Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Your one stop shop for all things Netskope Data Loss Protection.
Recently active
I have been tasked with allowing our user population to have access to the Generative AI category while also protecting the company and our patients by preventing uploads of any files with PHI in them to anything other than our internal instance of Copilot.I have created Realtime policies that I believe achieve this goal, but I have encountered an issue where certain AI sites do not upload the file in a format which Netskope can see into. Specifically, Grok uploads files as a blob while Quillbot and Heidi Health AI upload the file in blob, json or webm formats.Is there a way for Netskope to be able to view these file uploads and apply our PHI profiles to the upload? I have not seen any documentation which addresses this, and I am curious if anyone else in the community is running into a similar problem.
ObjectiveHighlight the outcome that improvements to international predefined entities are part of Netskope’s long-term roadmapNetskope existing detection mostly relies on a third-party entity. PrerequisiteThis issue generally applies to all Netskope Standard and Professional DLP modules, including, but not limited to, NGSWG DLP, Email DLP, Endpoint DLP, and more. ContextCustomers can test pre-defined identifiers in their own languages, particularly in non-English regions, to verify whether they function correctly. They may only trigger the sample data demonstrated in the UI, so using a variety of real-life samples is highly recommended for more accurate verification. Do You Know?Non-numerical identifiers such as addresses, names, or terms are likely to bypass Netskope’s DLP detection mechanism without triggering alerts or appearing in DLP incidents. This means the administrator will be unable to track or investigate the data leakage incident. NotesWe’ve discovered that others have alre
How can I change the Status for more then 100 incidents at a time, which is the dashboard limit? I have thousands of incidents created from a retro-active scan and would like to add my own custom status to them all at once.
ObjectiveThe combination of English characters and other special characters is treated as a single word. Netskope Regex does not support detection when English characters are combined with uncommon symbols, even underscore, and the specification of Netskope Regex rules remains unclear. PrerequisiteThis issue generally applies to all Netskope Standard and Professional DLP modules, including, but not limited to, NGSWG DLP, Email DLP, Endpoint DLP, and more. ContextCustomers can validate this issue by adding an underscore (“_”) or random characters after the English keyword they want to detect, as demonstrated below. Do You Know?Users can easily bypass Netskope’s DLP detection mechanism without even decomposing the keywords. This means administrators will be unable to track or investigate potential data leakage incidents.We have requested clearer instructions on how Netskope defines Regex rules, but so far nothing has been provided. NotesWe’ve discovered that others have already raised si
From this article, it mentions the feature flag Netskope Entity Modifier. Could you clarify the difference in behavior before and after it is enabled?Note:Can we suggest allowing a longer period for comments on articles? Otherwise, we have to create a new article just to ask follow-up questions.
I used the locally installed Postman application to send API POST requests with test data to evaluate whether Netskope could detect them. While SkopeIT is logging the events, the policy doesn't seem to be triggering, and I’m unable to view the actual data being transmitted in the API request. Has anyone encountered this issue or have insights on what might be going wrong?
