The following sections walk you through the best practices of Real-time Protection and how to get the most out of your Real-time Protection policies.
Real-time Protection (Inline) vs API Data Protection (Out of Band) Policies
Policy Placement
Understanding the order of your Real-time Protection policies is important:
- Real-time Protection policies are processed sequentially (top to bottom).
- When traffic matches rule conditions, the action (Allow/Block) applies without further processing through the rule base. All policies are terminal except for DLP policies set as Alert and Continue.
- You can drag and drop, or choose the policies to re-order.
- Click Apply Changes to save the order.
- Policy changes don’t take effect until you apply changes.

General Guidelines
- Rules are processed from the top-down in the Real-time Protection policies list.
- Place any rules applied to individuals or small groups near the top of the list.
- Place exceptions at the top for block policies.
- Use the Filter option to view specific policies.
- Netskope allows the activity by default if it doesn’t match a policy.
- Enable dynamic URL classification to further extend security coverage and policy enforcement to uncategorized URLs. When a URL isn’t found in the inline (NSProxy) database, this feature allows the system to initiate an asynchronous search of a second, larger database to find the correct category. This categorization is then shared across all instances within the same POP and remains valid for 12 hours, ensuring that all subsequent requests receive the categorization. After expiration, the category is automatically refreshed when the URL is accessed again.
- Allow list business critical applications.
- Block list predefined high risk categories and IOCs.
- Leverage the Netskope REST API to maintain URL lists.
Structuring Real-time Protection Policies
Netskope recommends using Threat Protection policies to block high risk behaviors, such as downloading malware or uploading sensitive data to an unsanctioned application. Broader access control policies must be towards the bottom of the policy list.
- Threat Protection (High risk)
- Utility Policies
- Remote Browser Isolation (RBI)
- CASB (Activity Oriented)
- Web (Category Based)
- Netskope Private Access (NPA)




