This guide outlines how to integrate Wiz with the Zscaler MDR for Cloud offering. Wiz is a cloud-native security platform that provides comprehensive posture analysis and threat detection across your cloud environments. The integration combines Wiz detection capabilities with Zscaler MDR’s expert investigation, enabling our teams to investigate Wiz-generated alerts and enrich Zscaler MDR investigations with valuable Wiz risk context. For more information on how Zscaler MDR ingests data from Wiz, see the FAQ.
Prerequisites
Before you start the Wiz integration, please make sure the following requirements are met:
You have an active Zscaler MDR Cloud subscription
You are sending control plane telemetry to Zscaler MDR through the AWS, Azure, or GCP integrations
You have the following Wiz licenses:
Wiz Advanced Cloud License: This is the minimum required license and must include Threat Detection Issues, Toxic Combinations, and Cloud Config Findings.
Wiz Defend Ingestion Add-on: This add-on enables additional features. To ingest identity threats and additional detections into Zscaler MDR, you must have the Wiz Defend add-on and at least one integrated identity provider (Okta, Entra ID, or Google Workspace).
You consent to the required permissions (configured in Step 2). For more details, see the FAQ.
1 Zscaler MDR | Add the Integration
In the Zscaler MDR portal, go to the Integrations page, then click Add Integration.

On the Add integration dialog, search for the Wiz integration, then click Configure.

On the Zscaler MDR configuration page, enter a name for the integration.

2 Zscaler MDR | Record the API and Oath Tokens
In Step 2: Record the API and OAuth tokens, copy the Wiz OAuth Client ID and Wiz OAuth Client Secret. You’ll need this in a later step.

3 Zscaler MDR | Customize How This Data Is Retained
[OPTIONAL] If you’re subscribed to the Zscaler MDR Security Data Lake managed storage solution, you can choose to copy the telemetry generated by the integration to long-term storage for later query or retrieval.
Check the Store in the Security Data Lake box.

Enter your desired data retention period in days. The maximum is 1095 days (three years).
4 Wiz | Connect Zscaler MDR to Wiz
In Wiz, go to the Connect to Wiz page:
Under Security & Identity, select Zscaler MDR.
On the Connection page:
Enter a Base URL. The default value is
https://api.redcanary.com.Paste the Client ID and Client Secret you copied from the Zscaler MDR integation.
Enter an Application ID such as "wiz-redcanary." Make sure to use only lower case letters and no spaces.
Click Continue.
On the Details page:
Enter a display name.
(Optional) Enable Filter out on-prem events if your instance of Zscaler MDR covers on-prem workloads that Wiz cannot scan.
Click Finish.
5 Zscaler MDR | Activate the Integration
After you’ve completed the configuration, click Save to activate the integration.
The Wiz integration is now live!
Wiz data should appear in Zscaler MDR within 5 minutes, provided it is a supported data type that meets our filtering criteria. For additional details, see the FAQ.
6 Zscaler MDR | Modify the Integration
After the Wiz integration is active, you can make the following modifications to the configuration:
Update the API configuration used by the integration
Adjust the Security Data Lake retention period
Decommission the integration
To modify the configuration:
In the Zscaler MDR portal, go to the Integrations page, then click on the name of the integration you want to modify.

After you’ve finished editing the configuration, click Save to apply your changes.
Deleting the Integration
To delete the integration from Zscaler MDR, click the
button, then click OK to confirm.
Important
Deleting the integration will prevent any new alerts from being sent to Zscaler MDR. While existing threat data will remain, all processed alerts will be permanently deleted, and this action cannot be undone.
For this reason, we recommend deactivating the integration instead, which will retain all previously processed alerts but stop further ingestion. You can reactivate the integration at any time.
FAQ
What are the required permissions for the Wiz integration?
The table below details all required permissions and explains why Zscaler MDR requires each one.
Category | Permission | Justification |
|---|---|---|
Cloud Events | Read (read:cloud_events_cloud) | Used to resolve triggering event data within detections for investigative context |
Detections | Read (read:detections) | Used to retrieve threat detections, the primary data source for Wiz alert ingestion |
Issues | Read/list (read:issues) | Used to retrieve issues associated with detections for investigative context |
Read/list (read:threat_issues) | Used to retrieve threat detection issues linked to detections for display in the Zscaler MDR portal | |
Resources | Read (read:resources) | Used to retrieve cloud accounts for scoping detection queries and to enrich cloud resource data |
Which types of Wiz data does Zscaler MDR ingest?
Zscaler MDR is capable of ingesting the following types of alert data, each serving specific purposes for threat detection and investigation:
Alerts processed through Zscaler MDR’s investigative workflows
These alerts undergo comprehensive analysis through Zscaler MDR’s investigative workflows. They enable Zscaler MDR to identify and address potential threats effectively.
Detections: Detections represent findings generated by Threat Detection Rules when analyzing cloud events, logs, or runtime activity. These high-fidelity alerts are designed to identify suspicious and unusual activity in cloud environments. Wiz automatically groups related Detections into a broader Threat for better context.
Threat Detection Issues: Generated by Threat Detection Rules, these Issues arise from the evaluation of cloud events affecting individual resources. They indicate the detection of specific suspicious activities within a cloud environment. Zscaler MDR fetches the associated Threat Detection Issue for each Detection to provide additional investigative context, including source rules, affected entities, and project information.
Why is Wiz data not appearing in Zscaler MDR?
If you're not seeing Wiz data in Zscaler MDR, it may be due to one or more of the following reasons:
Non-essential Alert Data: Zscaler MDR only ingests alerts categorized as Medium, High, or Critical. Any Low-level alerts sent to Zscaler MDR will be filtered out and will not appear in the portal. For details, see the FAQ What are the required permissions for the Wiz integration? above.
Unsupported Data Types: Zscaler MDR only ingests Detections and Threat Detection Issues from Wiz. Other Wiz data types, such as Toxic Combination Issues or Cloud Configuration Findings, are not ingested and will not be visible in the portal.
Incorrect Permissions Configuration: Zscaler MDR requires certain permissions, which are configured in Step 2 of the setup process. If any of these permissions are missing or misconfigured, it could prevent the ingestion of Wiz data into Zscaler MDR. For details, see the FAQ What are the required permissions for the Wiz integration? above.