Beta Release of the Netskope Identity Dashboard
Your one stop shop for all things Netskope Data Loss Protection.
Recently active
Background :We have Netskope SMTP DLP, Endpoint DLP, and Microsoft Exchange integrated with Netskope. Users are currently imported via Directory Importer (LDAP/AD) with a synchronization interval of 180 minutes.Use CaseWe are implementing a Leavers Email and Endpoint Monitoring Policy (Monitor/Allow mode only). When HR raises a MyAccess request, the user is automatically added to a dedicated LDAP group. The Netskope policy is configured against this group.The challenge is that policy enforcement is delayed until the next Directory Import sync, which can take up to 60 minutes. Our requirement is for the policy to become effective immediately after the user is added to the LDAP group. Options ConsideredSCIM Provisioning: We considered using SCIM to provision the specific leavers group and apply policies based on SCIM group membership. However, our understanding is that users already imported through Directory Importer should not also be provisioned through SCIM, as this could create ide
Will Endpoint DLP support Airdrop as a device control in the future?
Hello Everyone,I have a query regarding Netskope with Sensitivity Labels for Email DLP.We have integrated Netskope with the "Sensitivity Label" feature and successfully published all labels into Netskope. Using this integration, our Endpoint DLP, Cloud and Web DLP label‑based policies are working as expected.However, for SMTP Email Proxy, labeled attachments (Secret, Top Secret, Restricted) are getting bypassed. We tested multiple approaches:GUID‑based method: Extracted GUIDs from the MIP Compliance Portal and created custom regex entities (e.g., MSIP_Label_<GUID>_Name These did not trigger in SMTP DLP. Metadata extraction workaround: For Word files, we extracted metadata via File → Info → Properties → Advanced Properties → Custom and used regex ( ClassificationContentMarkingHeaderText.*Restricted This works only for Word attachments. Excel do not expose metadata in the Custom tab.its empty. Service account permissions: Assigned EXPORT role to the service account used for Sensiti
Hi all: Is anyone out there running WSL Version two and using Netskope?
We are facing one issue where users are sharing google docs from external domains eg: gmail.com to nykaa.com, and nykaa.com users are able to access the google docs or sheets on which they can paste /write the sensitive information.So how do we block this transaction with Netskope
HI Team,We are currently receiving 24-hour scheduled reports for USB activity from Netskope; however, this does not fully meet our organization’s monitoring requirements.We would like to highlight a specific requirement from our end:• Whenever USB access is granted to any user, we need the ability to capture and receive activity details immediately (near real-time or on demand).• The report/log should include:o User detailso Device informationo Type of activity (Allow/Block/Alert)o Files accessed or transferredo Accurate timestamp of the activityAt present, while these activities are visible in the Alerts/Events section, the scheduled 24-hour reports do not provide complete visibility, especially for all actions (Allow/Alert/Block) in a timely manner.Therefore, we request you to:1. Validate this requirement from a product capability standpoint.2. Confirm whether real-time or near real-time reporting/export for USB (Device Control) activity is feasible.3. Advise on any configuration cha
I am experiencing intermittent periods when I am unable to update incidents (In Progress/Resolved/False Positive) which last for hours at a time. Is it possible that another user making changes is causing this?
Hi there,Currently Netskope has a process to encrypt the forensic data collected via DLP incidents. However once encrypted this data can the only ever be accessed the netskope, which prevents legal investigations or ever migrating this data away from netskope.Therefore there should either be a way for user to bring their own keys for this encryption, so it can also be managed separately or have a break glass process so in the need of accessing outside netskope it is possible.Thanks
Hello,I'm building an internal framework for safely adopting MCP (Model Context Protocol) servers at FCBT. I came across the Netskope community articles on the MCP penetration testing methodology, the Netskope MCP Server (technology preview), and AI behavioral security — all directly relevant to what I'm scoping.A few questions on what's available in our tenant today:1. Does our current Netskope subscription include visibility into AI host traffic (Claude, Copilot, ChatGPT) and MCP server endpoints (e.g., URLs containing /mcp or /sse, domains like mcp.atlassian.com)? If yes, can you share or point me to the dashboard/report?2. Is the AI behavioral security capability (the "Invisible Insider" feature) available to us, or does it require a different SKU?3. Can our team get access to the Netskope MCP Server technology preview? I'd like to evaluate it as part of the framework.4. For the next 90 days, can you pull a report of FCBT user traffic to AI hosts and MCP endpoints — user, destinati
Dear Netskope TeamI am currently experiencing issues with Microsoft Teams calls while Netskope client is enabled. Specifically, the calls go on hold, and once I disable Netskope, the Microsoft Teams calls are fine without any issues.Could you please advise any ports needs to allow on firewall. RegardsMohammed Anwar
Hi Team,We are exploring how to enforce Data Loss Prevention (DLP) controls on the Grammarly browser extension in Chrome and Edge. While our existing DLP policy successfully restricts sensitive data uploads within the Grammarly application itself, the same restrictions are not being applied to the Grammarly extension.Thanks & RegardsManisha Joshi
Hi everyone,I’m looking for a solution to define a policy in Netskope Standard edition to give me an alert on shared folders that are unsafely shared among external and al internal users.I’ve already have a policy in place for files but I can’t find a way to define it specifically for folders. I’ll appreciate it if anyone has a comment on the solution.
