This article outlines the third-party app limitations that could affect the functionality of Next Generation API Data Protection.
| Limitation | Reason |
|---|---|
| Tickets, comments, and files cannot report PUBLIC (internet-accessible) exposure. | Atlassian Jira API limitation |
| For tickets, exposure is only computed when the ticket has an explicit Issue Security Level configured. Tickets without a security level return no access data at the ticket level; broader access is instead reflected at the project level. | |
| Comment visibility is restricted to specific roles or groups only. The Jira API provides no option to mark a comment as publicly accessible. | |
| Files always inherit the parent ticket's access permissions and have no independent visibility control. | |
| Users can hide their email address in their personal profile settings. Any user with a hidden email is treated as externally exposed by default. |
| Impacted Application | Limitation | Reason |
|---|---|---|
| Unknown user and empty file owner in DLP alerts Sometimes, Microsoft Graph API may not return complete details about the owner of a file or folder. When this happens, the DLP alert shows the user as Unknown, and the File Owner field remains blank. | Microsoft Graph API limitation |
| Netskope does not support Microsoft 365 apps during the migration of your Microsoft tenant between data centers. Ensure the migration is fully completed before granting access to Netskope. For more information about Microsoft tenant migration, see: | Microsoft API limitation |
| No support for OneNote files DLP and malware scanning are not supported for OneNote files because Microsoft Graph APIs do not provide download URLs for them. As a result, Netskope cannot scan OneNote files for DLP or threat protection on Microsoft 365 OneDrive and SharePoint. | Microsoft Graph API limitation |
| Microsoft 365 SharePoint | No support for SharePoint Lists While exposure information for folders and files (drives/driveItems) can be retrieved via the Microsoft Graph API, metadata for SharePoint lists is not accessible. As a result, Next Generation API Data Protection for Microsoft 365 SharePoint does not support SharePoint lists. | Microsoft Graph API limitation |
| Adding/Removing ‘Owner’ level access from files/folders "Site Collection Administrators" will maintain 'Owner' access to files and folders, and this cannot be changed using Microsoft Graph APIs. | Microsoft Graph API limitation |
| Limitation regarding ‘Deleted Groups’ When a file is shared with a group that is later deleted, the Microsoft Graph API will still indicate that the file is shared with that group. Additionally, any members who were part of the group prior to its deletion will retain access to the file. Due to this limitation, during onboarding or provisioning, Netskope has no effective means to assess the exposure of files shared with groups that were deleted before the Microsoft account was connected. Consequently, these files will appear on the Next Generation API Data Protection Inventory page with an EXPOSURE status of UNSPECIFIED. As a result, no alerts will be generated, and no policy actions will be applied to these files. To resolve this issue, customers are advised to remove the deleted groups from the permission list of affected files. Once this is completed, Netskope will be able to accurately calculate exposure and enforce policy actions for those files. | Microsoft Graph API limitation |
| Microsoft 365 SharePoint | No support for Microsoft 365 SharePoint sites created by Microsoft Loop As Microsoft Loop is still in public preview, the necessary permissions are not publicly documented. Consequently, when Netskope encounters this type of 'site' during provisioning, it will provision the site but not its subsites, drives, or drive items. | Microsoft Loop limitation |
| Microsoft 365 Teams | Real-time membership tracking in channel meetings For channel meetings initiated via 'Meet Now,' the Microsoft Graph API does not send webhooks while the meeting is in progress. As a result, Netskope cannot track changes in channel meeting membership during the live meeting. However, once the meeting concludes and the chat is posted in the channel, normal policy processing will resume, as Netskope will then receive webhooks for membership and data changes from Microsoft. | Microsoft Graph API limitation |
| Incoming shared channels For shared channels created by external organizations and shared with a team in your organization, the Microsoft Graph API does not trigger webhooks for posted chat messages. Consequently, Netskope cannot scan the content of incoming shared channels. | Microsoft Graph API limitation | |
| Real-time membership tracking for shared groups in shared channels For shared channels, the Microsoft Graph API does not send webhooks when a shared channel is shared with a group. Instead, Netskope must periodically poll for changes, currently every 60 minutes. As a result, Netskope cannot track shared group membership changes in real time. | Microsoft Graph API limitation | |
| Chat with Self feature When chatting with self, the Microsoft Graph API does not return chat metadata or send webhooks for self-chat messages. Consequently, Netskope cannot support listing self-chats in the inventory or scanning their contents. | Microsoft Graph API limitation |
-
For Salesforce, Netskope supports a soft-delete only for content document, document, and attachment. This is due to upstream API limitation. On performing the delete action, Netskope moves the file to the recycle bin.
-
You cannot configure Salesforce as a legal hold or quarantine destination. However, an offending file or an object can be copied or quarantined to a different SaaS app as a destination (like Google Drive, Microsoft 365 OneDrive, SharePoint, or any other app that supports legal hold or quarantine as a destination).
Due to a Salesforce API limitation, the connected OAuth user must have write permission on files to perform the delete and quarantine remediations. Additionally, if this remediation needs to be applied to specific libraries, the user must be a member of those libraries with write access. -
When a quarantine action is performed on a Salesforce content document, Netskope replaces the original file content with a placeholder (tombstone). However, due to a Salesforce API limitation, the original file content remains accessible through previous versions of the content document.
Email-Based Share Events
Due to current Smartsheet API limitations, certain email-based sharing actions cannot be enforced through access control changes. These actions share content via email without modifying permissions on the underlying sheet, report, or discussion object.
As a result:
-
Access to the original object remains unchanged.
-
Policy actions that rely on modifying sharing permissions are not supported.
-
If the shared content is scanned and a DLP violation is detected, an alert can be generated.
The following events are affected:
-
ATTACHMENT_SEND – An attachment is sent directly by email to users or user groups.
-
DISCUSSION_SEND – A discussion thread (including comments and replies) is sent directly by email.
-
DISCUSSION_SEND_COMMENT – A specific discussion comment or reply is sent directly by email.
-
REPORT_SEND_AS_ATTACHMENT – A report is sent as an email attachment.
-
SHEET_SEND_AS_ATTACHMENT – A sheet is sent as an email attachment.
-
SHEET_SEND_ROW – Selected sheet rows are sent by email.
-
UPDATE_REQUEST_CREATE – A sheet update request is created and sent.
These limitations are inherent to the current Smartsheet API capabilities.
Exposure Data Consistency
Due to limitations in the Smartsheet /shares API, permission and exposure changes made in the Smartsheet UI may not be reflected immediately in API responses. As a result, exposure information may be temporarily outdated.
This behavior is intermittent and depends on the responsiveness of the upstream API.
Exposure data is synchronized when updated permission information becomes available through subsequent API responses.
| Limitation | Reason |
|---|---|
| Delete remediation action cannot be performed on chat messages sent by an external user. | Zoom API limitation |
| Next Generation API Data Protection cannot scan attachment uploaded from 3rd party apps in team chat and in-meeting chat. | |
| Next Generation API Data Protection cannot scan attachments sent by external users in team chat, including direct, channel, and group messages. |

