A steering configuration steers private app traffic to Netskope Private Access (NPA). When you steer a private app that is defined broadly — for example a wildcard domain such as *.corp.com or a large subnet published for App Discovery — every destination that matches is tunneled to NPA. A Private App bypass lets you exclude specific destinations within that scope from the NPA tunnel, sending them straight to their destination on the local network instead.
Private App bypasses are defined using a Destination Profile (and optionally a Service Profile) that you attach to a steering configuration as an exception. The exception is enforced by the Netskope Client.
Common use cases:
- Reach a resource on the user’s local subnet (such as a local printer) whose IP overlaps a subnet that is steered to NPA.
- Bypass a subset of a steered domain — for example steer
*.corp.comto NPA but senda.corp.comandb.corp.comdirectly to their destination. - Bypass VOIP/soft-client subnets (for example Cisco Jabber) that are not supported over NPA.
Private App bypasses are not applied on a steering configuration that steers only Private Apps. If the configuration’s Traffic setting steers Private App Segments only — with no Cloud App or Web traffic steered — the attached Destination/Service exceptions are ignored.
Workaround: On the same steering configuration, enable Cloud App steering and steer specific Cloud Apps only. Do not add a Cloud App that you do not intend to steer. This keeps the steering-exception engine active so your Private App bypasses take effect, without broadening what is steered.
Guidelines
When configuring Private App bypasses, consider the following:
- Ensure you have the right administrative privileges to your Netskope account.
- The steering configuration must steer Cloud Apps or Web traffic in addition to Private App Segments (see the Important note above).
- A single exception has a limited number of steering objects across its Destination Profiles. The webUI blocks saving an exception above this limit. In case this number needs to be increased please contact your Account Team.
- A Destination Profile and a Service Profile in the same exception are evaluated together as an AND condition (the destination must match and the port/protocol must match).
- If a Destination Profile already includes a port, it cannot be combined with a separate Service Profile in the same exception.
- If you attach only a Service Profile with no Destination Profile, the webUI displays a warning: the bypass then applies to the specified port/protocol across all destinations. Confirm this is intended.
- Bypasses supported for private apps include: single IP, IP range, subnet/CIDR, FQDN, wildcard or subset of a domain, and regex — optionally scoped by port and protocol.
- Full Client support is available on Windows and macOS.
- Steering bypasses from Partner Access are not honored.
Exception Traffic Logs
Private App bypasses are enforced locally by the Netskope Client, so bypassed traffic never reaches the gateway and is not shown in Skope IT events. Bypass decisions are recorded at debug level in the Netskope Client log bundle. To troubleshoot, collect a device support/log bundle from the endpoint.
Before You Begin
Create the profiles you will attach to the exception:
- Create a Destination Profile with the destinations to bypass. Go to Policies > Destination, click New Destination Profile, and add the IP addresses, IP ranges, CIDR blocks, FQDNs, wildcards, or regex entries. Optionally include a port. For details, see Destination Profile.
- (Optional) Create a Service Profile to scope the bypass by port and protocol, when the Destination Profile does not itself specify a port. Go to Policies > Service, click New Service, and add the protocol and ports. For details, see Service Profile.
Adding a Private App Bypass Exception
To add a Private App bypass to a steering configuration:
- Go to Settings > Security Cloud Platform > Steering Configuration.
- On the Steering Configuration page, click … for the steering configuration you want to add the bypass to.
- Click View Exceptions.
- In the Exceptions tab, click New Exception and then Private App Bypass.
- In the New Exception window:
- Exception Type: Choose Private App Bypass.
- Destination Profile: Select one or more Destination Profiles that define the destinations to bypass. Click the + icon to create a new Destination Profile if needed.
- Service Profile: (Optional) Select one or more Service Profiles to scope the bypass by port/protocol. This field is unavailable when a selected Destination Profile already includes a port.
- Action: Bypass — matching traffic is sent straight to its destination and is not tunneled to NPA.
- Notes: (Optional) Enter comments or notes for the exception.
- Click Add.
The new bypass appears in the Exceptions list with its Action, Type, Notes, and Last Modified details.
Configuration changes are applied to the Netskope Client on the next hourly update, or immediately when the end user performs a manual steering configuration update.

