Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Your one stop shop for all things Netskope Data Loss Protection.
Recently active
I have a few questions related to Netksope MIP integration. I looked around but did not get any concrete answers. Does Netskope require the customer to provision an Azure subscription or similar services when applying MIP labels to OneDrive files? From what i understand , we only need the M365 licence ? Is the timestamp of a OneDrive file altered when Netskope applies a label? - This is important for our org to ensure that we dont modify the file timestamp. Is Netskope's file labeling service charged separately, or is it included with the standard Office 365 protection license? - I'm guessing there is no extra charge. Are there any restrictions on the number of files that can be labeled within a specific period by Netskope? - This is something our security team is asking and would love to know if there are any known limitations
We have been unable to deploy Endpoint DLP. Having the same issues with different versions and the newest 1408. A good number of Managed devices on reboot disable the usb devices like mouse, keyboard, and printers. Has anyone been able to successfully deploy Endpoint DLP protection?I currently don't have any device control policies but do have quite a few Content Control policies.Any help would be appreciated.
I have few alerts triggered for the policy that I have created for DLP related policy when user post on ChatGPT.However, I am unable to know the exact reason why the alert was flagged. Also, I cannot view the content/part of the content of the post that was considered as a DLP violation. How and where can I view these details? Regards,Thomas
Netskope's real-time protection provides a plethora of access-controls to enforce data security. Starting from R96, Netskope has standardized the function of "Alert and Continue policy evaluation" on all tenants. This feature would allow Netskope Cloud to continue evaluating Real-time policies for additional DLP violations, instead of terminating and exiting policy evaluation after a match. This function would help influence the sequential processing of real-time protection policies based on specific configuration and thereby evaluating & matching against multiple DLP profiles and rules.Refer to the PDF document to know more about the policy flows and behavior. https://docs.netskope.com/en/netskope-help/netskope-release-notes/netskope-cloud-release-notes/netskope-release-notes-hotfix-version-96-1-0/new-features-and-enhancements-in-hotfix-release-96-1-0/#UUID-76b0e39c-45b3-eb8c-0049-b6222ae411e5_section-idm4583494220057633155495922816 Document Authors - @vramnarayan &a
Hi Team I want to ask some Netskope question I just checked one configuration of Netskope SMTP proxy where we can see there are two connector connector 1 office 365 to partner and the second connector from your organization to O365. So why we required your organization in second connector. Also from MS team when they are tried to select Your organization they get and error of licensing but same licensing part is working for another please let us know.
Hi Community Team, A DLP policy with PCI-DSS profile is placed as top-rule to identify sensitive information in upload & download activities. It is working as expected only with DOCX files. This policy is not working with CSV, TXT, JPG & PNG files. When uploading CSV/TXT files, the policy is not even being hit. I would like enquire with Netskope community if anyone has noticed such issue and how they fixed it. Thanks.
Hi Community Team,Working Scenario: When we upload or download sensitive data (Credit card, CVV & email) with TXT, CSV & DOCX files to Facebook & LinkedIn, then Netskope DLP is alerting fine with PCI-DSS, DLP-PCI & DLP-PII profiles.Working Scenario: when we type & send sensitive data (Credit card, CVV & email) in LinkedIn Messages, then that message is being alerted (fine). LinkedIn Message DLP alert is showing Activity as POST and Object type as Message.Failed: However, When we type & send sensitive data (Credit card, CVV & email) in Facebook Messages, then it is not being blocked or alerted. We are expecting the action to be POST and activity should be Message or anything. However, Facebook Message sensitive data share action is not visible in Application Events, Alerts and Page Events.Below screenshot is the policy. Has anyone noticed this issue? If yes, please suggest the fix.Thanks.
