If Zscaler is not connecting, start with the exact Client Connector error and current Zscaler status. An operational provider indicator does not verify your device, company configuration or every application. Equally, an incident affecting one cloud or service does not establish that all Zscaler connections are failing.
“Unable to enroll at this time”
Zscaler's Client Connector error reference associates code 3071 with enrollment requests exceeding the server's capacity to handle them. The message supplies a retry interval that can vary. Allow the displayed interval to expire before trying again; repeatedly restarting enrollment is not a useful recovery test.
Check the numeric code, not just a similar-looking message. Code 10108 describes device registration failing because the server could not be reached or returned an error. That needs connectivity and matching cloud-status checks; it does not identify the same cause as 3071.
If enrollment keeps failing, record the code, timestamp with timezone, operating system and Client Connector version. Tell your IT team whether this is first-time enrollment or a previously working device. Keep any additional error detail: it can narrow the investigation more than “Zscaler is down.”
Separate internet access from private applications
Client Connector exposes distinct service indicators. Its user documentation describes Internet Security for protected internet traffic and Private Access for internal resources. Record which indicator is affected and whether one application or several fail.
| What you observe | Useful next check |
|---|---|
| Enrollment fails before access starts | Error code, retry message and sign-in stage |
| Internet Security has an error | Its exact status message and an approved public website |
| Private Access fails but public websites work | The affected internal application and Private Access status |
| One internal application fails | Its application owner and a known working internal application |
| Several colleagues fail at the same time | Shared cloud, location, application and first failure time |
These comparisons help locate the problem; they do not prove its cause. A working public website does not test access to a private application, and one working private application does not verify every application behind ZPA.
Match an official incident to your cloud
Open the relevant notice on Zscaler Trust and compare its service, cloud, location and update time with your evidence. Ask IT for the organization's actual ZIA or ZPA cloud if you do not know it.
Zscaler documents separate ZIA and ZPA cloud assignments. A Client Connector portal can communicate with different ZPA clouds, so do not infer your ZPA cloud from the portal address alone. A scheduled maintenance notice also needs a matching time and stated impact before it explains a failure.
Try the action that matches the error
The connection status error guide distinguishes network, authentication, captive portal and driver problems. Use the relevant Retry or Authenticate option when offered. If a captive portal is detected on a network you recognize, complete its normal sign-in through the app's browser prompt.
Follow your organization's instructions for repair or restart options. Keep managed security controls enabled; firewall, certificate and policy changes belong with IT. Changing several settings at once also makes the original failure harder to diagnose.
If available, use Report an Issue in Client Connector to send diagnostic details through the configured support path. Otherwise contact your IT team. Keep logs and internal hostnames out of public comments.
After a fix, recheck the original failing application. Follow Zscaler provider alerts or review Zscaler incident history while your team investigates the connection.