Skip to main content

AD_4nXfkYeWv0rnY0u6bPO-k1Lygs8pvRFFf2LyOCFwru4lMuJFxCrDPyPVyn8mKcroc_ZMT4DtspiyXZE46XAiUVZUJ3ozEnlDDB1PEKKkMZhe4sMFl46HrAATq4ojX4NScLMfGBsHV8Ck_VUo3vwrOF_HPwqFW?key=4xPM8MAdYcvBgm4U_m2Ujw

Netskope Global Technical Success (GTS)

Streamlining Admin SSO with Azure AD: Custom Netskope Tenant Role Assignment

 

Netskope Cloud Version - 123

 

Objective

This document explains how to assign Custom Netskope Tenant Role in the Azure AD gallery application for Admin SSO.

 

Prerequisite

Netskope Administrator Console integration with Azure AD.

 

Context

As a Prerequisite, Netskope Administrator console should be integrated with Azure AD. Below article illustrates step-by-step guidance for the same:Single Sign On with Microsoft Entra ID This article also describes assigning Pre-defined roles to the SSO User.

 

Configuration

  1. Log in to the Microsoft Azure Portal.
  2. Select Enterprise applications:

AD_4nXfPTKLI_iWDxm7akfJ1klxmxD1Y2Txa5p-jIrfzTMy_ee7O8sQ5N8oh6CZXPlpkG9agbtZUkgI9pFNm_oGgd80gsRraTG-3SeZZjwcKbLr1X--7d9816fl01LFlaqY7Gw4MaezU2DiWmMwc54EBh2NzF2U2?key=MZoH0xEDBkYz9g06jt2lGg

  1. Search for the already integrated 'Netskope Administrator Console' Application in the Application list.

AD_4nXcJWg5fR46VJ0cWYfpVSL_kNpQ2V_LUcZRX_Js6F0JMloSBQS613nyPBHD0x80z6MBoflrTzK7A37fdkZBM7YWGVQxzAlO5EKFq-fvmeHZIqmUt7hIjwghIW-j2fDmFe8reTvN759weD92Vyiq-pWgAV2Z0?key=MZoH0xEDBkYz9g06jt2lGg

  1. Select “Get Started” on the “Set up single sign” on the tile.

AD_4nXdMOghED32faFAURvZQoN7ZY4OMwyrUxq1b1tf30nlo17rGLUvkFh_Pfa5ndEpWkySqVU8YhGNL0Q8zFhGv6M0hjY4Kv6Q7CFQs7nNrGvLN-HSR0Rqctg3WMe8lWnNl8XkY3zMFA9GQeVsLYtr9EQvwEqo?key=MZoH0xEDBkYz9g06jt2lGg

  1. Click the pencil icon for User Attributes & Claims:

AD_4nXcYlOGcbOXrufbMK19SmhxIJlsxwCwWCRMmCldnu17XcYo5a6rV0jgDBZUZQtXceBHMHT-SPkeXoJlBhFf_RMfHwotmp5DWvnpezGY84QnM6LYZ-jgbA67N6No0cOVNO8SKiEZNUB2CbW4nByEmSVT7enMM?key=MZoH0xEDBkYz9g06jt2lGg

  1. Click on the admin-role claim.

AD_4nXdOvtblFQWHFuuqDwU1ysXzc3i8ChZC85GFJMLx3nlDkp3yBJAT6vsokszt4I2xfxUnqYdpft_kf1lVfLGBQYRHtGwM572aIXqskiJNJ-ewo8P0gYCySgU-JZQj6uBRx9b8OTCv7JxQXWsV-KsVoSnD8qRV?key=MZoH0xEDBkYz9g06jt2lGg

  1. This pane is for the user attribute that will be passed to Netskope representing the admin role. By default, AzureAD uses the user.assignedroles as the attribute that is passed to Netskope during the single sign-on process. You can assign the admin role a number of ways but two examples are listed below:
  • If all members accessing the Netskope UI require the same role then you can statically assign a role by entering the role name in the “Source attribute” field. This must match the name of the role in the Netskope UI.

AD_4nXdHILw_mQbseXi6d7cUfrl_pCbfvIKHm__zk6UKHOSVM6u5-YXEzcvWIoqjIllS_ApKPpfcWDRhFoPkt5BFWpDfqYBLRjFQDYqvrlwKWtkcliD9L1J6VPTiB3YFtDJZ55_mHxLewc1PO7sXwZusmUXo24g?key=MZoH0xEDBkYz9g06jt2lGg

  • You can also pass the admin role based on specific users or groups by using Claim conditions. For the same, Click Claim Conditions.

AD_4nXcSoJjuAPugYcS79TGP1ESmImPb4aRJQRxSSnvBW1DFb5ALYBWjC9_huASpHpIENNivPCXnmDXfyd45M4VSs42OJhJS1W0RIwhkCWU4dZCAJxHfAhc_Y2MI4njFsRrE2PWVzPLNfH1YfoiFCWXhPRCUUQql?key=MZoH0xEDBkYz9g06jt2lGg

  • Select User type “Members” and click “Selectgroups”:

AD_4nXc86090VUn0z5DtoVA4gbeMM9qHrK7kyd5dinGEyxcZJUMXqgvPCB-pBYmu0MraRyhXYs8wisvwgyG2rMuGDZVoGVaEwiHyhMUT0Nah_NHZvH-sHxTi-hYRHZ1jnLui3rv1KeMqUS1LuMlgFeYDDjnoEUlF?key=MZoH0xEDBkYz9g06jt2lGg

  • Select the group(s) you want to scope the role to and click“Select.”