Netskope Global Technical Success (GTS)Netskope DLP – Step-by-Step Beginner’s GuideNetskope Cloud Version - 127IntroductionThis article provides a high-level overview of how Data Loss Prevention (DLP) is configured and enforced in the Netskope platform. It is designed for administrators and security professionals who are implementing Netskope DLP for the first time or need a structured refresher.Netskope’s DLP framework is modular — built from several dependent components that must be configured in the correct sequence. This guide outlines those components, their roles, and the logical flow of implementation. Key Components of Netskope DLPThe DLP framework in Netskope consists of the following core building blocks: Component Description Entities Define the actual content to detect (e.g., credit card numbers, project names, customer data) DLP Rules Contain detection logic using Entities and scanning behavior DLP Profiles Group one o
Netskope Global Technical Success (GTS)Netskope DLP – Enforcing Netskope DLP Policies Netskope Cloud Version - 127IntroductionThis article explains how to create and apply DLP Policies in Netskope.DLP Policies represent the final enforcement layer — they determine where DLP scanning occurs, who is impacted, and what action is taken when sensitive data is detected.Policies are where DLP Profiles meet real-world enforcement across cloud apps, web traffic, private applications, and endpoint activity. What is a DLP Policy?A DLP Policy defines:Which DLP Profile is applied Which users, groups, or locations are affected Which traffic channels or applications are inspected What action is taken on policy violations (e.g., Alert, Block, Bypass, Coach) It is the final step in operationalizing your DLP setup. Key Policy Configuration Options Section What is it? Why does it matter? Exampl
Netskope Global Technical Success (GTS)Netskope DLP – Designing DLP Profiles and File Filters in NetskopeNetskope Cloud Version - 127 IntroductionThis article explains how to create and use DLP Profiles in Netskope.A DLP Profile is a container that brings together one or more DLP Rules and applies additional filters and classifications, including file types and size-based criteria.This step is essential for organizing DLP logic and optimizing what kinds of files and content are inspected in various use cases. What is a DLP Profile?A DLP Profile combines:One or more DLP Rules (the detection logic) A File Profile (filters files by type, size, and extension)Profiles allow you to group rules by business purpose or regulatory need, then apply them selectively using DLP Policies. Core Components of a DLP Profile1. File Profile (Filtering by File Types and Sizes) What is it? Why it matters Example Use Case Defines filters to include or exclude files based on MIME t
Netskope Global Technical Success (GTS)Netskope DLP – Building Effective DLP Rules in NetskopeNetskope Cloud Version - 127IntroductionThis article explains how to create and configure DLP Rules in Netskope.providesDLP Rules define how sensitive data is detected based on previously created Entities, and control the conditions, logic, and severity under which detections are triggered.Rules form the heart of Netskope DLP — without them, Entities alone cannot inspect or enforce anything.This document breaks down each part of a DLP Rule, with configuration guidance, use cases, and practical examples. What is a DLP Rule?A DLP Rule connects one or more Entities to a specific set of detection behaviors. It defines how data is matched, where it is inspected (content vs metadata), how many matches are required to trigger detection, and what severity should be assigned.Rules are then added into DLP Profiles, which are later applied to traffic via DLP Policies. Core Components of a DLP Rule1. Ent
Netskope Global Technical Success (GTS)Netskope DLP – Creating and Using DLP Entities in NetskopeNetskope Cloud Version - 127IntroductionThis article explains how to create and use DLP Entities in Netskope.Entities are the foundation of the DLP engine — they define what kind of data is considered sensitive and must be detected and protected.Entities can be predefined or custom-built, depending on the sensitivity and uniqueness of your data.This guide will cover:The types of DLP Entities When and why to use them Practical examples and configuration steps What is a DLP Entity?A DLP Entity in Netskope is a reusable object that describes specific data patterns or terms that the system should detect during policy enforcement.Entities are used within DLP Rules to specify the nature of the sensitive data — such as PII, PCI, financial data, or confidential terms. Types of Entities in Netskope Entity Type Description When to Use Examples Best Practices
ObjectiveHighlight the outcome that Netskope does not re-examine files with the same MD5 hash permanently. PrerequisiteThis issue generally applies to all Netskope Standard and Professional DLP modules, including, but not limited to, NGSWG DLP, Email DLP, Endpoint DLP, and more. ContextCustomers can initially upload a file that contains no detectable data identifiers. Later, they may modify only the file name to include sensitive keywords. As a result, they can bypass Netskope’s DLP detection mechanism, potentially leaking sensitive information through the file name alone. Do You Know?If the administrator has not changed the DLP policies that should have been triggered, such data leakage will not generate any forensic records or DLP violation alerts. This means the administrator will be unable to track or investigate the data leakage incident. NotesWe’ve discovered that others have already raised similar concerns. I encourage you to vote for this feature as well, as this design issue d
At least two years ago, users were already raising similar concerns to the ones we are now requesting.However, in the App Catalog (CCI), Google Docs still only shows “discovery only” support. Google Slides and Google Sheets are not even listed in the catalog at this moment. I sincerely believe that Google Workspace is one of the most popular enterprise ready SaaS suites.I’m genuinely curious about your thoughts on this and how your companies currently monitors or regulates user activity within Google Workspace.If you agree, let’s vote together for this feature request.
Since deploying the latest golden release of the NS client (v126.0.0.2387) the Last Event field for all systems shows 55 years ago. Is this going to be fixed?
