zScaler Client [macOS] certificate identity popup

Hi all,
Maybe one can help me out here. I’m managing a fleet of macOS devices and the global VPN policy is using zScaler.
I’m up to date to version

Everytime a user logs out, and during the login after entering the Microsoft Azure password zScaler asks for a certificate identity. This can’t be skipped and for lots of users I need to remotely login and use administrator credentials to set the certificate.

I don’t know which certificate, I’ve tried the zScaler root CA, and a /Client certificate from zScaler as well, but the popup keeps coming up and I can’t choose the certificates.

It doesn’t matter which certificate I choose, it does work.
According to the admin there is no TLS/SSL inspection active.

Kind regards!