Netskope
Integrate Netskope with Cloudaware to inventory Netskope accounts, client device status, SCIM groups, and SCIM users for identity, endpoint, and security reporting in the CMDB.
- Audience: Cloudaware administrators, SecOps teams, IAM teams, and endpoint operations teams
- Outcome: Netskope objects are available in CMDB for reporting, access review, endpoint visibility, and security correlation
Capabilities
The integration supports:
- Read-only discovery of Netskope account details, client device status, SCIM groups, and SCIM users
- Identity and endpoint context in Cloudaware for access review, device coverage, and security operations
- Search and reporting for Netskope objects using CMDB Navigator, CMDB list views, and reports
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage integrations (Cloudaware Administrator).
- Access to the Netskope tenant that will be connected.
- Netskope API token with read access to account, client device status, SCIM group, and SCIM user data.
- The Netskope tenant URL for your environment.
Create Netskope API Credentials
Create dedicated Netskope API credentials for Cloudaware discovery.
- Sign in to the Netskope admin console.
- Create or identify an API token for Cloudaware.
- Grant the token read access to Netskope account, client device status, SCIM group, and SCIM user data.
- Copy the token value and store it in an approved credential store until it is added to Cloudaware.
Use a dedicated Netskope API token for Cloudaware so it can be rotated or revoked without affecting other integrations.
Add a Netskope Account to Cloudaware
To connect Netskope to Cloudaware:
- In Cloudaware, go to Admin.
- Find Netskope, then click + ADD.
- Enter the following values:
- Name: Enter a display name for the Netskope connection.
- API URL: Enter the Netskope tenant URL or API base URL in the format
https://<tenant>.goskope.com - API Token: Enter the Netskope API token.
- Click Save.
- Confirm that the integration status indicator is green.
Allow the initial discovery cycle to complete after enabling the integration.
View Netskope Data in CMDB
To browse discovered Netskope resources:
- In Cloudaware, open CMDB Navigator.
- In the left pane, select NETSKOPE.
- Open an object list, e.g., Netskope Client Device Status or Netskope SCIM Users, to view records.
Supported Objects
Cloudaware ingests the following Netskope objects:
| Netskope Object | CMDB Object API Name |
|---|---|
| Netskope Account | CaNetskopeAccount__c |
| Netskope Client Device Status | CaNetskopeClientDeviceStatus__c |
| Netskope SCIM Group | CaNetskopeScimGroup__c |
| Netskope SCIM User | CaNetskopeScimUser__c |
Troubleshooting
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify that the Netskope base URL matches the tenant being connected.
- Confirm that the API token is active.
- Check that the credential has read access to account, client device status, SCIM group, and SCIM user data.
- Re-enter the credential by editing the Netskope integration in Cloudaware.
Netskope Objects Are Missing
- Allow the initial discovery cycle to complete.
- Confirm that the Netskope tenant contains the expected users, groups, and client device status data.
- Review the Netskope credential permissions for the affected objects.
- In CMDB Navigator, verify that you are viewing the NETSKOPE section and related resources.
- Review the Netskope integration status and any error messages in Cloudaware Admin.
Changes in Netskope Are Not Yet Visible in Cloudaware
- Synchronization is periodic. Wait for the next collection cycle.
- If changes remain missing, confirm that the API credential can still access the changed Netskope objects.
- Review the integration status and error messages in Cloudaware Admin.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
To rotate Netskope API token or update the base URL, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Netskope.
- Select the specific integration.
- Open the three-dot menu, then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Netskope.
- Select the specific integration.
- Open the three-dot menu, then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Avoid using personal administrator credentials for long-running integrations.
- Store Netskope API tokens only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
- Rotate Netskope API tokens according to your organization's credential-rotation policy and immediately after suspected exposure.
- Update the Cloudaware integration immediately if the Netskope API token is revoked, regenerated, or replaced.