Did you know that you can use Netskope DLP Incident dashboard to manage up to 100 Incidents at a time? -Incident Dashboard allows you to use SkopeIT query to find Incidents by status or date range or severity or even incident number. (Sample query at the bottom of this page) -You can change status of all incidents displayed on the page at once (You can expand page size to up to 100 per page from the drop down at the bottom right of the dashboard) Steps to find and resolve multiple incidents: 1. In the incident dashboard menu click the "Filter Search" funnel icon. (this icon switches between normal and query mode) 2. Enter a query using the "in" operator as shown for 2 incidents below. You can also add a custom status for filter e.g. if you want to omit incidents with status 'Resolved - Policy Updated' from the search. Note that incident numbers are included in single quote separated by comma) SkopeIT query: (dlp_incident_id in ['863060765611108610','82034833
Hi Netskope Community,We are following below admin guide & KB (both are same) for configuring Netskope SMTP proxy with MS O365 exchange.https://support.netskope.com/s/article/Configure-Netskope-SMTP-Proxy-with-Microsoft-O365-Exchangehttps://docs.netskope.com/en/configure-netskope-smtp-proxy-with-microsoft-o365-exchange.htmlWe encountered a backend error and see the attachment for error message screenshot.1. Has anyone encountered the same issue?2. What is the root casue for this issue?3. What is the fix to get rid of the error message?Thanks & Regards,Indu
Hello All,I'm hoping someone can help me. I am just trying to find out if Netskope has a language pack (Spanish, French, etc...) or the capability to detect DLP incidents in various languages, similar to how Symantec/Broadcom can. If so, can someone point me in the right direction of the setting in the tool? If not, can someone tell me if this capability is on the Netskope roadmap for the future? Thanks in advance!
Hello everyone, My organization currently uses MIP to manually apply labels to Office files. We are looking to start using Netskope API Data Protection to automatically apply labels to files in SharePoint that contain sensitive data but I have a couple challenges I am not sure how to handle. 1. Microsoft Information Protection by default will not override any manual labels applied or override any label with a higher priority. We would like to keep this capability when using Netskope to apply labels but I cannot find any way to accomplish this. 2. We would like to build automated workflows to notify users when a file they own has had it's label upgraded because it contains sensitive data. This works great the first time the label is applied but a DLP alert will occur every single time the file is edited even if the file already has the upgraded label. I think a potential solution to challenge 1 would be to look for the manual label attribute in the files
Context: You have some users uploading sensitive data to Github. These smart users are avoiding detection by using non-text formats e.g. XLSX or docx. How to get alerted for binary commits on Github? Solution: Netskope next-gen Github API can detect and alert when a binary file is committed to Github. Create a very simple DLP rule that detects keywords for "Binary files". Call that into a profile and a Github ongoing policy. That's all that is needed. Here are the required screenshots showing how to create a DLP rule using custom entity with case insensitive keyword.
As the AI wars heat up, Google is stepping up its game against OpenAI with the release of Bard. Google originally (early 2023) made it difficult for the average user to play around with Bard by introducing an invitation based system resulting in waitlists, again this was earlier this year when ChatGPT rocketed into the mainstream consciousness, but as it stands today, most, if not all Google account holders can access, play around, I mean, leverage Google Bard. What are the risks involved for enterprises ? The reality is that it's not any different than the risk of using an unsanctioned app. I mean data exfiltration capabilities, privacy issues et al, makes Google Bard a veritable minefield for every security organization. Google explicitly advertises Bard as way to make life simpler for software devs. This is the biggest risk I see for most enterprises when it comes to Bard and other similar platforms. The risk of devs copy/pasting sensitive code for debugging, and/or un
Is it possible to create a policy to block whatsapp .exe download?I created but I didn't succeed in the test.
Hello All, Looking for some help !! If we need to manage the traffic of unmanaged Devices like personal laptop , Tablets and mobile the usual proposed methodology is Reverse Proxy integration to map the control, But i wanted to check on the below mentioned point. If we have user authentication mapped with the Netskope proxy and user when logging in via personal devices and getting authenticated via Netskope Proxy in this case do we require the reverse proxy integration? Thanks in advance for your help !! Thanks & Regards Amar
Is there the possibility of integrating IRM with Netskope and being able to restrict what types of documents can be sent through WhatsApp according to their label? I saw in the official documentation that Netskope supports the following cloud apps with MIP:Box, OneDrive, SharePoint, Google Drive. Thanks in advance for your help in this matter.
