addresses.
    preferSniOverConnHost boolean
    Prefer SNI over CONNECT host header for policy evaluation.
    preferSniOverConnHostApps string[]
    Cloud applications that prefer SNI over CONNECT host header.
    sipaXffHeaderEnabled boolean
    Enable X-Forwarded-For header for SIPA traffic.
    sniDnsOptimizationBypassUrlCategories string[]
    URL categories that bypass SNI/DNS optimization.
    trackHttpTunnelOnHttpPorts boolean
    Track HTTP tunnels on HTTP ports.
    uiSessionTimeout number
    UI session timeout in minutes.
    zscalerClientConnector1AndPacRoadWarriorInFirewall boolean
    Include Zscaler Client Connector and PAC road warrior traffic in firewall policy.
    auth_bypass_apps Sequence[str]
    Cloud applications that bypass authentication.
    auth_bypass_url_categories Sequence[str]
    URL categories that bypass authentication.
    auth_bypass_urls Sequence[str]
    URLs that bypass authentication.
    basic_bypass_apps Sequence[str]
    Cloud applications that bypass basic authentication.
    basic_bypass_url_categories Sequence[str]
    URL categories that bypass basic authentication.
    block_connect_host_sni_mismatch bool
    Block connections where CONNECT host and SNI mismatch.
    block_domain_fronting_apps Sequence[str]
    Cloud applications for which domain fronting is blocked.
    block_domain_fronting_on_host_header bool
    Block domain fronting when the host header mismatches the SNI.
    block_http_tunnel_on_non_http_ports bool
    Block HTTP tunnels on non-HTTP ports.
    block_non_compliant_http_request_on_http_ports bool
    Block non-compliant HTTP requests on HTTP ports.
    block_non_http_on_http_port_enabled bool
    Block non-HTTP traffic on HTTP ports.
    cascade_url_filtering bool
    Enable cascading URL filtering.
    digest_auth_bypass_apps Sequence[str]
    Cloud applications that bypass digest authentication.
    digest_auth_bypass_url_categories Sequence[str]
    URL categories that bypass digest authentication.
    digest_auth_bypass_urls Sequence[str]
    URLs that bypass digest authentication.
    dns_resolution_on_transparent_proxy_apps Sequence[str]
    Cloud applications with DNS resolution on transparent proxy enabled.
    dns_resolution_on_transparent_proxy_exempt_apps Sequence[str]
    Cloud applications exempt from DNS resolution on transparent proxy.
    dns_resolution_on_transparent_proxy_exempt_url_categories Sequence[str]
    URL categories exempt from DNS resolution on transparent proxy.
    dns_resolution_on_transparent_proxy_exempt_urls Sequence[str]
    URLs exempt from DNS resolution on transparent proxy.
    dns_resolution_on_transparent_proxy_ipv6_apps Sequence[str]
    Cloud applications with IPv6 DNS resolution on transparent proxy enabled.
    dns_resolution_on_transparent_proxy_ipv6_exempt_apps Sequence[str]
    Cloud applications exempt from IPv6 DNS resolution on transparent proxy.
    dns_resolution_on_transparent_proxy_ipv6_exempt_url_categories Sequence[str]
    URL categories exempt from IPv6 DNS resolution on transparent proxy.
    dns_resolution_on_transparent_proxy_ipv6_url_categories Sequence[str]
    URL categories with IPv6 DNS resolution on transparent proxy enabled.
    dns_resolution_on_transparent_proxy_url_categories Sequence[str]
    URL categories with DNS resolution on transparent proxy enabled.
    dns_resolution_on_transparent_proxy_urls Sequence[str]
    URLs with DNS resolution on transparent proxy enabled.
    domain_fronting_bypass_url_categories Sequence[str]
    URL categories that bypass domain fronting detection.
    dynamic_user_risk_enabled bool
    Enable dynamic user risk scoring.
    ecs_for_all_enabled bool
    Enable EDNS Client Subnet (ECS) for all DNS queries.
