Hello Fredle,
To verify whether ZPA is blocking the affected user due to a Client Posture Check, start by reviewing the access diagnostics in the ZPA Admin Portal under Administration > Diagnostics.
Find the affected user and compare the failed connection with a successful connection from another user.
Check the diagnostic information for the Access Policy Name, Posture Profile, username, and client type.
Then navigate to Administration > Access Policy and inspect the rule associated with the staging application.
Look for conditions referencing Client Connector Posture Profiles and identify the specific profile applied to the user.
Review the posture profile's configured requirements, such as Microsoft Defender status, endpoint security products, or other compliance checks.
A posture failure alone does not prove that it caused the denial; confirm that the access policy uses that posture result to block access.
If the diagnostic information does not identify the failing condition, please share the ZPA Client Connector error message and the relevant posture profile configuration, with sensitive information removed.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
HP.