## TL;DR
Check the Zscaler service status page first, then verify the device is enrolled and the app profile is assigned. If the connector spins on "connecting" with no error, restart the Zscaler service and check for conflicting VPN clients or firewall software.

## The error
```text
Connecting... (spins indefinitely, never reaches "Connected")
```

## Steps
1. Check the Zscaler status page and the admin's cloud status. Expected: no ongoing incident. Do not troubleshoot a cloud outage as a client problem.
2. In the client, open More > About and confirm enrollment: the device should show as enrolled to the right cloud. Expected: enrolled. Unenrolled devices spin forever.
3. Check for conflicting software: any other VPN client, or third-party firewall, running at the same time. Expected: none active. Two tunnel drivers fight each other.
4. Restart the service: Windows services > "Zscaler Tunnel" > restart, or reboot the machine. Expected: connector proceeds past connecting within a minute.
5. In the ZIA admin portal, confirm the user's app profile and that their location is not excluded in a way that breaks enrollment. Expected: profile assigned. Collect client logs (More > Diagnostics) before escalating.

## When to use
- Client Connector never leaves "connecting"
- Fresh installs that never connected

## When not to use
- Connected but specific sites blocked (policy issue)
- Slow performance on an established tunnel

## Compatibility
- Zscaler Client Connector 3.x/4.x; ZIA/ZPA tenants

## Variants
### Connects then immediately disconnects
Usually a policy or authentication failure, not a connectivity failure. Check the admin's client logs.
### "Authentication failed" during connecting
The device or user auth is rejected; check IdP integration and enrollment.

## Why it happens
"Connecting" covers enrollment validation, tunnel setup, and policy download. A failure at any stage with no clear error surfaces as an endless spinner, so the checklist eliminates the stages in order.

## Edge cases
- Trusted network detection misconfigured: the client may try to bypass Zscaler on networks it thinks are corporate.
- macOS upgrades: the system extension approval may need re-granting after major OS updates.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_lnE-HT2_MvBRYup0tRQ0eg