AD_4nXerKsL9-wGfR_UReEyxbWzW7RAX3rpa9nIiRcxbzu-S_4-xOtYkPtYEuHabSLr6De_ALWIZMwGI6ML0OE5yUFmf4rPaBaKvHhXoMB7ghRwsLInv-9kUVUmXCOH4xBJxdDPS8ib0RvipJvnTfAH3EWNXCf1a?key=MZoH0xEDBkYz9g06jt2lGg

  • Select the “Attribute” radio button and enter the custom admin role you want to assign to the selected group that you created on Netskope Tenant. For this article, The Custom Role I have created is “NS Custom Admin”

AD_4nXcZLcD5PMCnhrCcS9jAB9DcbioXDdn0bAYwBN576Bx7yL1hC2hhNOlvZeXbClVIGTOAaEvGkK8oMZrIF2vucV3cyKlrB11LPoSmXl44aWn_paTfv7MWiiVvXds3zmNMcZIdUWroUbfGxsz7Gi5Mot0NWB3V?key=MZoH0xEDBkYz9g06jt2lGg

  • Repeat the above steps for each group and role that needs access.
  • Click “Save”

AD_4nXcpKbFQOJn_QcO58z5mBkRNCP_UIjRxH5ep01qIlN6JmMhRMvD7457Juwms13TL1UP-Df_7RIeOwjTcRaVBQgx-BtQqL64ipmQoiyu5ntGJc42hmK9yWaK5mcwBX1Dr1DcDjygYDhjRuyp8tV2L8O0TpJg2?key=MZoH0xEDBkYz9g06jt2lGg

  1. Exit out of the User Attributes and Claims pane.
  2. Navigate back to the Netskope Administrator Console Overview and select Users and groups:

AD_4nXdWT6MnpJlQt911dJEgEm5iZlrngM1hPxE-3kEpoBtPqbdnem4YD1fewcI_BtvAE_ePvWnVNMYN4s-kYRtbG0NygG59aOEgmG08q0N8nbK1MM0Rt0TkSEdcuAMUSA8fsTOBmtHTfRHEz6HRIeLmRxqUQlxg?key=MZoH0xEDBkYz9g06jt2lGg

  1. Click Add user:

AD_4nXcQ0gwAH4JVI9_3eOXuRNGpLF4O2kS-4C3o4W-SHlAnUBOkJNYiyHFxseBsXvoE5voT-NRW2POXfNZ40hB85fN8R1d7mVadurf0s9FVpBsxOyuvXhJzNgioJOfXBNBPeKbfgovej9VHw2faxCtjtVxlKPG_?key=MZoH0xEDBkYz9g06jt2lGg

  1. Click Users and groups and select the user(s) and group(s) who need access and then click Select. For this article, ‘Netskope SSO Admin’ Group is selected. All the members under ‘Netskope SSO Admin' group will have ‘NS Custom Admin’ Role.

AD_4nXfZTgI4I7K1SMM5gGLIX8RFjOIaRUk9gPRvpw019x1-dkqMWow_9aop9L-JeLCED9V1O--LjdlcWL69V2ldQGybbsaKWdySjA9Uzz-ZB_jEVtnf5XMmZXzusN4yNHIW0wZtGNGJqnv9bBObGRQwuJkK2xiu?key=MZoH0xEDBkYz9g06jt2lGg

  1. Click “Select Role”

AD_4nXfq6vIAnZxlgK2ap2AQtP8dvNRz_JOlI46zfSdiZ2q0Sj9tHPdBOungu-PhFUc-OajRtpWsx_pQMnF2H1B3tddlYLOFwTvSxT4t20HYSipKNQSV20KDXKA8BurnS5WZIlZv61M_PUFjkVJkzBFaEo-lPzM?key=MZoH0xEDBkYz9g06jt2lGg

  1. Select the User role and click “Select.”

AD_4nXfuOYRvoGb3zEHtMoBOGCtKPqu_xcwShLdYgdlpZHcUbsftll5T7cmCIFgtU4_HbFPPD7Bs0jPxjlmvhz4oOHK1zBSP4v4Nk7Y5F7JEFpnVycCZk8fVPbYdSNGYpYn_TG1x4fv9uZ8yfkCIjcNovzBkruY?key=MZoH0xEDBkYz9g06jt2lGg

  1. Click “Assign”

AD_4nXfVuesW5EyVnnsCj1IJj-p4K-bGHgFYY4jRoskszZr5NXmJXyX3_OwrWZB7r51sFbu7Z_e9nxzLLMRhudJ5kKu19kbm2z41KJihSJP_O3VeN6s7taVMUCFlViPMueLHIGcN9aGA0X1_BgWMccxxHesJPc8?key=MZoH0xEDBkYz9g06jt2lGg

This completes the custom role assignment process.

 

Verification

You can test by going directly to your tenant (tenantname.goskope.com) and verifying that SSO works for the assigned User(s)/Group(s).

AD_4nXdxeQA8wG_P4f7PtlR9UydvJqr2lKgsMCUJXB_3DkW5vVbve_Nyg8ScpWMNOr_Y8NXKOTWq66AORqHcOcD1Oh5XBPB-tRxrrQrd1MlucB2ugkmt6-vH2i70vV02KbbXSWU0lwISeVw29IrzEPrX96b2nhI?key=MZoH0xEDBkYz9g06jt2lGg

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.


 

Be the first to reply!