We have created a policy for USB content control with size limit 50 mb.Issue faced here is if i share file of 40 MB and another of 15 mb it get shared.Use case is we want to restrict complete data transfer over 50 mb not file size The file size limitation is enforced per file, not per session. What we are observing is the expected behavior by design. If your expectation is for Netskope to track the cumulative file size uploaded within a session , for example, a user uploads a 40 MB file at 10:00 AM and then another 15 MB file 15 seconds later, totaling over 50 MB , this functionality is currently not supported.
As a customer facing company, we regularly receive booking-related emails from customers and partners that contain Personally Identifiable Information (PII) such as passport numbers, ID documents, and travel itineraries. To prevent external data leakage, we’ve implemented Netskope DLP to monitor outgoing emails for PII. However, we’re facing a challenge: When our employees reply to incoming emails (even without including any PII in their response), Netskope DLP still quarantines those replies. This is because it detects the original PII from the customer’s message in the reply thread. We want to understand if there’s a way to configure DLP policies so that it only quarantines emails that are originated internally and contain PII, and not block replies to incoming messages that happen to include previously received PII. Is there a solution or best practice to achieve this behavior?
I understand that Netskope’s DLP supports multiple languages and offers high detection accuracy. Could you please share whether the keyword matching inspection is performed using external libraries, or if Netskope uses an in-house developed engine?If external libraries are being used, would it be possible for you to disclose information about them?I am particularly interested in how Netskope has addressed challenges such as multilingual support and detecting word boundaries accurately.
When creating a policy to detect email addresses, I used the following regular expression:[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}However, the string "csv test" triggered a detection, even though it does not contain an "@" symbol and therefore should not match the expression above.Is there any limitation or specific behavior in how regular expressions are interpreted on the Netskope side that might explain this?
Hi, Some customers asked about DLP support for Claude.AI and Perplexity.AI.They are on the roadmap? If so, there’s any estimate on when will it be available? Regards,Rodrigo Borges
What is the definition of "Formpost," which is one of the activity types?
Anyone concerns about Email draft can not be detected by Netskope?On App Catalog it says “Create, Edit, Post, Send” support DLP.On the Application Events, ObjectID can successfully be fetched and we also can clearly saw the activities and content through DevTools.However, DLP policy is not triggered but the action is recorded.We also created a support case on this but L3 support responded and claimed it should be related to SMTP DLP module. We are curious if anyone else has encountered this and have similar concern as we do.
Are there any planned integrations with Cyera for data classification label usage in DLP policies?Does anyone have experience with this product and use case?Thanks
Is it possible to create a dashboard representing what actions an analyst has taken on a DLP “file” incident?The analyst can “Change File Permissions” with a dropdown of actions and/or “Contact Users”.Our analysts don’t assign the incidents or resolve them they just take actions since we use a separate case management system. I’d like to report on actions taken and the incidents/files that were associated to the action.
When we first evaluated Netskope, visibility into non-org accounts within the Outlook desktop application was a known gap due to the application being certificate pinned. I recall that other vendors we evaluated were able to enforce DLP controls on other Outlook accounts, but these vendors often excelled in Endpoint DLP and leveraged more “legacy” approaches as opposed to Netskope’s reliance on the forward proxy.We currently block non-org accounts in the Outlook desktop app, but the allowance of client accounts within Outlook is a frequent request from our team users. With Netskope’s newer ventures into the Endpoint DLP space, are there any new or future-anticipated abilities to enforce DLP controls over these Outlook accounts/other certificate-pinned applications?
Hello all,I’m looking for recommendations/examples of global default DLP policies.Currently, my organization has a default block policy at the bottom of the tenant for categories that we’ve deemed to have no business use case (weapons, security risk, etc) or to be risky for usage (cloud storage, social media, etc.).In a similar fashion, I’d like to have DLP rules at the bottom of the tenant to act on web traffic before Netskope allows it through. I’ve done some testing with just outright blocking any activities that could be used to exfil data (upload, post, send, edit, etc.) and very quickly ran into issues, and example being background traffic for the Microsoft Edge browser being classified as upload and resulting in a large number of user notifications. I’m currently working through using app tagging to exclude any standard user applications from this policy.Given that not all websites have support for DLP, I’d ultimately like the behavior to be “If the website supports DLP, check t
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.