Guidelines and Limitations
- iOS does not currently support step-up authentication, so users will not be able to use
the Zero Trust Access app to access a private resource if step up authentication is enabled
for that resource. You can disable this functionality by default on the Rule Defaults page,
or disable it in private access rules that include access for iOS devices:
For information, see Network Authentication for Zero Trust Access.
- Traffic originating from the iOS client has an implicit subdomain wildcard on every rule.
So, for example, if a resource is configured with the address
foo.com
, iOS traffic to that resource will also matchbar.foo.com
. Configure your private resources and rules accordingly.