Skip to main content

 Netskope Adoption Welcome Pack

 

Thank you for your investment and welcome to Netskope! Your customer experience team is here to ensure you have everything you need to make your Netskope journey a success.

 

Attention ! Don’t miss these crucial resources. 

While you get started with Netskope, please ensure to use the below links to access various Netskope portals and resources. Brownie :  Don’t forget to bookmark these links for future reference.

 

Task 

Link

Request your first support account through your Netskope representative 

 

Create a Netskope Academy Customer Learning portal account 

Link

Create a support portal account and “Follow the sections shown below” for important announcements.

Link

Subscribe to the Trust Portal to get live Maintenance and Incident updates

Link

Check out our Knowledge Base articles 

Link

Join the Netskope Community

Link

Subscribe to receive the latest Product Updates

Link

Stay current on Netskope's Events including Webinars, Workshops, User Groups 

Link

Stay up to date on Release Notes and research knowledge base articles

Link

Measuring your success using Netskope Reporting dashboards

Link

Learn about all the tools available to accelerate your Adoption Journey

Link

 

Following important sections from the support portal

Once you have created your support portal account, it is crucial that you follow on to the below highlighted sections to receive notifications within your email inbox related to Service Notifications, Scheduled Netskope Data Center Maintenance, Threat Advisories, Security Advisories etc.

 

 

Hit the follow button at the right as shown below

 

 

Netskope Resources

We are here to guide you on your self-paced path to success, however, should you need help along the way, you can use these resources.

 

Resource

Type of Request

Contact Methods

Technical Support

  • Technical Problem
  • Account Creation
  • Password Reset
  • Case Escalation
 

Note: additional support accounts can be requested through a support case.

 

Global Support Numbers:

  • US: 1-800-685-2098
  • UK: 44-8455280141
  • Australia: 1-800-505-486
  • Europe: 44-8455280141
  • Singapore: 800-321-1684
  • India: 00080-0100-4400
  • New Zealand: 0800-359-800

Technical Success

  • How-To/Best Practices Questions
 

Note: Select case type of: How To Question

 

Getting Started

Netskope has developed foundational learning modules focused on enabling administrators with best practice knowledge on core components of the SASE platform. 

We have broken these up into essential and recommended modules for easy, self-paced learning. The following Jump Start series provides you with the fundamentals to get started with Netskope and are essential to know at the beginning of your journey.

 

Netskope Component

Essential Learning Modules

Jump Start: Getting started with Netskope

Expanding on the Jump Start series, we recommend you progress your knowledge by understanding some of the Administrative processes.

 

 

Self-Serve: Operationalization & Adoption Checklist (Also increases your Tenant Health Score!)

Now that you have completed the fundamental knowledge phase, we move into the Operationalization & Adoption phase, where you use that knowledge to configure policies using the best practices and increase your Tenant Health score.

Match the Netskope component you are subscribed to and mark off the tasks when completed in the checklist below at your end.

Instructions

The Netskope Component describes a tenant configuration, client configuration, product configuration or a process that is recommended by Netskope to ensure you are aligned with the foundational best practices.

Go through each line item and continue to align your tenant as per the recommendations defined below.

 

Netskope Component

 

Task Checklist

Reference 

Client Configuration

Client Auto Upgrade Configuration

Client Auto Upgrade Configuration : Ensure the client versions are set to Auto upgrade to Latest Golden release

Link

Client Configuration Settings

DTLS : Ensure DTLS protocol is enabled in all client configurations

Link

Advanced Debug : Ensure that the debug level is set to "info" or disabled in all client configurations

Link

Allow disabling of clients : Ensure the option to disable the Netskope client is not allowed in client configuration

Link

Hide client icon on system tray :Verify that the system tray icon is visible in all client configurations 

Link

Password protection for client uninstallation : Ensure password protection is enabled for client uninstallation in all configurations

Link

Protect client configuration and resources : Verify that client self-protection is enabled to prevent tampering with client processes and files

Link

Number of Client Configurations

Number of Client Configurations : Ensure that there are multiple client configurations created apart from default configuration

 

Client Version Distribution

Client version Distribution Maturity : Ensure that Netskope clients are upgraded to Latest Golden release across the environment

 

DLP Policies and Configuration

Forensics Profile Configuration

Ensure that Forensics profile is configured : Netskope recommends using a public cloud storage (like Azure Blob, AWS S3, or GCP Cloud Storage) as a forensic destination over a SaaS storage app, because a SaaS storage app cannot scale for high frequency forensic write workloads.

Link

 

DLP policies Configuration specific to Industry needs

Ensure to create Data protection policies specific to your compliance, industry regulations to ensure there are essential safeguards in place to protect your sensitive data.

