Skip to main content
Solved

Deny corporate email usage with unsanctioned apps

  • July 15, 2023
  • 3 replies
  • 456 views

Forum|alt.badge.img+7

Hi Netskopers, is it possible to deny employees logging into unsanctioned apps using a corporate email account?  Can see it is possible to permit or deny other activities such as upload/download. Would like permit usage of unsanctioned apps using personal email addresses/accounts but not with corporate email addresses/accounts.

Thank you  

Best answer by sshiflett

Yes.  This is possible using constraints on activities.  As you noted, this is available on Upload, Download, as well as Logins and other activities.  You will need to figure out the sanctioned apps to allow this login and then block remaining apps via categories or app tags (I.e allow logins with corp credentials to apps with the "sanctioned" tag and block all others).  You can create a User Constraint profile with your corporate domains:

You can then create a policy that blocks any Login activities with these domains to specific apps.  In my policy below I block logins to any Webmail tagged as Unsanctioned.  You could expand this to additional categories such as Cloud Storage and others.  

 

The exact policy structure will depend heavily on how you've written policies already. 

 

  

This topic has been closed for replies.

3 replies

Forum|alt.badge.img+16
  • Netskope Employee
  • 277 replies
  • Answer
  • July 19, 2023

Yes.  This is possible using constraints on activities.  As you noted, this is available on Upload, Download, as well as Logins and other activities.  You will need to figure out the sanctioned apps to allow this login and then block remaining apps via categories or app tags (I.e allow logins with corp credentials to apps with the "sanctioned" tag and block all others).  You can create a User Constraint profile with your corporate domains:

You can then create a policy that blocks any Login activities with these domains to specific apps.  In my policy below I block logins to any Webmail tagged as Unsanctioned.  You could expand this to additional categories such as Cloud Storage and others.  

 

The exact policy structure will depend heavily on how you've written policies already. 

 

  


jwilson
Netskope Employee
  • Netskope Employee
  • 2 replies
  • July 19, 2023

Yes this is possible... didn't see Sam's reply before and I can't erase mine haha... Sam's smart, listen to him 🙂


Forum|alt.badge.img+7
  • Author
  • Explorer III
  • 13 replies
  • July 19, 2023

Excellent, thank you for the detailed response. Exactly what I was looking for!