Zscaler Client Connector for Virtual Desktop Infrastructure (VDI) Deployment Issue
ResolvedMinor
April 20, 2026 - Started about 1 month ago
- Lasted 28 days
Incident Report
Summary
AI Generated
Zscaler experienced an issue where access tokens generated before April 11, 2026 could not be used to deploy Zscaler Client Connector for VDI environments, causing "Init Config error" messages for administrators attempting deployments. The problem particularly impacted non-persistent VDI deployments without backup restore mechanisms, as agents failed to re-enroll on every boot when using old tokens from golden images. Zscaler deployed a mitigation across most cloud environments and provided a workaround of generating new access tokens, with full resolution scheduled for completion during a maintenance window.
Zscaler detected an issue where the existing access token that was generated before April 11, 2026 can not be used to deploy Zscaler Client Connector for VDI. As a workaround customers can create a new access token while the Zscaler team investigates and fixes the issue. We will continue to provide updates here as the investigation progresses. Status changes and additional details will be posted there as they become available.Customer Impact: Customers won’t be able to deploy Zscaler Client Connector for VDI using existing access tokens that were created before April 11 (administrators generate access tokens in the Cloud and Branch Connector portal under Administration > VDI Templates). Administrators will receive "Init Config error" once they try to deploy Zscaler Client Connector for VDI with an existing access token.Customers running non-persistent VDI deployments and do not have a backup restore mechanism implemented to restore user profiles and config files stored in %programdata%/ZCCVDI. In this case, the agent must re-enroll on every boot using the access token from the golden image. If the golden image contains an access token generated before April 11, every boot will fail with "Init Config error" until the golden image is updated with a new token. Already-enrolled agents in persistent environments are not affected, as they do not need to re-enroll.Workaround: Generate a new access token from the Cloud and Branch Connector portal (Administration > VDI Templates) and use the new token for any new deploymentsFor non-persistent VDI where no user backup/restore was implemented: Update the golden/master image with the new access token, this is critical since the agent re-enrolls on every boot.Latest Update - Mon, 11 May 2026 16:08:06 UTCZscaler has successfully deployed the mitigation across the zscaler.net, zscalerone.net, and zscloud.net cloud environments. Deployment activities for the remaining zscalertwo.net and zscalerthree.net cloud environments are scheduled to be completed during the upcoming maintenance window next weekend.Update - Thu, 23 Apr 2026 20:51:22 UTCZscaler has identified the root cause and is actively implementing a fix. We will provide further updates as progress continues and will confirm once the fix has been deployed.Update - Mon, 11 May 2026 16:08:06 UTCZscaler has successfully deployed the mitigation across the zscaler.net, zscalerone.net, and zscloud.net cloud environments. Deployment activities for the remaining zscalertwo.net and zscalerthree.net cloud environments are scheduled to be completed during the upcoming maintenance window next weekend.
Trusted by 1,000+ teams
The Status Page Aggregator with Early Outage Detection
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
The Status Page Aggregator with Early Outage Detection
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.