Netskope SAML Single Sign-On (SSO)

The following is an overview of the steps required to configure the Netskope Web application for single sign-on (SSO) via SAML. Netskope offers both IdP-initiated SAML SSO (for SSO access through the user portal or CyberArk mobile applications) and SP-initiated SAML SSO (for SSO access directly through the Netskope web application). You can configure Netskope for either or both types of SSO. Enabling both methods ensures that users can log in to Netskope in different situations such as clicking through a notification email.

SP-initiated SSO for Netskope is automatically enabled when the SAML feature is activated.
  1. Prepare Netskope for single sign-on (see Netskope requirements for SSO).

  2. In the Identity Administration portal, add the application and start to configure application settings.

    Once the application settings are configured, complete the user account mapping and assign the application to one or more roles. For details, see Configure Netskope in the Identity Administration portal (Part 1).

  3. Configure the Netskope application for single sign-on.

    You will need to copy some settings from Application Settings in the Identity Administration portal and paste them into fields on the Netskope website. For details, Configure Netskope on its web site

    After you have finished configuring the application settings in the Identity Administration portal and the Netskope application, users are ready to launch the application from the Identity User Portal.

  4. In the Identity Administration portal, finish configuring application settings.

For details, see Configure Netskope in the Identity Administration portal (Part 2).

Netskope requirements for SSO

Before you configure the Netskope web application for SSO, you need the following:

  • An active Netskope account with administrator rights for your organization.

  • A signed certificate.

  • You can either download one from the Identity Administration portal or use your organization’s trusted certificate.

Set up the certificates for SSO

To establish a trusted connection between the web application and CyberArk Identity, you need to have the same signing certificate in both the application and the application settings in the Identity Administration portal.

If you use your own certificate, you upload the signing certificate and its private key in a .pfx or .p12 file to the application settings in the Identity Administration portal. You also upload the public key certificate in a .cer or .pem file to the web application.

What you need to know about Netskope

Each SAML application is different. The following table lists features and functionality specific to Netskope.

Capability

Supported?

Support details

Web browser client

Yes

 

Mobile client

Yes

iOS and Android.

SAML 2.0

Yes

 

SP-initiated SSO

Yes

 

IdP-initiated SSO

Yes

 

Force user login via SSO only

Yes

 

Separate administrator login
after SSO is enabled

Yes

Only administrators can log in.

User or Administrator lockout risk

Yes

After SAML settings are enabled and saved, there is no back door to login to Netskope by username-password.

Automatic user provisioning

No

 

Multiple User Types

Yes

Admin user

End users

Self-service password

Yes

Users can reset their own passwords. Resetting another user’s password requires administrator rights.

Access restriction using a corporate IP range

Yes

You can specify an IP Range in the Identity Administration portal Policy page to restrict access to the application.

Configure Netskope in the Identity Administration portal (Part 1)

Configure Netskope on its web site

Configure Netskope in the Identity Administration portal (Part 2)

  1. Return to the browser tab you were using to work in the Identity Administration portal in Configure Netskope in the Identity Administration portal (Part 1) and navigate to the Application Settings screen of your Netskope app.

  2. Configure the following:

    Field

    Set it to

    What you do

    Assertion Consumer Service URL

    The URL provided on the Netskope web site.

    To to More > Settings > SSO, copy the Assertion Consumer Service URL, and paste it here.

    Service Provider Entity Id

    The ID provided on the Netskope web site.

    To to More > Settings > SSO, copy the Service Provider Entity Id, and paste it here.

For more information about Netskope

Contact Netskope for more information about configuring Netskope for SSO.