Transparent authentication for PAC & Zapp

Would like to know if below configuration is achievable. We receive enquiry scenario from customer, due to their limited IT team resource they would like to deploy Zscaler without user interaction and notice.

Authentication Method : On premise Microsoft AD
Requirement :
-Hidden Zapp tray/agent
-Transparent authentication without prompt for login.
-Notified IT if user are not authenticate or uninstall the agent.

These are possible,

For authentication - you can use ADFS.
Agent customisation refer-

Appreciate the feedback and KB information. Does Zscaler have the same custom install parameter for Android and IOS?. Thanks

This may help you. [Guide] Deploy Zscaler Client Connector with Intune (iOS & Android)