Link

General Tenant Configuration

Basic Security Settings

Privacy Notice : Privacy Notice should be enabled

Link

 

Idle Timeout : This should be set to automatically log out inactive users

Link

 

Password expiry : Password expiry should be configured to enforce regular password changes

Link

 

Multiple concurrent logins : Multiple concurrent logins should be disabled for Security reasons

Link

 

IP Allowlist : This should be enabled to restrict access from unauthorized IP addresses

Link

SSO Enablement

SSO should be enabled and properly configured in order to mitigate security risks associated with console (Web UI) access.

Link

MFA for local admin users

Enable MFA for all local administrator accounts Consider implementing a policy requiring MFA setup before granting administrative privileges Regularly audit administrator accounts to ensure MFA remains enabled

Link

Administrator provisioning

Ensure RBAC is provisioned as per roles within the organization

Link

Netskope personnel access

Netskope recommends tenants to enable SSO in order to allow Netskope personnel access to the tenant.

Link

SSL Policies

SSL DnD policies

SSL DnD policies limit Netskope’s ability to have visibility on the traffic. Ensure that SSL DnD is only configured for required traffic

Link 

SSL DnD Policy for Microsoft 365

Check if there is a SSL DnD (Do Not Decrypt) policy set for Microsoft365 (Office 365) related web traffic. Following Netskope recommendations, such a policy should not be enabled.

 

SWG Policies

Ads Block Policy

Ensure that there is a policy that blocks web advertisement content

Link

 

DoH Block Policy

Ensure that  DoH (DNS over HTTPS) is being blocked.

Link

 

Safe Search Enablement

Ensure that Safe Search is being enabled on the tenant.

Link

 

Real time policy Blocking AUP categories

Ensure that all categories identified as inappropriate or risky are being blocked.

Link

 

Dynamic URL Classification

Ensure that Dynamic URL Classification is enabled on the tenant

Link

 

Policy to Block Risky Destination Countries

Ensure that web traffic to high-risk countries is properly blocked through web security policies.

Link

Steering Configuration

Bypassed Traffic Logging 

Ensure that Bypass Traffic logging is set

Link

 

Steering Configuration Best practices

Ensure that there are Multiple steering configurations leaving default at the bottom, Test steering configuration applied to subset of users, Review Exceptions in different configurations, Ensure that Steering mode is set as per entitlement

 

 

Link

Threat Protection Policies

Real Time Policy Blocking Security Risk Categories

Ensure that there is a policy blocking Security Risk categories.

Link

 

Real Time Policy with Threat Protection Profile

Ensure that there is a policy to block Threat Protection Profile

Link

 

IPS Enablement

Ensure that IPS is enabled

Link

 

Real-Time Protection Policies - Best Practices

 

Below are the best practice inline policies for Netskope. Ensure to have these policies configured in the structure as shown below for your tenant.

A deep understanding of each of these policies can be obtained from this link

 

No

Policy group

Policy

Reference Link

1.1

Threat

Block DNS over HTTPs

Link

1.2

 

Block security risk categories

Link

1.3

 

Block traffic destined to High risk destination countries

Link

1.4

 

Block upload/download of malicious files

Link

2.1

RBI

Steering all RBI categories with action set to isolate

Link

3.1

Webmail

Allow sanctioned webmail instances

Link

3.2

 

Block all the unsanctioned webmail platforms

Link

4.1

Cloud storage

Allow sanctioned cloud storage instances

 

4.2

 

Block all the unsanctioned cloud storage platforms

 

5.1

Streaming

Block Youtube globally

Link

5.2

 

Allow only specific youtube videos

Link

6.1

Generative AI

Allow Sanctioned Generative AI instances

Link

6.2

 

Block all the unsanctioned Generative AI platforms

 

7.1

Online converter

Allow sanctioned online converter applications

Link

7.2

 

Block all the unsanctioned Online file converter platforms

Link

8.1

Collaboration

Allow sanctioned collaboration applications

Link

8.2

 

Block all the unsanctioned collaboration platforms

Link

9.1

Social Media

Allow sanctioned social media platforms

Link

9.2

 

Block all the unsanctioned social media platforms

Link

10.1

Cloud firewall

Block Apps - L7 based policies

Link

10.2

 

Block Apps - L3 based policies

Link

11.1

Global blocklist

Block online Ads

Link

   

Block all acceptable use categories

Link

 

If you need assistance in understanding these best practise checklist or aligning your tenant in accordance with the best practices, you can raise a ticket at support.netskope.com by using the “Case Type - How to Questions”

 

Done Already? Congratulations! Your Level 1 Tenant Health score is 100/100. To move further in your adoption journey, review the additional resources available here

You can also access product learning paths for various platform offerings available here


Warm Regards,

Netskope Customer Experience Team

 

Be the first to reply!