Talk to Your Tenant: Querying Netskope with Claude
Education, Training, Certification, and Thought Leadership
Recently active
Generative AI is rapidly reshaping how we work. However, unsanctioned AI tools can create significant blind spots, leading to the potential loss of sensitive data. Security leaders are left with the critical challenge of discovering how to embrace the benefits of AI, without exposing the organization to risk.We are going to cover the who, what, when, where, and how when it comes to discovering the use of generative AI in your organization and how to ensure its safe use with the enterprise. Rapidly Reshaping WorkThe rapid integration of Generative AI into our daily workflows marks a pivotal moment in enterprise technology. These powerful tools are no longer niche innovations but have become standard, expected features within the products and services we rely on, promising unprecedented gains in productivity and creativity. As we embrace this transformative wave, however, we must also recognize that this new frontier comes with inherent challenges. The very nature of AI tools, with their
“Another Security Assessment report to review? I’ll need coffee… and maybe another pair of eyes.” If you’ve ever found yourself buried in long, detailed Security Assessment reports, you know the pain.Pages of findings to go through. CVSS scores that may (or may not) be consistent. Missing screenshots or vague remediation steps. And the endless back-and-forth just to make the report business-ready.Sound familiar? You’re not alone. Manual report reviews are slow, error-prone, and rely heavily on the reviewer’s bandwidth and expertise. But what if we had a smart first-pass reviewer that flagged gaps, standardized structure, consistency in findings & recommendations and freed us to focus on the real contextual risk analysis?That’s exactly what we set out to build — an LLM-powered Report Reviewer. Why Report Reviews Matter More Than EverSecurity assessments don’t end when testing is complete. The report is what travels to:Engineering teams → to guide fixes. Executives and stakeholders →
We know that managing legacy systems like MPLS and outdated VPNs can be a challenge.As we continue to build the future of SASE, we're dedicated to delivering a truly unified, single-vendor platform that makes your network more secure and agile. That's why we acquired our own SD-WAN solution in 2022, to simplify the journey for customers like you.Join Netskope CEO Sanjay Beri and CPO Parag Thakore and discover a practical way to evolve your network with SASE. You’ll learn how to simplify that process, reduce costs, and still deliver a high-performance, secure experience for your users.We'll dive into the practical steps of your SASE journey, including:Migrating from legacy networks to a unified SASE platform Simplifying branch infrastructure and securing IoT devices Delivering consistent zero-trust access everywhere
Hear from our internal security team as they discuss how to leverage User and Entity Behavior Analytics (UEBA) to gain full visibility of the risks that end-users face or perform and ways to take action based on User Confidence Index (UCI) scores. Key Topics:What is User and Entity Behavior Analytics (UEBA) How does Netskope use and implement this within our SOC (Security Operation Center) Detection/Ticket Creation from UCI (User Confidence Index) Enabling user risk scores from our other applications feeding into a user's UCI Policies within Netskope to coach users, or taking action for specific users’ depending on their UCI View past events in this series!
