Skip to main content

AD_4nXc_dBkasEpWFP5Lxg6IHVYvlDi4F7IcAFURC3khP7qtaAPAAy_8__ln6zFIoidAFa0f1XjxFEh8yNl2KByEiuvYY61H46XZ7SE_0EdNApdENWBeI0Gmx3iGqHkCp2ODQD0ZPTknegWnDS8tVXyYyTsI5Qz1?key=IIdImRxYEB-7lfdr14uHDg

Netskope Global Technical Success (GTS)

Use Case - Allow AWS Management Console access - Corporate Instances

 

Netskope Cloud Version - 121

 

Objective

Allow access only to corporate instances when accessing AWS Management Console

 

Prerequisite

Netskope CASB Inline license is required

 

Context

The customer wants to ensure that only corporate users can access the AWS Management Console.

 

Configuration

There are two ways to achieve this use case:

 

  1. Method 1: Using App Instance ID
  2. Method 2: Using User Constraint

 

Method 1 - Using App Instance ID: 

  • Step 1: Instance Tagging

You can refer to this document for detailed instructions on how to tag application instances: https://community.netskope.com/real-time-protection-key-policies-72/how-to-tag-application-instances-6275?tid=6275&fid=72

Path - Netskope Tenant UI >>> Policies >>> Profiles - - - App Instance >>> New Custom App Instance >>> New App Instance

AD_4nXcpKceCRgm2WO28lE2_B5CxrkCl_oXR00e5JtoTOgwqx-zh5XUVOfInGYzUV-emYOFElcFATeLIP203fv5KBDWVeek89sLuEXKCVOns2WJBiplR3W1lVV6sx1_OGrIOuvxofNGgRqfkffouXfWxtsNPkJ0?key=IIdImRxYEB-7lfdr14uHDg

Note - Netskope enables administrators to name application instances using Application Events.

  • Step 2: Real-time policies

 

First, create a policy allowing access to your corporate instance:

 

AD_4nXcnP2HYd_C5Kt5jIq5LFvR3FGhmLZ3fPoUYU-Cvagli9HflRasrqTaJ-z6ruPmPsBGMIpNjuEtgfKzegQu4GlOqTtx0uUiMGNaIzG181UZqiTt4ecnJxnS73f6JZAPlDBcooBcB_VBgPmqsPpE3-4g81LoZ?key=IIdImRxYEB-7lfdr14uHDg

 

Then create a second policy blocking “Login Successful” activity for Amazon Web Services Console app:

 

AD_4nXdUGqkWe6He426CDSoZs0mIdsN1zz88YyqSYO9u9_1e9sjl3Db5qV45g8Bj8T6a7fG0v6SND7ebsKZFXV0bK0Be3LfvD6DrHUlCTpF0Zbn9nyRmEn73x4lhtK213UOBZ1oNJCgt9wuiNoRSI1a7GiXJZ9tg?key=IIdImRxYEB-7lfdr14uHDg

 

Please, make sure your policies are as follows:

 

AD_4nXenqwcn1N7AVc45R7USOUZBLMS657taPWmeLsD7e6R65ibKZzsRYtKv7sjNLX14GBCmm0JEFs5b-PvfVYPEYbgVt-qi1Kwdhv-QHJvQRkQqd7k42a_0dycgaszPTdezDcyyASJXF8zzYWh7FdcsTat5OIUv?key=IIdImRxYEB-7lfdr14uHDg



 

  • Step 3: Test your configuration by trying to log in to the AWS management console using your corporate credentials, and you should be able to do it. Then try to log in using different credentials, and you should be blocked.


 

Method 2 - Using User Constraint:

There is another way to apply the use case, which is through the use of User Constraint. 

 

To create the user constraint please go to Policies >>>  Profiles >>>  Constraint >>>  Users and create a new one. 

 

For the use case to apply only to allow corporate accounts, use the following configuration (please change the netskope domain with your corporate domain).

 

AD_4nXdkS-cGDdxZjmWCApxTbR2sVrFmw1sETs32yNDIMqLF2Bg1_DKM-m2zW6q_co0qnlbezNumsvXeEbHb9O4SaakfcdkuIRsMQbsGozwuQ22aX8mCdJtDNJBqcu3UH2OKrhh5BzPtVTs_1LY1Peox3d2pS64n?key=IIdImRxYEB-7lfdr14uHDg

 

After this, assign the user constraint to a single policy blocking access. This will ensure that only accounts that are corporate can log into the AWS console.

 

AD_4nXeX6KWmCySzu1xYo0WcuZLvKKsRpNwNVAxlWaUhspJ6zXsnsPbvuRcUetmtXYF9DE_X8XCPL1PpYKj2ohk_mM0MLKEEjBu1GmvKMBp8S540AfoNSdtX-1namO3_psV5NJ8ISnfGnMyatn9tykHkm2786hXd?key=IIdImRxYEB-7lfdr14uHDg

  • Policy Configuration:

 

AD_4nXerP_qej2CW6rh48ODMW-nenb1IaTioTweIPPAyyyEdy6M1ChgPKWQp9_LB0ST01FxE1PBs_Vyrk8P6Iwc1akrwM6y8th5eSvBl9vPHlljO6juq20GLTUbmEqpws2qOfmEb1a1SVIxBfhhaooMYU3rcZ64?key=IIdImRxYEB-7lfdr14uHDg

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

Be the first to reply!