Talk to Your Tenant: Querying Netskope with Claude
Education, Training, Certification, and Thought Leadership
Recently active
The majority of enterprise employees are already using AI applications their IT organization has not approved. Your Identity pillar does not see them — the agent authenticates through a personal or unsanctioned service account. Your Network pillar does not flag them — AI API calls look like ordinary HTTPS. Your Data pillar does not catch the exposure — DLP rules were written for file exfiltration, not conversational data ingestion at scale. Five pillar teams, five telemetry blind spots, and a single AI application slipping through all of them simultaneously.Structural gaps in AI security are best addressed by extending existing architectural controls rather than fragmented tuning. CISA's Zero Trust Maturity Model v2.0 provides the necessary ownership domains to govern AI assets. This document establishes the five-pillar baseline—the essential "enforcement" foundation for AI security. The architectural controls defined here in part 1 are the necessary prerequisite for the governance fra
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 136, 137 and 138.Key product updates:Enterprise Browser Now Covers Every Device, Everywhere: Expanded protection to all major platforms, including IGEL thin clients, with new features like watermarking, sandboxed clipboard controls, and NPA integration on mobile. AI Security: From Threat Testing to Real-Time Enforcement: Use AI Red Teaming to identify LLM vulnerabilities, detect deepfakes via API, and enforce real-time guardrails on AI traffic, including custom topic controls. Data Lineage: The Full Story Behind Every File: Built into Incident Management, this allows DLP analysts to follow sensitive data from origin to destination for faster investigations and to stop unauthorized data movement. Zero Trust Private Access: Performance, Compliance, and Coverage: Enhanced for better network throughput (BBR congestion control, dual-stack IPv4/IPv6 support), geo-fencing, and en
A brief introduction to Advanced Analytics.
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 133, 134, and 135. Key product updates: Comprehensive AI Security and Governance: Protect private AI applications with the Netskope AI Gateway and AI Guardrails, providing real-time content moderation, threat protection, and vulnerability assessments via AI Red Teaming to ensure compliance and quality Advanced Visibility for Agentic Workflows: Gain full oversight of Model Context Protocol (MCP) communications through the Agentic Broker, featuring detailed audit logs and policy enforcement for remote MCP servers and clients within Skope IT Steganography detection: Identify and protect sensitive information from the growing threat of sophisticated data-hiding techniques Manager Escalation: DLP Analysts can now initiate a review workflow to request feedback from the manager of the user who committed the DLP violation DLP on Demand: Power your DSPM scans using Netskop
We’re excited to introduce a simpler, more transparent way to register for training at Netskope Academy! You can now self-register for courses using training vouchers, which means no more forms or back-and-forth. Just purchase training, receive your voucher, and enroll in minutes. Any existing, non-expired training credits you already have will automatically convert into vouchers. We’ve created a short video to show you how the new system works. See the new process in action: We’re confident this update will make your learning experience faster and easier.Questions? Contact us at training@netskope.com
Learn how to best monitor & manage the AI applications being used in your organization with our latest AI Usage Dashboard.
A common use case using Netskope One SSE and Okta is to extend your zero trust perimeter using Okta Network zones and the Netskope NewEdge network. This will create an additional obstacle for an attacker to use compromised credentials and is recommended by Okta as a defense against credential stuffing attacks. The Netskope One client checks the device posture or compliance in real time via Device Classification to ensure that only Corporate managed devices are allowed to connect to Okta. The following Okta authentication policy rule scenarios are presented below: (these would also apply when using tunnels)Prerequisites for all policy scenarios Scenario: Restrict access to application(s) for users that originate from Netskope NewEdge Scenario: Restrict access from Netskope NewEdge in the United States Scenario: Restrict access to originate from Netskope NewEdge and the user’s client IP originates in the United States Scenario: Restrict access for Administrators to originate from Netsk
This video helps you get started with Advanced Analytics in around 5 minutes, which includes an overview of the UI, copying & pasting dashboards, customizing dashboards, and editing widgets (visuals).