How the Salesloft Drift breach highlights the urgent need for visibility into SaaS-to-SaaS connections.The recent Salesloft Drift security incident has impacted hundreds of organizations and serves as a powerful reminder of a growing threat: risk from third-party SaaS-to-SaaS integrations. This attack exploited trusted connections between applications to access sensitive data, bypassing traditional security controls. The attack chain: How stolen tokens led to data exfiltrationThe incident began when a threat actor acquired OAuth and/or refresh tokens connected to Salesloft's Drift application. Drift, an AI chatbot, integrates deeply with platforms like Salesforce to log user interactions, leads, and meeting data. By using these stolen tokens, the attacker could effectively impersonate the legitimate Drift application. This allowed them to make authorized API calls to their victims' Salesforce instances, exfiltrating sensitive customer accounts and meeting information. The full extent
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on “Managing Certificate Errors with Netskope Client” can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Our recommendation from a Netskope implementation engineer was to keep developers in a steering configuration group that was only cloud apps, not all traffic. This doesn't seem like a feasible nor secure option. Is this recommended to most all customers?A: This is the initial approach to temporarily resolve the issue and keep things running. But as mentioned in the webinar, you will have to work with the developers and understand their traffic patterns to add the Netskope CA to tools to securely enable developers. Q: There is a script that is available on your Support site but it doesn't appear to be updated oft
In today's dynamic digital landscape, organizations are increasingly leveraging a diverse array of Software-as-a-Service (SaaS) applications. While publicly available SaaS apps offer immense benefits, many organizations also rely on custom-built or specialized in-house applications. This presents a unique challenge: how to effectively monitor the security posture of these custom SaaS apps alongside your standard, out-of-the-box solutions? Netskope Security Posture Management (SSPM) has the answer! We're thrilled to announce our new Bring Your Own App (BYOA) feature, designed to extend SSPM's comprehensive monitoring capabilities to your custom SaaS applications. What is Bring Your Own App (BYOA)?BYOA allows you to seamlessly integrate any custom SaaS app, whether it's publicly available or developed internally, into Netskope SSPM. This means you can now define configuration attributes to be monitored, create custom rules, and enjoy continuous monitoring and reporting for all your uniqu
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 127, 128, and 129. Key product updates: Copilot for CCI (SkopeAI) gets smarter with new enhancements for expanded insights across multiple applications directly from Cloud Apps pages Netskope One DSPM data visibility and risk assessment for OneDrive, SharePoint, Google Drive, Box, and Oracle Cloud Infrastructure NextGen API Protection Jira Support for ongoing and retroactive DLP and threat scans for Jira NextGen API Protection SharePoint enhancement to detect files in SharePoint that are exposed to Copilot, helping to prevent sensitive data overexposure Enterprise Browser now supports screenshot, screen sharing, and watermarking Browser Protection Policies Cloud TAP now supports AWS IAM Roles Anywhere to securely store tapped data into S3 buckets Netskope Client Secure Enrollment capabilities Netskope Client Debug Mode makes log collection frictionless for e
Certificates have become the backbone of communicating securely over the internet. When the Netskope Client intercepts the traffic to perform DLP & TSS, certain applications might have adverse effects because of how the application certificates are handled. Hear from our internal security team as they cover: The basics about application certificates and their working How the Netskope Client handles application certificates How to configure the Netskope Client to work with certificate pinned applications How to resolve certain certificate issues by bypassing them For more information, check out our blog post. View past events in this series!
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on “Netskope Data Loss Prevention for Sentiment Analysis” can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: If we are creating keywords in English, will the dictionary be captured in all regional languages?A: No, I think it would just be for the keywords which are specified within the framework. So as far as regional languages, we'll have to check internally if we are supporting those. Q: When creating and deploying a DLP policy for AI, can you provide some tips on how to identify false positives in the Alerts?A: It involves extensive analysis of the incidence and forensic data because this is something that is a challenge for us as well whenever we implement a new DLP framework or a policy. So, we take a step by
Hear from our internal security team as they explain how Netskope DLP can be applied for sentiment analysis of user queries in Generative AI web applications. Learn how to: Compile positive and negative words into CSV files, creating dictionaries and DLP rules for these words in the Netskope tenant console Create Realtime policies to perform sentiment analysis on Gen AI categories Identify the intent and thought of users when using Gen AI with policies that check for the overall sentiment of users, whether it is positive or negative Extend this application of DLP profiles to other use cases like detecting social media trolling or abusive messages For more information, check out our blog post. View past events in this series!
