Skip to main content
Solved

Can prelogon settings be updated via NSDIAG or is a reinstall required?

  • June 24, 2025
  • 3 replies
  • 185 views

elawaetz
Forum|alt.badge.img+4

If I look at the instructions for configuring prelogon, then this seems to require a reinstall of the client with the correct “prelogonuser=<user>@prelogon.netskope.com” command line parameter.

The “nsdiag” command does have a few extra things up its sleave, including update of the secure enrollment tokens.

Is there a (hidden) option to also allow adding a prelogon user to an already installed client?

 

--Erik

Best answer by sshiflett

@elawaetz

A reinstall is not required for prelogon.  You can enable prelogon for already provisioned and enrolled devices by updating the respective client configurations with prelogon settings.  Once you’ve done this, the clients will begin enrolling with these settings as they check in.  

The instructions to enable via the command line installer are for cases where a user hasn’t enrolled and you want to provide machine level connectivity such as first time log ons, joining a remote machine to the domain and Intune Autopilot. 

This topic has been closed for replies.

3 replies

Forum|alt.badge.img+16
  • Netskope Employee
  • Answer
  • June 25, 2025

@elawaetz

A reinstall is not required for prelogon.  You can enable prelogon for already provisioned and enrolled devices by updating the respective client configurations with prelogon settings.  Once you’ve done this, the clients will begin enrolling with these settings as they check in.  

The instructions to enable via the command line installer are for cases where a user hasn’t enrolled and you want to provide machine level connectivity such as first time log ons, joining a remote machine to the domain and Intune Autopilot. 


elawaetz
Forum|alt.badge.img+4
  • Author
  • Explorer III
  • June 26, 2025

@sshiflett  

Thank you for clarifying that Sam!

Does this apply for first time users on a multi-user (peruserconfig) device as well?

--Erik

 

 


Forum|alt.badge.img+16
  • Netskope Employee
  • July 1, 2025

It should yes.  The assumption being that one of the users who logs on is assigned a client config that has prelogon enabled.  

Depending on the device type there may be additional configuration options on multiuser systems as well:

https://docs.netskope.com/en/use-the-npa-client-in-windows-multi-user-virtual-desktop-environments/