while I understand the traffic from Client connector to ZPA to Internal Server, can an internal resource connect to a remote endpoint as per traditional VPN Network model?
Example.
An internal support person uses RADMIN to connect to a remote user on ZPA for general support issues.
How does the support staff identify (ie DNS, IP, something else) how to connect to the remote user?