Why Certificates and What is Cert-Pinning?In the internet age, it has become mandatory for all organisations and services which are hosted on the internet to rely on certificate based authentication and authorisation in order to protect the confidentiality and integrity of their data accessible and traversing over the internet. Certificates help prove your identity over the internet when communicating with parties/services which you have not interacted with before. As organisations and service providers started heavily relying on certificates for their security needs, they wanted to be sure that there was no chance of data leakage through techniques such as man-in-the-middle attacks. This led to the rise of adoption of the concepts like trusted certificate stores and certificate pinning.Certificate pinning is a security method which protects the service providers against man-in-the-middle attacks. The server/host is associated with a specific certificate or public key and the applicati
The Netskope One Enterprise Browser (NOEB) is a security solution designed to provide security access to sensitive applications and content in specific scenarios. The NOEB enables Netskope One SSE (Secure Service Edge) services such as Secure Web Gateway (SWG), CASB, as well as threat protection and DLP to be extended to cover corporate users with unmanaged/personal devices, as well as non-employee contractors. NOEB leverages the Netskope One platform, with a single policy engine and admin console. It enables organizations to secure access to sensitive applications and content when devices are unmanaged and also when Netskope client services are not running on devices. NOEB can be deployed through MDM solutions and supports automation for installation and profile management. How is NOEB used by the customer zero team?At the customer zero team, we have been involved in designing, implementing and validating security use cases and protection strategies with NOEB. Some of the specific sc
Netskope provides a comprehensive data loss prevention (DLP) enforcement solution for cloud applications and public cloud resources that is ideal for addressing regulatory compliance requirements and protecting sensitive data in your enterprise. In addition to securing traditional confidential and sensitive data on the web, Netskope DLP can also be diversified for some creative data analysis. In this blog post, I would like to share one of the use cases that can be implemented with Netskope DLP, which is sentiment analysis of user queries in Gen AI web apps. Sentiment Analysis is a technique used to determine the overall sentiment expressed in a piece of text, such as a customer review, social media post, or email. Sentiment analysis relies heavily on positively and negatively used words to determine the overall sentiment of textual data. To learn more about this topic, read the following and register for our upcoming webinar—where we’ll cover this live in more detail and answer custom
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on “Tracking Client Bypasses with Netskope Endpoint SD-WAN” can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: We are in the process of implementing BWAN functionality in OCC. I would love to understand how we can get rid of bypasses, specifically for cert pinned apps such as ZoomA: Well, there's a couple different things. One, in order to see those bypasses we would have to steer it one way, shape, form, or another. So you're either steering it with the NG SWG traditional Client, steering it with the BWAN client, or you're not steering it at all. If you don't steer it at all, you don't get that visibility or that functionality. So it's really who, what, when, where, and how on being able to monitor as well as use
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 124, 125, and 126. Key Product Updates: NextGen API Protection Enhancements for Zoom – DLP/TSS support for In-Meeting and Team Chat conversations Retroactive Scan Enhancements – Advanced Scan Filter options based on Time Ranges Next-Gen API – Write Google Labels Support for Customizing SSPM Scoring – Customize SSPM scoring as per your organization requirements Netskope Private Access (NPA) – Explicit Proxy Configuration Support on a Publisher Netskope Private Access (NPA) – Updated Limit for Publishers per Private App Definition Log Streaming – Product capabilities for direct to cloud integrations Explore past webinars in this series!
Hear from our security engineers as they discuss how we use Netskope Endpoint SD-WAN for gaining real-time visibility into bypassed traffic, tracking SSL certificate-pinned applications, and uncovering the roots of "shadow IT" behavior. Learn how to: Use the SD-WAN console to capture and analyze bypass flows Configure AppX policies to flag "interesting" traffic Monitor and investigate SSL-pinned app behavior (including custom and pre-defined apps) Strengthen security posture with intelligent exception handling Leverage this capability for troubleshooting, resource tuning, and forensics For more information, check out our blog post. View past events in this series!
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on Client Troubleshooting can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Is there a solution to force Netskope to switch multiple devices (>100) to a specific POP in case of issues with one POP?A: It is my understanding that our GSLB will detect those issues and reroute you to a new POP very quickly. Q: How to troubleshoot issues with uninstallation process for older Netskope clients? (Netskope client unable to be removed)A: I recommend renaming the folder. After renaming it, you can uninstall the old client. Here is a great troubleshooting guide! Q: How would you go about troubleshooting a Microsoft Teams call performance issue to confirm if Netskope proxy is the root cause or its something else?A: For me,
Hear from our internal security team as they discuss the systematic approach we take at Netskope to diagnose and resolve client issues effectively. Key Topics:Understanding Netskope Client Architecture – How the client interacts with cloud security services and network components. Common Client Issues and Root Causes – Connectivity failures, latency, and policy misconfigurations. Troubleshooting Tools and Logs – Leveraging Netskope Client Debug Logs, Packet Captures, and Browser Developer Tools. Best Practices for Resolution – Steps to address common client-side issues and optimize deployment. DEMO: Using the Netskope Client itself to troubleshoot issues on the OS and applications.For more information, check out our blog post. View past events in this series!