Enterprises are adopting AI at a pace that has outstripped the existing Zero Trust Maturity Model (ZTMM). Current security pillars are designed to verify the authenticity of human and application entities, but they are not architecturally equipped to inspect the intent and scope of autonomous AI agents. The result is not merely an operational oversight; it is a structural gap where AI interactions bypass existing telemetry streams. This document defines the framework for bridging this gap by evolving CISA ZTMM 2.0 to include a dedicated 6th Pillar for AI & Autonomous Systems.This 6th pillar is designed to own the governance and lifecycle of AI models and agents, distinguishing it from the existing five pillars (Identity, Devices, Networks, Applications & Workloads, and Data) which continue to act as "Enforcement Points" for AI security. Executive SummaryProblem: Current ZTMM 2.0 pillars are designed for known assets; they cannot interpret the autonomous intent of AI agents. Sol
A publisher's identity is bound to a specific tenant through its registration token. "Moving" a publisher means unregistering it from the source tenant and re-registering it to the destination tenant. This can be done manually via the Publisher Wizard or automated via the Netskope REST API v2.One critical thing to understand: private app segment definitions, steering policies, and upgrade profiles do not travel with the publisher. These are tenant-level configurations that you'll need to recreate on the destination side. Plan for that before you start. The Manual ProcessMoving a Netskope Publisher—whether for tenant consolidation, environment separation, or lab-to-production migration—is a common infrastructure task. While there is no native "transfer" button, the process is efficient when performed correctly. This guide details both manual and automated methods to migrate your Publishers while ensuring service continuity. It is ideal for moving one or two publishers Step 1. Unregiste
Goal: Learn how to automate Netskope Admin Console role assignment based on a user's login location when authenticating through Okta. Example: When logging in to the Netskope Admin Console through Okta, different admin roles should be assigned automatically depending on the country the user is signing in from. Partner requirement: Administrators should be able to configure different roles for different members, based on their own requirement definition (e.g., country, region). PrerequisitesNetskope tenant configured for SSO/SAML with Okta as the Identity Provider for Admin Console login. A local tenant admin account in Netskope with rights to view predefined roles and create custom roles. Okta Workflows enabled on the Okta tenant. Workflows is a separate entitlement/add-on and is not included in every Okta edition — confirm this is licensed before scoping the project. Admin rights in Okta to create groups, edit the Netskope SAML app configuration, and build/activate Workflows.Limitatio
Hear from our SOC manager and Sr. Data Analyst as we share how Netskope leverages AI security dashboards to monitor AI usage, uncover AI security concerns, and convert this into actionable insights. Learn how to:Monitor AI adoption, uncover risky AI usage, and gauge overall AI risk level using the AI Usage and AI Risk Assessment Dashboards Manage risky user and model behaviors using the AI Guardrails Dashboard Monitor and control AI app-to-app traffic using the AI Gateway Dashboard Monitor MCP usage using the Agentic Broker - MCP DashboardFor more information, check out our Advanced Analytics forum. View past events in this series! Check out some customer questions below, or feel free to comment and continue the discussion! Q: Where can I access this Activity in the AI Apps dashboard within the console?A: Visibility into user activities can be found in the "Activity in AI Apps" section of the AI Usage Dashboard. Q: How can Netskope monitor and control the use of unsanctioned AI to
If you have spent any time online recently, you have likely encountered a CAPTCHA verification or an unexpected browser error message. Cybercriminals are banking on that exact muscle memory. Today, they are leveraging our habit of clicking through technical glitches to bypass traditional security filters entirely. At Netskope, our Global Information Security team recently launched an internal awareness campaign targeted at a highly sophisticated social engineering tactic known as "ClickFix." Rather than relying on technical exploits, these attacks trick users into manually infecting their own machines. To ensure our team remained vigilant, we deployed a real-time training mechanism using our very own Netskope Client. Here is a behind-the-scenes look at how the campaign worked, what the threat looks like, and the remarkable engagement data we gathered across our departments.What is a "ClickFix" Attack?Unlike traditional phishing where a malicious file is downloaded automatically, ClickF
Less Clicking, More DescribingSpending an entire afternoon navigating the Netskope Tenant to extract a report, conduct an investigation, or trace a misconfiguration is a familiar, time-consuming challenge. However, this entire equation is rewritten by combining the Netskope CLI with Cowork and Claude Code. Work that previously consumed hours collapses into a single conversation as you simply describe your objectives in plain English, allowing AI to convert intent into direct action instead of navigating sections in the Tenant. This post puts that promise to the test across the standard workflows administrators handle each week: examining user activity across diverse tenant sections; extracting months of Skope IT logs to optimize CASB and real-time policies; evaluating actual user experience via Digital Experience Management; and confirming the reachability and connectivity of publishers and private applications. Each of these workflows typically requires hours of data exporting, clicki