We tried with Iban (ALL) option but didn’t worked So Please provide an appropriate solution for this
We see a discrepancy in file names being visible in DLP incidents. Currently we have a DLP policy to detect exfiltration of sensitive information using file converter tools. While we are getting the file information using forensics for https://www.sejda.com/, the same is not happening for ilovepdf and ilovepdf only captures “blob” as an object and does not show any information. Is this a known limitation?
Are only predefined Profiles are Working? If Any Regex is there Kindly Provide!
This feature is available in realtime protection. Can we make this expiration feature available in USB DLP as well so we dont need to manage removing the exemptions manually?
I am writing to inquire about the current roadmap and support for Manus AI within the Netskope NewEdge network. As Manus AI gains traction as a powerful general-purpose AI agent, our organization needs to ensure robust data protection and visibility over the sensitive information being shared with this platform.1. Current Status Inquiry: Does Netskope currently have a functional Cloud App Connector for Manus AI? Specifically, are the activities (such as "Post" or "Upload") already being indexed in the CCI (Cloud Confidence Index)?2. Development Suggestion (DLP Integration): If full support is not yet available, I would like to suggest the development of specific DLP controls for Manus AI, focusing on: Prompt Protection: Real-time inspection of text inputs to prevent the leakage of PII, PHI, or source code. File Transfer Control: Monitoring and blocking sensitive documents uploaded to the Manus AI interface. Activity Monitoring: Granular visibility into user sessions to distinguish
User case : Git Pull/Push basic commands does not work and throws connection timeout error when i enable NPA and even i have whitelisted git hub web site with ports 22,443 but when i disable NPA and use AOVPN it works . so need some advice ?Note: even i have enabled virtio proxy enabled at wsl setting but no luck
Ref Link Quarterly Product Release Webinar – December 2025 | Community
Dear Team, We have implemented a policy to block the sharing of source code when a user attempts to send it via file attachments (such as TXT, PDF, DOC, etc.) to personal email domains like @gmail.com. The policy is working as expected when the source code is shared directly as plain text within the email or message body. However, when the same source code is included inside a file attachment and sent, the policy does not trigger. We have already raised this concern with the Netskope Support team, and the response received was that this use case is not supported. However, we request you to please re-check and confirm if there is any possible way to achieve this requirement. Note:We are able to block uploads entirely, but our specific requirement is to block the transfer only when the to_user does not belong to the corporate domain. We request you to please help us understand why this behaviour is occurring and assist in resolving the issue, as this use case is critical and needs to be
Netskope Microsoft Purview Integration with AI AgentsOverviewThis solution implements an integration with Netskope and Microsoft Purview for DLP enforcement and uses an AI Agent in Security Copilot to ask questions about the policies on both systems and about any alerts that might be happening. The Netskope One for Microsoft Purview DLP setup is documented here https://docs.netskope.com/en/netskope-one-for-microsoft-purview-dlpI will be covering the Microsoft side and how the two work together. There is one thing to note on the Purview DLP integration. You will see in that documentation that Entra ID user provisioning within Netskope is a prerequisite. When setting up you create an Enterprise Application in Entra. The application you set up is touched again in the Purview setup in step 5 where you will need to re-grant permissions.PrerequisitesNetskope tenant account Microsoft Purview Microsoft E5 licenseArchitecture FlowVia Netskope policy, web traffic will be sent to Microsoft Purvi
Hello,I have a DLP policy that blocks the upload of unlabeled documents. The issue I’m facing is that when I try to upload a PPTX file that is labeled with Microsoft Purview Information Protection (MPIP), the upload is blocked by this policy.It’s important to note that not all PPTX files are blocked—only some of them.What I’ve noticed is that, for the blocked files, the “True file type” is detected as “ZIP archive.” In contrast, for files where the label is recognized and the upload is allowed, the “True file type” is shown as “Microsoft PowerPoint 2007 XML.”Has anyone encountered this problem before? Your help would be very much appreciated.Thanks,
Here's an article for Netskope on blocking Base64 encoded sensitive data using custom regex, along with the step-by-step DLP policy creation process. Blocking Base64 Encoded Sensitive Data with Netskope DLP: A Step-by-Step Guide In today's cloud-centric world, organizations face the persistent challenge of preventing sensitive data from leaving their control. While traditional DLP solutions are effective against clear-text data, a common evasion technique involves encoding sensitive information, particularly using Base64, to bypass detection. This article will demonstrate how Netskope's powerful DLP capabilities, combined with custom regular expressions, can effectively block the sharing of sensitive data transformed into Base64 encoded strings.The Challenge: Evading DLP with Base64 EncodingBase64 encoding is a method of representing binary data in an ASCII string format. While legitimate for many purposes, it can be misused to obscure sensitive information like credit card numbers, so
Hi Team, Wanted to know if we can restrict the USB file transfer to USB devices via EDLP? Use case- If a user attempts to transfer a file larger than 100MB, the action should be blocked. Thanks
What's the best way to create a DLP Rule that looks for Email Addresses (using the Built In Netskope Email pattern) but not generate hits on our company domain ie @company.com.I was trying to make a custom Entity and then use a not clause in the DLP Rule but not sure if that will give us the behavior I was looking for.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.