Skip to main content

Can we use Netskope NPA to enforce all user sessions to authenticate to all private applications using MFA (using our organization’s IdP)? Let’s say some of our internal applications do not support SSO and we wanted to use NPA to force users to authenticate using MFA (just for those apps that do not support SSO) How can we do that? 

Can we use Netskope SWG/CASB to do the same for external cloud/SaaS/web applications? In other words, enforce MFA (through our IdP) when those applications are not able to directly support our SSO?

Any ideas on how to make this happen with Netskope NPA and SWG/CASB?

 

Thanks!

You can use step-up authentication with CASB, but not for NPA:

https://docs.netskope.com/en/apply-policies-to-enforce-step-up-authentication-as-required

 

NPA can do periodic reauthentication, but not selectively:

https://docs.netskope.com/en/use-client-re-authentication