Building a CrowdStrike Falcon Dashboard on Netskope Data: a Step-by-step Guide How my team streamed Netskope web, DLP, and alert telemetry into CrowdStrike Falcon Next-Gen SIEM, wired up automated indicator sharing, and built a cross-source security dashboard that correlates Netskope, Falcon, and Okta signals in one place. Everything below is enough to build the same thing in your own tenant. Why we built this My security operations team lives in CrowdStrike Falcon. That is where analysts triage, hunt, and respond. But a lot of the signal they need sits in Netskope: web transaction logs, DLP violations, anomaly alerts, and policy actions from the Netskope One Security Service Edge (SSE) platform. Every time an analyst had to pivot out of Falcon to check the Netskope Admin Console, we lost time and context. Our solution had two parts. First, stream Netskope logs into Falcon LogScale so analysts get a native Netskope dashboard inside Next-Gen SIEM, sitting next to t
There's a question every security vendor eventually has to answer: do you actually use your own product to protect your business? At Netskope, the answer isn't just yes — it's the foundation of how we operate. As the Customer Zero team, our job is to deploy our Netskope products before they reach customers. That includes our full portfolio of AI-powered security capabilities, which today sit at the center of how we detect threats, govern data, control access, and keep our workforce productive without sacrificing visibility. This isn't a case study from a customer. It's what we do every day. And the products we've deployed across our own environment paint a clear picture of where enterprise AI security is headed — and what it actually takes to get there.Our internal security strategy is structured around four primary pillars, which collectively ensure that our AI-driven capabilities provide comprehensive protection across every layer of the organization. Capability Problem So
The problem we kept running intoEvery day, multiple Netskope employees would post in our internal #customerzero Slack channel asking for Enterprise Browser (EB) access. The messages were nearly identical: someone had just heard about EB, wanted to try it out, and needed a license key or enrollment invite to get started.The CZ team would then manually look up the user, send an enrollment invite through the Netskope admin console, and reply in the thread. This worked, but it was repetitive, manual work that pulled our team away from higher-value investigations and dogfooding activities.We started asking ourselves: why are we the bottleneck here? The process was entirely mechanical — receive request, identify user, send invite, confirm. It was a perfect candidate for automation.📊 By the numbersAfter analyzing 200+ posts in #customerzero, Enterprise Browser invite/license key requests were the second most common issue category — 16+ posts, fully repeatable, zero judgment required to resol
Visibility in the Age of Artificial IntelligenceAs enterprises rapidly shift toward a cloud-first and AI-driven landscape, the traditional boundaries of the corporate network have dissolved. Employees are accessing sophisticated AI tools from everywhere, making the internet the primary delivery mechanism for business productivity. This transition introduces a critical challenge: a loss of visibility into network paths, user experience, and application performance. Enter Netskope Digital Experience Management (DEM). DEM is a native component of the Netskope platform designed to provide comprehensive operational status and health visibility for all customer traffic. By leveraging a highly scalable data architecture, DEM pulls telemetry from various back-end sources to deliver real-time, actionable insights into the overall user and application experience. From monitoring tunnel status to tracking client steering and service availability, Netskope DEM ensures that IT teams maintain contro
INTEGRATION GUIDEAutomating Noncompliant Device Enforcement with Netskope Cloud Exchange and Microsoft IntuneCloud Exchange × Microsoft IntuneThis guide shows how the Netskope Cloud Exchange Risk Exchange (CRE) module reads device compliance from Microsoft Intune, tags noncompliant devices in the Netskope tenant, and drives real-time enforcement. The result is a closed loop between your Mobile Device Management (MDM) system and Netskope, with no manual handoff between consoles.How the integration worksMicrosoft Intune continuously evaluates enrolled devices against its compliance policies. Cloud Exchange pulls that device data through the Microsoft Intune plugin, merges it with the matching Netskope device record, and, when a business rule matches, pushes a device tag back to the Netskope tenant. A Device Classification rule reads that tag, and a Real-time Protection policy acts on the classification.The stages below trace a single noncompliant Windows device end to end. 1 2
