Requested production exports and logs may expose sensitive network and identity data
Source references: 2The Skill requests structured exports and logs covering users, groups, internal applications, destinations, tunnels, DNS, firewall, DLP, TLS exceptions, and compliance logging. These materials can reveal internal topology, security rules, identity structure, and business activity.
If unredacted production material is submitted to an unapproved AI service, shared workspace, or uncontrolled session, the service operator or other workspace members may gain access to that sensitive information.
These are legitimate migration inputs, but they include identities, internal applications, addresses, tunnels, security policies, exceptions, and activity logs. If uploaded to a model or shared with unauthorized parties, they could expose internal topology, access relationships, and business activity. Users can require disclosure of where data is sent and retained, and provide only minimized, redacted exports.
1. Identify the source stack: Zscaler ZIA, Zscaler ZPA, Palo Alto NGFW/Prisma/GlobalProtect, legacy VPN/SWG/SD-WAN, or other.2. Request exports and logs before mapping. Prefer structured exports over screenshots or prose summaries.3. Build an inventory: identities, groups, apps, destinations, connectors/tunnels, DNS/URL/firewall/DLP/TLS policies, objects/lists, locations/sites, exceptions, hit counts, and compliance logging.4. Produce a mapping plan: source object, Cloudflare One target resource, confidence, prerequisites, unsupported/partial mappings, and manual decisions.Show 1 other places
- ZIA: URL filtering, firewall filtering, SSL inspection, DLP, custom URL categories, IP groups, network services/service groups, users/groups/departments, locations, GRE tunnels, and static IPs.- ZPA: app segments, segment groups, server groups, app connectors/connector groups, access policies, IdP/group mapping, private DNS domains, ports, and protocols.- Palo Alto/Prisma: security/NAT/decryption rules, address/service objects and groups, URL categories, HIP profiles, GlobalProtect config, Prisma Access remote network/service connection config, zones, tags, logs, and hit counts.