    enable_admin_rank_access bool
    Enable admin rank-based access control.
    enable_dns_resolution_on_transparent_proxy bool
    Enable DNS resolution on transparent proxy.
    enable_evaluate_policy_on_global_ssl_bypass bool
    Enable policy evaluation on global SSL bypass.
    enable_ipv6_dns_optimization_on_all_transparent_proxy bool
    Enable IPv6 DNS optimization on all transparent proxy connections.
    enable_ipv6_dns_resolution_on_transparent_proxy bool
    Enable IPv6 DNS resolution on transparent proxy.
    enable_office365 bool
    Enable Office 365 one-click configuration.
    enable_policy_for_unauthenticated_traffic bool
    Enable policy evaluation for unauthenticated traffic.
    enforce_surrogate_ip_for_windows_app bool
    Enforce surrogate IP for Windows applications.
    http2_nonbrowser_traffic_enabled bool
    Enable HTTP/2 for non-browser traffic.
    http_range_header_remove_url_categories Sequence[str]
    URL categories for which HTTP range headers are removed.
    kerberos_bypass_apps Sequence[str]
    Cloud applications that bypass Kerberos authentication.
    kerberos_bypass_url_categories Sequence[str]
    URL categories that bypass Kerberos authentication.
    kerberos_bypass_urls Sequence[str]
    URLs that bypass Kerberos authentication.
    log_internal_ip bool
    Enable logging of internal IP addresses.
    prefer_sni_over_conn_host bool
    Prefer SNI over CONNECT host header for policy evaluation.
    prefer_sni_over_conn_host_apps Sequence[str]
    Cloud applications that prefer SNI over CONNECT host header.
    sipa_xff_header_enabled bool
    Enable X-Forwarded-For header for SIPA traffic.
    sni_dns_optimization_bypass_url_categories Sequence[str]
    URL categories that bypass SNI/DNS optimization.
    track_http_tunnel_on_http_ports bool
    Track HTTP tunnels on HTTP ports.
    ui_session_timeout int
    UI session timeout in minutes.
    zscaler_client_connector1_and_pac_road_warrior_in_firewall bool
    Include Zscaler Client Connector and PAC road warrior traffic in firewall policy.
    authBypassApps List<String>
    Cloud applications that bypass authentication.
    authBypassUrlCategories List<String>
    URL categories that bypass authentication.
    authBypassUrls List<String>
    URLs that bypass authentication.
    basicBypassApps List<String>
    Cloud applications that bypass basic authentication.
    basicBypassUrlCategories List<String>
    URL categories that bypass basic authentication.
    blockConnectHostSniMismatch Boolean
    Block connections where CONNECT host and SNI mismatch.
    blockDomainFrontingApps List<String>
    Cloud applications for which domain fronting is blocked.
    blockDomainFrontingOnHostHeader Boolean
    Block domain fronting when the host header mismatches the SNI.
    blockHttpTunnelOnNonHttpPorts Boolean
    Block HTTP tunnels on non-HTTP ports.
    blockNonCompliantHttpRequestOnHttpPorts Boolean
    Block non-compliant HTTP requests on HTTP ports.
    blockNonHttpOnHttpPortEnabled Boolean
    Block non-HTTP traffic on HTTP ports.
    cascadeUrlFiltering Boolean
    Enable cascading URL filtering.
    digestAuthBypassApps List<String>
    Cloud applications that bypass digest authentication.
    digestAuthBypassUrlCategories List<String>
    URL categories that bypass digest authentication.
    digestAuthBypassUrls List<String>
    URLs that bypass digest authentication.
    dnsResolutionOnTransparentProxyApps List<String>
    Cloud applications with DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyExemptApps List<String>
    Cloud applications exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyExemptUrlCategories List<String>
    URL categories exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyExemptUrls List<String>
    URLs exempt from DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6Apps List<String>
    Cloud applications with IPv6 DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyIpv6ExemptApps List<String>
    Cloud applications exempt from IPv6 DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6ExemptUrlCategories List<String>
    URL categories exempt from IPv6 DNS resolution on transparent proxy.
