Netskope Community
08-07-2023 07:06 PM - edited 08-07-2023 07:07 PM
Good Afternoon folks
We're pretty new to Netskope, so please excuse me if this is the wrong place for this question or if it's a particularly basic question, and we're going through the Eseential 8 security process at the moment. To that end, we're looking to prevent Admin accounts from being able to access the internet when logged into machines with Netskope installed.
Is this something that Netskope is capable of? I'm assuming it's a policy that we can roll out to a created group of users?
Thanks very much
Solved! Go to Solution.
08-08-2023 07:59 AM
Hi @PearsonJ , welcome. I'm new to netskope too.
One method that comes to mind to achieve your desired result is to use real-time web policy with block for admin user group on NSClient traffic. [Choose all predefined categories for destination]
08-09-2023 07:17 AM
Hi @PearsonJ the following should provide some guidance
Reference - Best Practices for Real-time Protection Policies
08-08-2023 07:59 AM
Hi @PearsonJ , welcome. I'm new to netskope too.
One method that comes to mind to achieve your desired result is to use real-time web policy with block for admin user group on NSClient traffic. [Choose all predefined categories for destination]
08-08-2023 10:51 PM
Thanks very much, I'll test that out now.
Looking at the order of operations in our tenancy, should this be sitting right at the top? It's only going to be blocking web traffic for a few accounts, and I don't want them picking up Allow permissions as they work their way down the order before getting to the policy.
08-09-2023 07:17 AM
Hi @PearsonJ the following should provide some guidance
Reference - Best Practices for Real-time Protection Policies
08-08-2023 12:10 PM
Hi,
Yes, if there's a user group created for the admins in your IDP which is integrated with Netskope, you would be able to create a realtime policy that includes the said group, and block access to all the web categories.
In order to view this content, you will need to sign in to your account. Simply click the "Sign In" button below
Sign In