As a security architect or as a Netskope admin it is sometimes tempting to configure controls that are too broad. Especially when a tool's UI makes it easy for you to do so.:) Think of the implications of broader controls from an operations point of view. Think of some of the side effects: false positives, missed true positives, barge of DLP incidents in your queue to name few. A seasoned DLP admin would share stories of painstaking tasks of managing those incidents, storing chain of custodies using Legal Hold and Forensic folders, determining the right storage of choice and then the cost associated with it just storing files and meta data that may or may not make sense without a good DLP program in place. Here are some questions you might want to ask your DLP / Compliance team / or the sponsor of DLP program to get a discussion started on this topic: It allows me to apply DLP to "All Web Categories", should I go ahead and create such a broad DLP policy though? Answers to the questio
Single Sing On - SSO Tenant UI with SAML Azure-AD Hello community Netskope, good afternoon. As always thanks for the support and collaboration. I have the following problem, I am configuring SSO for Netskope Tenant UI, to use Azure-AD credentials from Office 365. Guided by this Doc/Links:https://docs.netskope.com/en/netskope-sso-with-azure-ad.htmlConfigure an Enterprise Application in Microsoft Azure Active Directory using SAMLConfigure SSO Settings in the Netskope UIAdd Azure Active Directory Users to the Defined Application and Assign RolesDefine Custom Roles for Azure Active Directory Enterprise ApplicationNow I configure everything, everything seems to be OK, but I get the following error when trying to login to the Tenant: - "We seem to have hit a problem.Error Code: General ErrorError: Failed to get SAML IdP Certificate!"- - Is this something related to the Partner Tenant we have ? any particular step ? If I go to the Seetings- Administration -
anyone else having issues or have a solution for E911 and compliance with the below requirements. https://www.fcc.gov/911-dispatchable-location
Total integrations with Office 365 / Azure AD / Sharepoint / Outlook / OneDriveHi good afternoon, first of all thanks for the time and for the collaboration. I am interested in knowing which one(s) are All possible integrations with Office 365 environments, example: -Provisioning Users/Groups ? -Security Outgoing/Incoming Mail ? From Outlook web and from the desktop APP andand Mobile/Smartphone clients ? -Filtering for Onedrive desktop Apps and web access ? -Filtering for Sharepoint ( Desktop Apps and web access ? ) What are the minimum requirements to achieve this? At the level of licenses of office 365 ? Azure AD ? At the level of services ? prerequisites ? requirements etc ? Scope, Limitations, to what extent you can filter, advantages and disadvantages ? Thanks in advance for your time, support and collaboration. I remain attentive Best regards
Overview Cloud Exchange CLS’s Syslog forwarding gives you the ability to send Netskope Event, Alert, and WebTx messages to any Syslog server. Using the Microsoft Incoming Webhook application from the Admin center Cloud Exchange will send messages to a configured Teams channel to notify you when an Alert was seen from Netskope. Requirements CloudExchange 3.3.3 or newer Basic Cloud Exchange setup (Netskope tenant API v1 and v2 setup) Netskope plug - Netskope CLS Any Syslog server Syslog Server For testing and writing this document, I am running a Ubuntu 20 LTS Compute Engine on GCP with Docker and Graylog running in a container. Leave a comment if you would like me to write up that setup. Verify url/ip and port of your Syslog server In Graylog you can see the input port by going to System > Inputs Netskope Cloud Exchange setup steps Cloud Exchange Plugins On your Netskope Cloud Exchange go to Settings > Plugins You will need two plugins configured for this solu
Overview Cloud Exchange CLS’s Syslog forwarding gives you the ability to send Netskope Event, Alert, and WebTx messages to any Syslog server. Using the Microsoft Incoming Webhook application from the Admin center Cloud Exchange will send messages to a configured Teams channel to notify you when an Alert was seen from Netskope. Requirements CloudExchange 4.2 or newer Basic Cloud Exchange setup (Netskope tenant API v1 and v2 setup) Netskope plug - Netskope CLS Any Syslog server Syslog Server For testing and writing this document, I am running a Ubuntu 20 LTS Compute Engine on GCP with Docker and Graylog running in a container. Leave a comment if you would like me to write up that setup. Verify url/ip and port of your Syslog server In Graylog you can see the input port by going to System > Inputs Netskope Cloud Exchange setup steps Cloud Exchange Plugins On your Netskope Cloud Exchange go to Settings > Plugins You will need two plugins configured f
Created a File Profile with a File Name (exclude.xlsx) and applied into a DLP Profile (tried with Match and Does not Match). When I running tests, none of them are working (not checking the exclude.xlsx file with the matching profile // not excluding the exclude.xlsx file).Can you please advise?Thanks
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.