Overview This guide shows how to stream Netskope alerts and events into Microsoft Sentinel.The connector is called Netskope Alerts & Events Connector (via Blob Storage). Netskope publishes it. It ingests alerts and events logs from Netskope Log Streaming into Microsoft Sentinel via Azure Blob Storage, using the Microsoft Sentinel Codeless Connector Framework (CCF).The data flow does not push logs straight into Sentinel. Netskope Log Streaming writes logs to an Azure Blob Storage container. Sentinel then reads those blobs and writes the records into the Log Analytics table NetskopeAlertEvents_CL.This article is based on the connector's own deployment template (netskope_alert_events_log_streaming.json). UIs in Netskope and Azure change over time, so verify each screen against current documentation as you go.How it works (architecture)The pipeline has three stages.Netskope Log Streaming sends Alerts & Events logs to an Azure Blob Storage container. Azure infrastructure signals new
OverviewA continuation of Sending Alerts and Events to Microsoft Sentinel using the Codeless Connector Platform.The first article set up the Codeless Connector for a single Netskope tenant. This post extends it. It sends alerts and events from several Netskope tenants into one Microsoft Sentinel workspace, and it labels each record so you can tell the tenants apart.If you have not read the single-tenant article, start there. The base ideas carry over: the Codeless Connector Framework, the RBACv3 service-account token, and the REST API index. Architecture Each Netskope tenant sends alerts and events to the same connector. The connector posts the data to one Data Collection Endpoint. A separate Data Collection Rule for each tenant adds a TenantSource value and writes the record to the shared tables. The result: all tenants share the same tables, and the TenantSource column tells you which tenant a row came from.This template supports up to five tenants.What is different from the single-t
Hear from our security engineers as we share how Netskope moved beyond blanket restrictions to a more adaptive, context-aware approach that lets us safely say “yes” to SaaS and GenAI. We’ll highlight real-world patterns of risky usage, common blind spots across managed and unmanaged apps, and the unique data exposure risks posed by GenAI assistants and copilots. Learn how to:Discover and continuously assess SaaS and GenAI usage across your environment Protect sensitive data with granular, inline, and context-aware controls Apply consistent policies to managed, unmanaged, and AI-powered applications Partner with business stakeholders to securely accelerate SaaS and GenAI initiativesFor more information, check out our blog post. View past events in this series! Check out some customer questions below, or feel free to comment and continue the discussion! Q: Can you share best practices for GenAI apps control in RTP policy structure given new app connectors and capabilities?A: Discover
This document outlines the integration of Netskope Web Transaction Logs with Microsoft Sentinel on Azure US Government cloud using the Codeless Connector Framework (CCF). Separate templates are provided for comma-delimited and space-delimited blob data. This native integration provides near real-time visibility for effective threat hunting and incident management. To configure Netskope Log Streaming to send logs to your Blob storage please go through the article: https://docs.netskope.com/en/stream-logs-to-azure-blob ⚠️ Important: You can't restrict network access to your Azure Blob Storage account as per the official guidance from Microsoft.🏗️ Integration Architecture OverviewThe integration leverages several Azure services to ensure reliable and scalable log delivery: Netskope to Azure Storage Blob: Netskope pushes Web Transaction Logs into a customer-owned Azure Storage Blob Container (as gzipped CSV files). Event Grid Notification: Every time a new file (blob) is written, an auto
Anthropic’s Claude has gone from "the AI tool a few teams were experimenting with" to mission-critical infrastructure: Developers ship code with Claude Code. Analysts build entire workflows on Claude Projects. Platform teams run inference at scale through the Claude Platform. But here's the uncomfortable question: Do you have the same security governance over Claude that you have over Slack, Google Workspace, or Salesforce? If the answer is "not yet" — this post is for you.Netskope has built an integration with the Claude Compliance API, giving security and compliance teams visibility into Claude usage directly within the Netskope One Platform. This brings Claude Enterprise and Claude Platform activity under the same security umbrella as every other application in your stack.No new tools. No separate dashboards. The same console your team already uses. Let me walk you through what this looks like — and more importantly, why it matters.The Problem: AI Apps Are the New Shadow IT When
Author: Stevan PierceDate: May 8, 2026Modern security teams are stuck in an old debate.The business wants ChatGPT, Copilot, Cursor, Gemini, and the next AI assistant your CEO sees demoed at a conference. The security team sees prompts full of source code and customer PII heading to a third-party model, an MCP server nobody vetted suddenly connecting to your data lake, and an "AI Overviews" toggle that quietly turned a sanctioned search engine into a generative assistant overnight.The instinct is to block. Block the domain. Block the category. Send a stern email.It doesn't work. Blocking a sanctioned AI assistant doesn't make the data exfiltration risk go away. It just pushes the user to a personal account on their phone, where you have zero visibility. And the embedded AI in apps you've already approved? You can't block that without breaking the app.At Netskope, we faced this exact problem in our own environment. As Customer Zero, our security team not only secures Netskope but also p
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.