This one is more for my tech partners than for customers. If you tie your idp into your Netskope tenant you would never do this. This is really just for a lab environment. This will create users and groups that you can then use in policy. Create API token for scimGo to Settings > Tools > REST API v2 > New Token Create an API token that has the two scim endpoints added. With the token copied and stored somewhere. Go to API Documentation. Add the token to the Authorize In the scim section use the apis to view and create the users/groups. Adding a userStart by adding the user. Be sure to change the userNamePOST /api/v2/scim/Users{ "schemas": [ "urn:ietf:params:scim:schemas:core:2.0:User" ], "userName": "taylorkelce", "name": { "familyName": "kelce", "givenName": "taylor" }, "active": true, "emails": [ { "value": "taylor@eras.tour", "primary": true } ], "externalId": "User-Ext_id", "meta": { "resourceType": "User" }} Search for your user
Hear from Deepti Hemwani, Director of Product Management, as she demonstrates how to better understand your data landscape, uncover hidden security risks, and enforce security policies to protect your most valuable assets against future threats with Netskope One Data Security Posture Management (DSPM). To learn more, check out our Customer Exclusive DSPM event on-demand!
Many organizations lack a structured and practical approach to enhance their cybersecurity maturity, resulting in inconsistent security practices, increased vulnerability to cyber threats, and difficulty in demonstrating compliance.Organizations often struggle to effectively improve their cybersecurity posture due to the absence of a clear, actionable roadmap. This lack of guidance leads to ad-hoc security measures, gaps in protection, and an inability to measure and track progress. "A Hands-On Guide to Improve Cybersecurity Maturity" addresses this problem by providing a practical framework, such as OpenSAMM, to systematically assess current security practices, identify weaknesses, and implement targeted improvements. This approach enables organizations to move beyond reactive security measures and proactively build a robust and mature cybersecurity program, ultimately reducing risks and enhancing overall security resilience. Understanding OWASP SAMMSAMM stands for Software Assurance
Hear from our internal security team as they discuss the possible settings and changes which can be made in the Netskope tenant to accommodate a lost/stolen corporate managed device. Learn how to: Modify settings in the tenant proactively for lost/stolen device cases in the future Effectively deal with lost/stolen devices by setting up protective measures against device misuse Minimize data loss in case of lost/stolen device cases by blocking data movement from the device Check out our blog for more information!
Hi can someone help me? I have a trining today Security Cloud Operation & Administration (NSCO&A) Training - EMEA (BST) - March 24-26, 2025but the link is not working:Here is your unique link - http://events.netskope.com/nscoa-emea-bst-march24-26/virtual?guest-access-hash=NDU5MTEwMTI5fDc5MDk2ODE3MHwxNzQxOTQyMzA3O2MwMDJmMzY2Nzc5ZGVhNWQxOTA5NGU3OGQ2YTcyZTcxZjE2YmM2N2Q3OTY4OGJhYzA2YzNjMjEzZWU2NjVkY2U%3D thanks
When I was asked to write an article on identifying, troubleshooting, and resolving common Netskope Client-related issues, I initially thought, "Sure! How hard can it be?" However, I quickly realized that troubleshooting is a broad and open-ended topic, varying significantly depending on the specific issues encountered.In this article, we will explore common Netskope Client problems, their root causes, and the best tools and methods to resolve them. These insights align with the key topics we will cover in our live presentation.Those topics are as follows:Understanding Netskope Client Architecture – How the client interacts with cloud security services and network components. Common Client Issues and Root Causes – Connectivity failures, latency, and policy misconfigurations. Troubleshooting Tools and Logs – Leveraging Netskope Client Debug Logs, Packet Captures, and Browser Developer Tools. Best Practices for Resolution – Steps to address common client-side issues and optimize deployme
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.