Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Real-time Protection
    Best Practices for User Alert Policies

    Best Practices for User Alert Policies

    This article outlines best practices for User Alert policies (i.e., Real-time Protection policies configured with the User Alert action).

    Configuring the Notification Delivery Method

    When configuring your policy notification templates, you can select Client or Browser as the Notification Delivery Method. If Netskope Client is deployed on your users’ devices, Netskope highly recommends selecting Client. This is because client-based notifications allow for consistent notification delivery and properly follow configured mute and timeout settings.

    In contrast, the behavior of browser-based notifications can vary by application and might not be supported in all scenarios. These notifications are also dependent on application behavior and might not be displayable for all applications. Note that each domain redirect within an application will trigger a new alert as well.

    Configuring Redirect URLs

    When configuring a policy notification template, you can select the Redirect end users to the following URL automatically option to provide a redirect URL. For Block notifications, the redirect will be performed when users click the OK button. For User Alert notifications, the redirect will be performed when the user clicks the Stop button.

    Note that this option only applies when Browse is selected as the activity in your Real-time Protection policy. This also only applies to browser-based activities, not native applications. In addition, redirects will not work for applications that use custom responses.

    The best practice for using this option is to provide real-time user coaching or policy enforcement instead of showing a dead-end block page when a policy violation occurs. For example, you can redirect users to an internal page (e.g., a company wiki or SharePoint site) that explains your organization’s Acceptable Use Policy (AUP) or educates users on why certain sites are blocked. You can also configure automatic redirects to company-approved applications when users attempt to browse to unsanctioned ones.

    Configuring User Alert Policies

    Best practices for configuring User Alert policies include:

    • Never use the User Alert action for threat protection policies or malsite-filtering policies. To learn more, see: https://support.netskope.com/s/article/Best-Practice-Do-Not-Use-User-Alert-Policies-for-Threat-Protection
    • Netskope recommends using User Alert with compatible activities such as Send, Upload, Post, Share, Create, Delete, Download, and Edit.
    • To avoid frequent alerts, do not use User Alert when the activity is Browse.
    • The User Alert action is not available for the policy if any of the following activities are selected: Login Failed, Login Successful, Logout, Preview, API Post, Copy, and Invite.
    • If the Activities field is left empty, then User Alert will not be available as a policy action.
    In this Topic
    • Best Practices for User Alert Policies