Skip to main content
Solved

Netskope SWG and Onenote

  • January 3, 2024
  • 5 replies
  • 273 views

Forum|alt.badge.img+1
  • New Member
  • 2 replies

While we have the normal exceptions in place for MS 365 and the likes, we seem to have users including myself that can't get Microsoft Onenote to sync unless we disable the endpoint client.

 

Has anyone seen this or have an idea on how to solve?

 

Thanks!

 

Best answer by hoby

Oh this is much easier!  Support gave me some info on creating Cert Pinned App for Onenote app on Mac and Windows, but I would prefer this as it works across the board.  Thanks!

This topic has been closed for replies.

5 replies

ejang
Netskope Employee
Forum|alt.badge.img+5
  • Netskope Employee
  • 69 replies
  • January 4, 2024

Onenote sync is detected as O365 OneDrive in Skope IT. You need to add this in Steering Exception if it is not in there.


Forum|alt.badge.img+1
  • Author
  • New Member
  • 2 replies
  • January 4, 2024

Thanks for the info, I had assumed the 365 suite was already part of the exceptions, but it appears Onedrive is not.  I don't see that as a Cert Pinned App, nor do I have the ability to make Application exceptions in our tenant for some reason like they talk about on the site.

I will reach out to support I guess.

Thanks for the info!


zthompsoncr
Netskope Partner
Forum|alt.badge.img+9
  • Netskope Partner
  • 49 replies
  • January 4, 2024

@hoby this is an easy fix, please add this URL only to an SSL Bypass this should fix your issue. That was bad advice to add that as a steering exception/bypass.

 

url: *.contentsync.onenote.com

 


Forum|alt.badge.img+1
  • Author
  • New Member
  • 2 replies
  • Answer
  • January 4, 2024

Oh this is much easier!  Support gave me some info on creating Cert Pinned App for Onenote app on Mac and Windows, but I would prefer this as it works across the board.  Thanks!


qyost
Forum|alt.badge.img+16
  • Explorer III
  • 146 replies
  • January 16, 2024

I'm still hoping that Netskope will implement a method by which traffic can be sent to Netskope by the client, but be identified as certificate-pinned and bypassed from processing in the cloud.   That way all traffic is still sent through Netskope rather than needing a direct-egress path.