Skip to main content

AD_4nXdSG30mat3MUPC0d8P9lxrIT97Aka1Bd3Wqg7wJja2uvkCK7IglbNc8aI5n21YRjrwUmFXEGea9GUr4lKT8HVADnt8fXuJW2QVQ7D6ZNC2FTnwgq1nMlEYdiPUef8osVNop2Qb0OA?key=BOYKzYgq4pgYW7yZbyxiuobX

Netskope Global Technical Success (GTS)

Permit Authorized Webmail Instances While Restricting Access to All Un-authorized Webmail Platforms 

 

Netskope Cloud Version - 123

 

Objective

This document is intended to describe several ways to create a policy to permit authorized webmail instances while restricting access to all unauthorized webmail platforms

 

Prerequisite

Netskope SWG/CASB Inline license is required

 

Context

Allowing only sanctioned webmail enhances security, prevents data leaks, reduces phishing risks, ensures compliance, and improves IT visibility and control.This document is meant to guide customers on their adoption journey to understand the steps for creating policy to achieve this use case.

 

Lab Recreate

  • For demonstration purposes, we will consider “Google gmail” as a sanctioned webmail platform. 

The document comprises of steps to -

  • Allow logins to corporate instances of Google gmail
  • Block logins to all non corporate Google gmail instances
  • Block all other webmail platforms

 

Step 1 : Allow logins to corporate instance of Google gmail

Start with tagging corporate and non corporate instances of application. Use the document here as a reference : Link

 

Path: Netskope Tenant UI >>> Policies >>> Real time protection – New policy – Cloud App access

AD_4nXeMEC83Rq5UOY7Mn9YvxPPylM8cmrtBjU5SmNNX0vp2Qaa2OEqUaW3E_DikkpwOkPSqOC4647rn1h36gjra6FizZ2utQErve4sc3WlJ548UoMn1SQ7zMScuON-fccN6DAalh6jr?key=BOYKzYgq4pgYW7yZbyxiuobX

 

Step 2 : Block non corporate instances 

AD_4nXfnkrGXPsuB5dj54N9mm_TM2TXI1jatwQAdepfWq3bYs2wZuxqmNndtQ4eYYxnNi4bw7LfXv5O7TGPBhjK6tPM1f_u1zAnmUxX7we1vOt2FizQFTC7IQoDyg5TR6ETXXdynog4v?key=BOYKzYgq4pgYW7yZbyxiuobX

 

Step 3 : Block all other webmail platforms

While blocking all other webmail platforms, it is essential to exclude URLs for Google gmail to ensure that while accessing corporate google gmail platform, the access is permitted.

Configuration steps are enlisted below -

 

Create a new URL list including google gmail URLs under

Path: Netskope Tenant UI >>> Policies >>> Profiles >>> URL List - - - New URL List

AD_4nXdfFR8Wa0wa5K3ey9QVke6UjqdqT8JlJuHgonnx4Su-UI_1DN7jTzXJLA-_5pwplHazhWOmn0Bs39-bmuu9THgN4LnCL5SrT50ag2SkM26fzc4pH9eofvusyEUfcPHgua22rmNi-A?key=BOYKzYgq4pgYW7yZbyxiuobX

 

Create a New custom category under

Path: Netskope Tenant UI >>> Policies >>> Profiles >>> custom categories - - - New Categories

AD_4nXfznplYV1oGlaUaAorpwvI-Hu9TWCHRhbd6S7gqxJ1d3N1K0yD5kVYsSFFaIuKcDmvnPrG4PglXW_l2bK2HDKsnK1qBnGHx1YokOjOzLZoi6awljVyRgFqNjDgPzAevhcSLNBsFpA?key=BOYKzYgq4pgYW7yZbyxiuobX

Create a new policy to block all other webmail platforms

AD_4nXeVnrqpZ8KqaqmiYIGJCbRZLjjQYiCTwpGmAuMy6Ba5ym6wgvwgdquwG97rDQKe9Pd2iiBWEYuO9wsQB_AHEcnoCf-XyLmTGzMKRleVpDfSqLcPm4pUJ4dqPsdtZ7cc88p13MmW?key=BOYKzYgq4pgYW7yZbyxiuobX

 

The policy structure with all three policies will be as follows -

AD_4nXdeAVHCicbv-GNfQgOufVk8DQaXx28TGj1qBHVEVLrLC5fQyIQRCYvBI_HufqR0MCpOi4Wyk6bKXkn27_y2JrgxEiCiTHR8NM3qkTF23e0CP_2yOYGzAin8vDH8A538du-oXk7k?key=BOYKzYgq4pgYW7yZbyxiuobX

 

Verification

When you try to access, corporate google gmail, access will be permitted.If you try to access any unsanctioned webmail platform, you will receive the below notification -

AD_4nXc1mT3PXtc6R-aXqCWZf0Ij9P7uvfc0AcvsTt78sshD78DA9RkaTw6IV9FJsBo1BPSWBAhhntQlhabZ4Yjv5ziRMo3nVkMwiHW4MS-FT0n6sENvKfyPUrqegOXoUSlew_QXP0cYOg?key=BOYKzYgq4pgYW7yZbyxiuobX

You can customize the above notification using the steps specified here

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

What to Read Next?

User Notification - User Alert for Non-Sanctioned Application

Link

Block Google gmail personal instance access

Link

Blocking emails destined to personal email accounts

Link

 

 

Be the first to reply!