End users in SIA-only orgs or in SPA and SIA orgs are unable to access private domains.
DNS_PROBE_FINISHED_NXDOMAIN ) when attempting to access a private domain.Add a domain bypass for each of your org's private domains:
In the Cloud Secure Edge Command Center, navigate from Internet Access > Internet Threat Protection, and select the relevant ITP policy.
Select the Edit icon (i.e., the pencil icon), and under the Blocking and Bypass tab, go to the Domain Bypass toggle.
Enter the private domain(s) that you want to bypass Blocking.