    dnsResolutionOnTransparentProxyIpv6UrlCategories List<String>
    URL categories with IPv6 DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyUrlCategories List<String>
    URL categories with DNS resolution on transparent proxy enabled.
    dnsResolutionOnTransparentProxyUrls List<String>
    URLs with DNS resolution on transparent proxy enabled.
    domainFrontingBypassUrlCategories List<String>
    URL categories that bypass domain fronting detection.
    dynamicUserRiskEnabled Boolean
    Enable dynamic user risk scoring.
    ecsForAllEnabled Boolean
    Enable EDNS Client Subnet (ECS) for all DNS queries.
    enableAdminRankAccess Boolean
    Enable admin rank-based access control.
    enableDnsResolutionOnTransparentProxy Boolean
    Enable DNS resolution on transparent proxy.
    enableEvaluatePolicyOnGlobalSslBypass Boolean
    Enable policy evaluation on global SSL bypass.
    enableIpv6DnsOptimizationOnAllTransparentProxy Boolean
    Enable IPv6 DNS optimization on all transparent proxy connections.
    enableIpv6DnsResolutionOnTransparentProxy Boolean
    Enable IPv6 DNS resolution on transparent proxy.
    enableOffice365 Boolean
    Enable Office 365 one-click configuration.
    enablePolicyForUnauthenticatedTraffic Boolean
    Enable policy evaluation for unauthenticated traffic.
    enforceSurrogateIpForWindowsApp Boolean
    Enforce surrogate IP for Windows applications.
    http2NonbrowserTrafficEnabled Boolean
    Enable HTTP/2 for non-browser traffic.
    httpRangeHeaderRemoveUrlCategories List<String>
    URL categories for which HTTP range headers are removed.
    kerberosBypassApps List<String>
    Cloud applications that bypass Kerberos authentication.
    kerberosBypassUrlCategories List<String>
    URL categories that bypass Kerberos authentication.
    kerberosBypassUrls List<String>
    URLs that bypass Kerberos authentication.
    logInternalIp Boolean
    Enable logging of internal IP addresses.
    preferSniOverConnHost Boolean
    Prefer SNI over CONNECT host header for policy evaluation.
    preferSniOverConnHostApps List<String>
    Cloud applications that prefer SNI over CONNECT host header.
    sipaXffHeaderEnabled Boolean
    Enable X-Forwarded-For header for SIPA traffic.
    sniDnsOptimizationBypassUrlCategories List<String>
    URL categories that bypass SNI/DNS optimization.
    trackHttpTunnelOnHttpPorts Boolean
    Track HTTP tunnels on HTTP ports.
    uiSessionTimeout Number
    UI session timeout in minutes.
    zscalerClientConnector1AndPacRoadWarriorInFirewall Boolean
    Include Zscaler Client Connector and PAC road warrior traffic in firewall policy.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the AdvancedSettings resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    ResourceId string
    The internal resource identifier for the advanced settings.
    Id string
    The provider-assigned unique ID for this managed resource.
    ResourceId string
    The internal resource identifier for the advanced settings.
    id String
    The provider-assigned unique ID for this managed resource.
    resourceId String
    The internal resource identifier for the advanced settings.
    id string
    The provider-assigned unique ID for this managed resource.
    resourceId string
    The internal resource identifier for the advanced settings.
    id str
    The provider-assigned unique ID for this managed resource.
    resource_id str
    The internal resource identifier for the advanced settings.
    id String
    The provider-assigned unique ID for this managed resource.
    resourceId String
    The internal resource identifier for the advanced settings.

    Import

    This is a singleton resource and does not support traditional import. It is automatically managed by the provider.

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    zia zscaler/pulumi-zia
    License
    zia logo
    Viewing docs for pulumi-resource-zia v1.3.8
    published on Friday, Mar 13, 2026 by Zscaler
      Try Pulumi Cloud free. Your team will thank you.